Posts
Token Kidnapping Windows 2008 PoC exploit
鬼仔注:发过 MS Windows 2003 Token Kidnapping Local Exploit PoC ,这次是2008.
Now it's time for Windows 2008 exploit (it should work on Windows 2003 too)
You will see that the super secure IIS 7 can be owned, too weak by default :)
You can find the PoC exploit here http://www.argeniss.com/research/Churrasco2.zip
Enjoy.
利用MS08-058攻击Google
用显卡算密码:有意思的“暴力”密码破解工具
Php Code Audits的方向
Nuke ET < = 3.4 (fckeditor) Remote Arbitrary File Upload Exploit
Vulnerable:
Tru-Zone NukeET 3.4
FCKeditor FCKeditor 2.4.3
FCKeditor FCKeditor 2.0 rc3
FCKeditor FCKeditor 2.0 RC2
FCKeditor FCKeditor 2.3 beta
FCKeditor FCKeditor 2.2
OWASP WebGoat + WebScarab
鬼仔 注:看到 TR 那里放了几个链接,这里来个详细的,我英文很烂,就不翻译了。
一、 OWASP WebScarab Project
a tool for performing all types of security testing on web applications and web services
下载地址: OWASP Source Code Center at Sourceforge
安装方法:
Linux: java -jar ./webscarab-selfcontained-[numbers].jar
Windows: double-click the installer jar file
A Mac OS X package of the latest version can usually be found on Corsaire's download page .
You can also try the Java Web Start version , which was signed by Rogan Dawes.