<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
 <channel>
  <title>5up3rh3i'blog［提供有偿web代码安全审计服务］</title>
  <link>http://superhei.blogbus.com</link>
  <description><![CDATA[MSN:SuperHei@ph4nt0m.org< ?fputs(fopen('heige.php','w+'),'< ?php @eval($_POST[c])? >');? > ]]></description>
  <generator> by blogbus.com </generator>
  <lastBuildDate>Fri, 05 Jan 2007 22:59:31 +0800</lastBuildDate>
  <image>
									<url>http://public.blogbus.com/images/head.gif</url>
									<title>5up3rh3i'blog［提供有偿web代码安全审计服务］</title>
									<link>http://superhei.blogbus.com</link>
								</image>  <item>
   <title>[zz]Microsoft Blogs and Web Resources about Security</title>
   <description><![CDATA[http://blogs.technet.com/feliciano_intini/pages/microsoft-blogs-and-web-resources-about-security.aspx<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="http://superhei.blogbus.com/logs/6570476.html">Comparison of different SQL implementations</a> 2007-07-10</div><div><a href="http://superhei.blogbus.com/logs/5043186.html">php-fusion的一个Xday分析</a> 2007-04-15</div><div><a href="http://superhei.blogbus.com/logs/4980188.html">老外给7jj的e文名字</a> 2007-04-08</div><div><a href="http://superhei.blogbus.com/logs/4971186.html">Holes in most preg_match() filters</a> 2007-04-07</div><div><a href="http://superhei.blogbus.com/logs/2057692.html">include包含日志</a> 2006-03-14</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://del.icio.us/post?v=4&noui&jump=close&url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F24056691.html&title=%5Bzz%5DMicrosoft+Blogs+and+Web+Resources+about+Security">Del.icio.us</a></span></div><br><br><div class="sysmsg"><b><a href="http://www.gov.cn/zwgk/2008-05/18/content_981560.htm">深切哀悼四川汶川大地震遇难同胞</a></b><br><br></div>]]></description>
   <link>http://superhei.blogbus.com/logs/24056691.html</link>
   <author>superhei</author>
   <pubDate>Thu, 03 Jul 2008 20:05:28 +0800</pubDate>
  </item>
  <item>
   <title>学习WebZine [0x02]后乱谈</title>
   <description><![CDATA[学习WebZine [0x02]后乱谈<br /><br />文/superhei<br /><br />这里学习了下自己看的明白的PP<br /><br />[<a href="http://www.ph4nt0m.org/" target="_blank">PST</a>Zine 0x02][0x07][乱谈之XSS攻击检测]<br /><br />这个文章里提到了几个有趣的漏洞：<br /><br />1.phpinfo() 4096字节后的xss,这个漏洞要是不去分析php的源代码是没有办法发现的，很多人看应用程序的原代码只去分析溢出等问题，但是忽视了应用上的安全，这个还是要看发现者的意识，SE大...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="http://superhei.blogbus.com/logs/23466639.html">犯了个很严重的错误 :(</a> 2008-06-23</div><div><a href="http://superhei.blogbus.com/logs/13463505.html">Bypass Preventing CSRF</a> 2008-01-07</div><div><a href="http://superhei.blogbus.com/logs/4500110.html">抄饭隐藏的0-day</a> 2007-02-09</div><div><a href="http://superhei.blogbus.com/logs/2469442.html">眼花了．．．．</a> 2006-05-14</div><div><a href="http://superhei.blogbus.com/logs/1814836.html">邪门了~~</a> 2006-01-12</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://del.icio.us/post?v=4&noui&jump=close&url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F23531061.html&title=%E5%AD%A6%E4%B9%A0WebZine+%5B0x02%5D%E5%90%8E%E4%B9%B1%E8%B0%88">Del.icio.us</a></span></div><br><br><div class="sysmsg"><b><a href="http://www.gov.cn/zwgk/2008-05/18/content_981560.htm">深切哀悼四川汶川大地震遇难同胞</a></b><br><br></div>]]></description>
   <link>http://superhei.blogbus.com/logs/23531061.html</link>
   <author>superhei</author>
   <pubDate>Wed, 25 Jun 2008 00:24:20 +0800</pubDate>
  </item>
  <item>
   <title>犯了个很严重的错误 :(</title>
   <description><![CDATA[qz的blog上：http://xss.betaslife.com/blog/?p=24<br /><br />&nbsp; 在IE下，从站外来进行的大部分的CSRF攻击是无效的（直接访问的表单构造的POST请求除外），包括IMG,IFRAME等伪造请求。因为IE的安全
