<?xml version="1.0" encoding="UTF-8"?><rss version="0.92">
<channel>
	<title>CQ-CSER</title>
	<link>http://cq-cser.cn</link>
	<description>计算机爱好者</description>
	<lastBuildDate>Sun, 15 Jan 2012 08:17:54 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	<!-- generator="WordPress/3.0" -->

	<item>
		<title>2012</title>
		<description><![CDATA[新年快到了，昨天到家了，整理下最近买的，强的，别人送的 各种怀念啊！ 新年要有新计划，还是写下来约束力大点。 1.OS,BROWSER,MUTIL PLAYER 3个重点方向要有成果 2.完善理论，开发自用工具，向大虾学习。 3.忘记一些东东，稳定下来，培养新习惯。 4.实践新技术方向 No related posts.


No related posts.]]></description>
		<link>http://cq-cser.cn/2012/01/2012/</link>
			</item>
	<item>
		<title>WAR3格式</title>
		<description><![CDATA[本来是考虑w3g格式的 参见如下 http://w3g.deepnode.de/files/w3g_format.txt 大致包含部分： 版本头 压缩数据 解压出来包含各类时间，动作等。用的是ZLIB解压 ///////////////////////////////////////////////////////////////////////////////////////////////////// 后来想了下，用录像不如用地图，随便打开一个 00000000h: 48 4D 33 57 00 00 00 00 E5 8F AA E6 98 AF E5 8F ; HM3W&#8230;.鍙槸鍙 00000010h: A6 E5 A4 96 E4 B8 80 E5 BC A0 E9 AD 94 E5 85 BD ; ﹀涓€寮犻瓟鍏? 00000020h: E4 BA 89 E9 9C B8 49 [...]


No related posts.]]></description>
		<link>http://cq-cser.cn/2011/12/war3%e6%a0%bc%e5%bc%8f/</link>
			</item>
	<item>
		<title>QQPLAYER PICT PnSize Buffer Overflow WIN7 DEP_ASLR BYPASS</title>
		<description><![CDATA[http://cq-cser.cn/wp-content/plugins/downloads-manager/upload/qqplayer.rb 样本： http://115.com/file/cl3naedv http://115.com/file/aqu3qzmk # Exploit Title: QQPLAYER PICT PnSize Buffer Overflow WIN7 DEP_ASLR BYPASS # Date: 2011,11,21 # Author: hellok(warptencq[at]gmail.com) # Software Link: http://dl_dir.qq.com/invc/qqplayer/QQPlayer_Setup_32_845.exe # Version: 32_845(lastest) # Tested on: WIN7 require 'msf/core' class Metasploit3 < Msf::Exploit::Remote include Msf::Exploit::FILEFORMAT def initialize(info = {}) super(update_info(info, 'Name' => 'QQPLAYER PICT PnSize Buffer Overflow WIN7 DEP_ASLR BYPASS', [...]


Related posts:<ol><li><a href='http://cq-cser.cn/2011/11/what_ever/' rel='bookmark' title='Permanent Link: 记事'>记事</a></li>
<li><a href='http://cq-cser.cn/2011/11/kankan-stackoverflowdos-exploit/' rel='bookmark' title='Permanent Link: thunder_kankan_stack_overflow/dos exploit'>thunder_kankan_stack_overflow/dos exploit</a></li>
</ol>]]></description>
		<link>http://cq-cser.cn/2011/11/qqplayer-pict-pnsize-buffer-overflow-win7-dep_aslr-bypass/</link>
			</item>
	<item>
		<title>thunder_kankan_stack_overflow/dos exploit</title>
		<description><![CDATA[http://cq-cser.cn/wp-content/plugins/downloads-manager/upload/kankan.py print &#8220;&#8221;" #1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0 #0      ___           ___           ___       ___       ___           ___     1 #1     /\__\         /\  \         /\__\     /\__\ [...]