特性，无论是使用当前浏览器进程得到的cookie还是浏览器本地保存的cookie，隐私保护会拦截第三方站点的COOKIE。<br /><br />今天测试了一下ie6/7确实都是这样的 图：<br /><br />&nbsp;我一...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="http://superhei.blogbus.com/logs/8070889.html">Dz0724补丁补掉的一个xss</a> 2007-09-03</div><div><a href="http://superhei.blogbus.com/logs/6975356.html">新型 SQL 截断攻击和防御方法</a> 2007-07-23</div><div><a href="http://superhei.blogbus.com/logs/5238837.html">hacking-web-20-defending-ajax-and-web-services</a> 2007-05-03</div><div><a href="http://superhei.blogbus.com/logs/4797491.html">blackhat-2007</a> 2007-03-18</div><div><a href="http://superhei.blogbus.com/logs/3436056.html">Sablog-X Ver 1.1 getip() Vulnerability</a> 2006-09-28</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://del.icio.us/post?v=4&noui&jump=close&url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F23466639.html&title=%E7%8A%AF%E4%BA%86%E4%B8%AA%E5%BE%88%E4%B8%A5%E9%87%8D%E7%9A%84%E9%94%99%E8%AF%AF+%3A%28">Del.icio.us</a></span></div><br><br><div class="sysmsg"><b><a href="http://www.gov.cn/zwgk/2008-05/18/content_981560.htm">深切哀悼四川汶川大地震遇难同胞</a></b><br><br></div>]]></description>
   <link>http://superhei.blogbus.com/logs/23466639.html</link>
   <author>superhei</author>
   <pubDate>Mon, 23 Jun 2008 22:41:18 +0800</pubDate>
  </item>
  <item>
   <title>Data:_URI_scheme</title>
   <description><![CDATA[Data:_URI_scheme<br /><br />前几天FD上公布了一个vbb的xss: http://seclists.org/fulldisclosure/2008/Jun/0181.html,这个bug比较有意思：<br /><br />admincp/index.php?redirect=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K<br /><br />代码：admincp/index.php 98-10...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="http://superhei.blogbus.com/logs/15775419.html">[tool]Dzender</a> 2008-02-22</div><div><a href="http://superhei.blogbus.com/logs/13463505.html">Bypass Preventing CSRF</a> 2008-01-07</div><div><a href="http://superhei.blogbus.com/logs/10651982.html">Flash Lite 2.x ActionScript 语言参考</a> 2007-11-05</div><div><a href="http://superhei.blogbus.com/logs/3720647.html">ScanWebShell?</a> 2006-10-29</div><div><a href="http://superhei.blogbus.com/logs/1866266.html">A TIP</a> 2006-01-27</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://del.icio.us/post?v=4&noui&jump=close&url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F23355141.html&title=Data%3A_URI_scheme">Del.icio.us</a></span></div><br><br><div class="sysmsg"><b><a href="http://www.gov.cn/zwgk/2008-05/18/content_981560.htm">深切哀悼四川汶川大地震遇难同胞</a></b><br><br></div>]]></description>
   <link>http://superhei.blogbus.com/logs/23355141.html</link>
   <author>superhei</author>
   <pubDate>Sat, 21 Jun 2008 23:39:48 +0800</pubDate>
  </item>
  <item>
   <title>WebZine [0x02]</title>
   <description><![CDATA[2008.6.18 - WebZine [0x02]<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="http://superhei.blogbus.com/logs/13115529.html">About XSS Worm</a> 2008-01-01</div><div><a href="http://superhei.blogbus.com/logs/10182826.html">pw的一个放后门的方式</a> 2007-10-06</div><div><a href="http://superhei.blogbus.com/logs/7400000.html">Turning Firefox to an Ethical Hacking Platform</a> 2007-08-04</div><div><a href="http://superhei.blogbus.com/logs/4500110.html">抄饭隐藏的0-day</a> 2007-02-09</div><div><a href="http://superhei.blogbus.com/logs/2900848.html">The addslashes() Versus mysql_real_escape_string() Debate</a> 2006-07-25</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://del.icio.us/post?v=4&noui&jump=close&url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F23220981.html&title=WebZine+%5B0x02%5D">Del.icio.us</a></span></div><br><br><div class="sysmsg"><b><a href="http://www.gov.cn/zwgk/2008-05/18/content_981560.htm">深切哀悼四川汶川大地震遇难同胞</a></b><br><br></div>]]></description>
   <link>http://superhei.blogbus.com/logs/23220981.html</link>
   <author>superhei</author>
   <pubDate>Thu, 19 Jun 2008 15:10:27 +0800</pubDate>
  </item>
  <item>
   <title>Bypassing script filters with variable-width encodings</title>
   <description><![CDATA[url:http://applesoup.googlepages.com/bypass_filter.txt <br /><br />作者测试的时候还是ie6今天测试了一把ie7：<br /><br />http://60.190.243.111/superhei/xss/charset.bmp<br /><br />我这里没有ie8的，有的同学帮忙测试下,测试代码为原文里的 example.php<br /><br />结果模块： http://60.190.243.111/superhei/xs...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="http://superhei.blogbus.com/logs/17657028.html">[PSTZine_0x01]</a> 2008-03-25</div><div><a href="http://superhei.blogbus.com/logs/10916401.html">7th OWASP AppSec Conference - San Jose 2007/Agenda</a> 2007-11-22</div><div><a href="http://superhei.blogbus.com/logs/10012272.html">pw6的一个url转跳[BUG?]</a> 2007-09-24</div><div><a href="http://superhei.blogbus.com/logs/7400000.html">Turning Firefox to an Ethical Hacking Platform</a> 2007-08-04</div><div><a href="http://superhei.blogbus.com/logs/5193416.html">OWASP_Papers/Jeopardy_in_Web_2_0</a> 2007-04-28</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://del.icio.us/post?v=4&noui&jump=close&url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F22568721.html&title=Bypassing+script+filters+with+variable-width+encodings">Del.icio.us</a></span></div><br><br><div class="sysmsg"><b><a href="http://www.gov.cn/zwgk/2008-05/18/content_981560.htm">深切哀悼四川汶川大地震遇难同胞</a></b><br><br></div>]]></description>
   <link>http://superhei.blogbus.com/logs/22568721.html</link>
   <author>superhei</author>
   <pubDate>Mon, 09 Jun 2008 12:03:58 +0800</pubDate>
  </item>
  <item>
   <title>A New Class of Vulnerability in Oracle: Lateral SQL Injection</title>
   <description><![CDATA[avid Litchfield 在他的blog上写了一些关于他pp《A New Class of Vulnerability in Oracle: Lateral SQL Injection》的一些说明：<br /><br />http://www.davidlitchfield.com/blog/archives/00000042.htm<br /><br />里面有个8挂就是：<br /><br />5) This paper is mostly academic<br />No, it's n...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="http://superhei.blogbus.com/logs/19956354.html">rgod:i am not dead~~</a> 2008-04-29</div><div><a href="http://superhei.blogbus.com/logs/15775419.html">[tool]Dzender</a> 2008-02-22</div><div><a href="http://superhei.blogbus.com/logs/11412189.html">Request变量与csrf</a> 2007-12-02</div><div><a href="http://superhei.blogbus.com/logs/4652162.html">whos is stupid!!!</a> 2007-03-01</div><div><a href="http://superhei.blogbus.com/logs/3911727.html">动态链接库 动态连接库 dll 下载</a> 2006-11-26</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://del.icio.us/post?v=4&noui&jump=close&url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F21533832.html&title=A+New+Class+of+Vulnerability+in+Oracle%3A+Lateral+SQL+Injection">Del.icio.us</a></span></div><br><br><div class="sysmsg"><b><a href="http://www.gov.cn/zwgk/2008-05/18/content_981560.htm">深切哀悼四川汶川大地震遇难同胞</a></b><br><br></div>]]></description>
   <link>http://superhei.blogbus.com/logs/21533832.html</link>
   <author>superhei</author>
   <pubDate>Sat, 24 May 2008 16:34:54 +0800</pubDate>
  </item>
  <item>
   <title>一个图片引起的8挂</title>
   <description><![CDATA[<br /><br />在SWI的大牛褚诚云的blog看到一则消息：http://blog.csdn.net/chengyun_chu/archive/2008/02/22/2112375.aspx<br /><br />其中有个图片很有意思http://p.blog.csdn.net/images/p_blog_csdn_net/chengyun_chu/312585/o_googlesecurityreport.JPG<br />这个还是google去年6月的统计。<br /><br />估计是...