Related posts:<ol><li><a href='http://cq-cser.cn/2010/01/internet-explorer-aurora-exploit/' rel='bookmark' title='Permanent Link: Internet Explorer Aurora Exploit'>Internet Explorer Aurora Exploit</a></li>
<li><a href='http://cq-cser.cn/2010/01/zzrising-antivirus-200820092010-local-privilege-escalation-exploit/' rel='bookmark' title='Permanent Link: [zz]Rising AntiVirus 2008/2009/2010 Local Privilege Escalation Exploit'>[zz]Rising AntiVirus 2008/2009/2010 Local Privilege Escalation Exploit</a></li>
<li><a href='http://cq-cser.cn/2010/09/%e5%85%b3%e4%ba%8eesp%e5%ae%9a%e5%be%8b/' rel='bookmark' title='Permanent Link: 关于esp定律'>关于esp定律</a></li>
</ol>]]></description>
		<link>http://cq-cser.cn/2011/11/kankan-stackoverflowdos-exploit/</link>
			</item>
	<item>
		<title>Blogs, Feeds, Guides &amp; Links[zz]</title>
		<description><![CDATA[原文：http://g0tmi1k.blogspot.com/2011/11/blog-guides-links.html 顺便FK GFW 特别推荐http://j00ru.vexillium.org/?p=893此系列 Programming/Coding [Bash] Advanced Bash-Scripting Guide &#8211; http://tldp.org/LDP/abs/html/ [Bash] Bash shell scripting tutorial &#8211; http://steve-parker.org/sh/sh.shtml [Bash] Bourne Shell Reference &#8211; http://linuxreviews.org/beginner/bash_GNU_Bourne-Again_SHell_Reference/ [CheatSheet] Scripting Languages: PHP, Perl, Python, Ruby &#8211; http://hyperpolyglot.org/scripting Offensive Security&#8217;s Pentesting With BackTrack (PWB) Course [Pre-course] Corelan Team &#8211; http://www.corelan.be [Pre-course] The Penetration Testing Execution Standard &#8211; http://www.pentest-standard.org/index.php/Main_Page [Hash] NTLM [...]


Related posts:<ol><li><a href='http://cq-cser.cn/2011/10/recent-life/' rel='bookmark' title='Permanent Link: recent life'>recent life</a></li>
<li><a href='http://cq-cser.cn/2010/01/internet-explorer-aurora-exploit/' rel='bookmark' title='Permanent Link: Internet Explorer Aurora Exploit'>Internet Explorer Aurora Exploit</a></li>
<li><a href='http://cq-cser.cn/2010/01/top-ten-web-hacking-techniques-of-2009/' rel='bookmark' title='Permanent Link: Top Ten Web Hacking Techniques of 2009!'>Top Ten Web Hacking Techniques of 2009!</a></li>
</ol>]]></description>
		<link>http://cq-cser.cn/2011/11/blogs-feeds-guides-linkszz/</link>
			</item>
	<item>
		<title>记事</title>
		<description><![CDATA[http://mpc-hc.svn.sourceforge.net/viewvc/mpc-hc/trunk/src/filters/transform/MPCVideoDec/MPCVideoDecFilter.cpp?view=log // We crash inside this function // In swscale.c: Function &#8216;simpleCopy&#8217; // Line: 1961 &#8211; Buffer Overrun // This might be ffmpeg fault or more likely mpchc is not reinitializing ffmpeg correctly during display change (moving mpchc window from display A to display B) 搞了好久才无意发现是这个。暂时不好利用。待定了。 枉费我在没SYMBOLS的情况下搞了好久，心碎啊，教训教训。。 While this DLL seems interesting, it does not [...]