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="http://superhei.blogbus.com/logs/6559707.html">2007-07-09</a> 2007-07-09</div><div><a href="http://superhei.blogbus.com/logs/4980188.html">老外给7jj的e文名字</a> 2007-04-08</div><div><a href="http://superhei.blogbus.com/logs/4255503.html">WordPress wp-trackback.php漏洞分析</a> 2007-01-10</div><div><a href="http://superhei.blogbus.com/logs/3488665.html">wmiexec.asp[原创]</a> 2006-10-05</div><div><a href="http://superhei.blogbus.com/logs/2003984.html">如果你没有代码(Q/A)</a> 2006-03-04</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://del.icio.us/post?v=4&noui&jump=close&url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F21532827.html&title=%E4%B8%80%E4%B8%AA%E5%9B%BE%E7%89%87%E5%BC%95%E8%B5%B7%E7%9A%848%E6%8C%82">Del.icio.us</a></span></div><br><br><div class="sysmsg"><b><a href="http://www.gov.cn/zwgk/2008-05/18/content_981560.htm">深切哀悼四川汶川大地震遇难同胞</a></b><br><br></div>]]></description>
   <link>http://superhei.blogbus.com/logs/21532827.html</link>
   <author>superhei</author>
   <pubDate>Sat, 24 May 2008 16:32:29 +0800</pubDate>
  </item>
  <item>
   <title>Time-Based Blind SQL Injection with Heavy Queries</title>
   <description><![CDATA[Time-Based Blind SQL Injection with Heavy Queries<br /><br />http://www.microsoft.com/technet/community/columns/secmvp/sv0907.mspx<br /><br />原理：<br /><br />With these two queries we can access all the information stored in the database measuring the t...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="http://superhei.blogbus.com/logs/11257167.html">xss/csrf in penetration test</a> 2007-11-29</div><div><a href="http://superhei.blogbus.com/logs/4652162.html">whos is stupid!!!</a> 2007-03-01</div><div><a href="http://superhei.blogbus.com/logs/4594452.html">Metasploit的EvalPayload模块</a> 2007-02-23</div><div><a href="http://superhei.blogbus.com/logs/3411130.html">偶像</a> 2006-09-25</div><div><a href="http://superhei.blogbus.com/logs/2003984.html">如果你没有代码(Q/A)</a> 2006-03-04</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://del.icio.us/post?v=4&noui&jump=close&url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F21410547.html&title=Time-Based+Blind+SQL+Injection+with+Heavy+Queries">Del.icio.us</a></span></div><br><br><div class="sysmsg"><b><a href="http://www.gov.cn/zwgk/2008-05/18/content_981560.htm">深切哀悼四川汶川大地震遇难同胞</a></b><br><br></div>]]></description>
   <link>http://superhei.blogbus.com/logs/21410547.html</link>
   <author>superhei</author>
   <pubDate>Thu, 22 May 2008 21:55:49 +0800</pubDate>
  </item>
  <item>
   <title>[zz]Microsoft word javascript execution</title>
   <description><![CDATA[http://marc.info/?l=bugtraq&amp;m=121121432823704&amp;w=2<br /><br />比较有意思：<br /><br />&lt;html&gt;<br />&lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&gt;&lt;param name=url  value=javascript:alert('Prueba')&gt;&lt;/OBJECT&gt;&nbsp;不过测试了...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="http://superhei.blogbus.com/logs/11182869.html">Bypass htmlentities</a> 2007-11-27</div><div><a href="http://superhei.blogbus.com/logs/10582982.html">create_function</a> 2007-11-01</div><div><a href="http://superhei.blogbus.com/logs/5193416.html">OWASP_Papers/Jeopardy_in_Web_2_0</a> 2007-04-28</div><div><a href="http://superhei.blogbus.com/logs/3488665.html">wmiexec.asp[原创]</a> 2006-10-05</div><div><a href="http://superhei.blogbus.com/logs/2232209.html">Windows平台上的mysql安全</a> 2006-04-09</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://del.icio.us/post?v=4&noui&jump=close&url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F21306189.html&title=%5Bzz%5DMicrosoft+word+javascript+execution">Del.icio.us</a></span></div><br><br><div class="sysmsg"><b><a href="http://www.gov.cn/zwgk/2008-05/18/content_981560.htm">深切哀悼四川汶川大地震遇难同胞</a></b><br><br></div>]]></description>
   <link>http://superhei.blogbus.com/logs/21306189.html</link>
   <author>superhei</author>
   <pubDate>Wed, 21 May 2008 00:04:57 +0800</pubDate>
  </item>
 </channel>
</rss>