Related posts:<ol><li><a href='http://cq-cser.cn/2011/11/qqplayer-pict-pnsize-buffer-overflow-win7-dep_aslr-bypass/' rel='bookmark' title='Permanent Link: QQPLAYER PICT PnSize Buffer Overflow WIN7 DEP_ASLR BYPASS'>QQPLAYER PICT PnSize Buffer Overflow WIN7 DEP_ASLR BYPASS</a></li>
</ol>]]></description>
		<link>http://cq-cser.cn/2011/11/what_ever/</link>
			</item>
	<item>
		<title>recent life</title>
		<description><![CDATA[chrome 待定 http://code.google.com/p/selenium/wiki/JsonWireProtocol http://www.chromium.org/developers/testing/webdriver-for-chrome/chromedriver-internals http://selenium.googlecode.com/svn/trunk/docs/api/java/org/openqa/selenium/chrome/ChromeDriver.html http://build.chromium.org/f/chromium/snapshots/Win_Webkit_Latest/4181/REVISIONS http://src.chromium.org/svn/trunk/ http://build.chromium.org/f/chromium/snapshots/Win_Webkit_Latest/4181/chrome-win32.test/ . binary_planting 系列,GOOD! http://blog.acrossecurity.com/2011/10/google-chrome-pkcs11txt-file-planting.html http://www.binaryplanting.com/guidelinesDevelopers.htm http://www.binaryplanting.com/test.htm this problem also affects the way Windows processes are launched via various functions such as CreateProcess*, ShellExecute*, WinExec, LoadModule, _spawn*p* and _exec*p*. library=c:\temp\malicious.dll library=\\www.binaryplanting.com\demo\chrome_pkcs11Planting\malicious.lib derbycon2011 http://www.irongeek.com/i.php?page=videos/derbycon1/tony-huffman-myne-us-when-fuzzers-miss-the-no-hanging-fruit bot funny! http://www.m86security.com/labs/bot_statistics.asp autocomplete stolen http://blog.mindedsecurity.com/2011/10/autocompleteagain.html WEB指纹识别 http://sebug.net/chweb/ peachfuzz http://peachfuzzer.com/TutorialNetworkServer 另 https://media.blackhat.com/bh-us-11/Cerrudo/BH_US_11_Cerrudo_Vulnerability_Hunting_Windows_Slides.pdf 此文系慢慢看 No related [...]


No related posts.]]></description>
		<link>http://cq-cser.cn/2011/10/recent-life/</link>
			</item>
	<item>
		<title>darungrim</title>
		<description><![CDATA[DarunGrim is a binary diffing tool. DarunGrim is a free diffing tool which provides binary diffing functionality. Binary diffing is a powerful technique to reverse-engineer patches released by software vendors like Microsoft. Especially by analyzing security patches you can dig into the details of the vulnerabilities it&#8217;s fixing. You can use that information to learn [...]


Related posts:<ol><li><a href='http://cq-cser.cn/2011/12/war3%e6%a0%bc%e5%bc%8f/' rel='bookmark' title='Permanent Link: WAR3格式'>WAR3格式</a></li>
</ol>]]></description>
		<link>http://cq-cser.cn/2011/10/darungrim/</link>
			</item>
	<item>
		<title>qtweb3.7.2</title>
		<description><![CDATA[################################################# QTWeb Internet Browser URL weakness lets remote attackers to do Spoof or phishing attacks Vendor URL: http://www.qtweb.net/ Vendor bugtrack=&#62; http://code.google.com/p/qtweb/issues/detail?id=151 Advisore: http://lostmon.blogspot.com/2011/10/qtweb-internet-browser-url-weakness.html Vendor notify: YES exploit available: YES ################################################## ################### Description By vendor ################### QtWeb Internet Browser - lightweight, secure and portable browser having unique user interface and privacy features. QtWeb is an open [...]


No related posts.]]></description>
		<link>http://cq-cser.cn/2011/10/qtweb3-7-2/</link>
			</item>
	<item>
		<title>samba4_smbclient_linux_winnt_share_file</title>
		<description><![CDATA[apt-get install samba4 http://wiki.samba.org/index.php/Samba4 http://wiki.samba.org/index.php/Samba4/HOWTO 例: root@bt:~# smbclient -L 192.168.1.3 Enter root&#8217;s password: Domain=[1UEUKFM1YARQQWT] OS=[Windows 7 Professional 7600] Server=[Windows 7 Professional 6.1] Sharename Type Comment &#8212;&#8212;&#8212; &#8212;- &#8212;&#8212;- Error returning browse list: NT_STATUS_NOT_SUPPORTED session request to 192.168.1.3 failed (Called name not present) session request to 192 failed (Called name not present) session request to *SMBSERVER [...]


Related posts:<ol><li><a href='http://cq-cser.cn/2009/12/asp-net%e7%9a%84%e5%87%a0%e7%a7%8d%e9%a1%b5%e9%9d%a2%e4%bc%a0%e5%80%bc%e6%96%b9%e6%b3%95/' rel='bookmark' title='Permanent Link: asp.net的几种页面传值方法'>asp.net的几种页面传值方法</a></li>
</ol>]]></description>
		<link>http://cq-cser.cn/2011/09/samba4_smbclient_linux_winnt_share_file/</link>
			</item>
</channel>
</rss>

