<?xml version="1.0" encoding="utf-8"?><?xml-stylesheet href='http://feed.haik8.com/styles/feedsky7.xsl' type='text/xsl' ?><!--这是一个由Feedsy提供技术支持的Feed，为了提高读者阅读的体验，以及满足用户美化自己Feed的需要，我们设计了多种精美的Feed模板，提供给大家选择，所有最终呈现出来的样式，皆由用户自愿选择使用，未经许可，任何团体和个人，请不要擅自修改样式或者盗用，这是对于用户选择权的尊重。--><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:fs="http://www.feedsky.com/namespace/feed" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0"><channel><atom:link href="http://feed.haik8.com" type="application/rss+xml" rel="self"></atom:link><fs:self_link href="http://feed.feedsky.com/sbgl" type="application/rss+xml"></fs:self_link><lastBuildDate>Sat, 26 Nov 2011 05:05:11 GMT</lastBuildDate><title>骇客吧</title><description>程序源码,病毒教学,程序开发,免费资源,免费教程.骇客,骇客教学,骇客代码,骇客资源,程序源码,病毒教学,程序开发,免费教程,hack,virus,kill,free,code</description><image><url>http://www.feedsky.com/feed/sbgl/sc/gif</url><title>骇客吧</title><link>http://www.haik8.com/</link></image><link>http://www.haik8.com/</link><copyright>Copyright(C) haik8.com</copyright><pubDate>Sat, 26 Nov 2011 07:12:19 GMT</pubDate><item><title>狂盗小说小偷GETshell漏洞</title><link>http://www.haik8.com/haikejishu/2011-11-26/soft_11330.html</link><description>必须开启缓存才能利用 先看代码book.php$kd_cachedir = &amp;amp;quot;./cache&amp;amp;quot;;  if($kd_book_cache==&amp;amp;quot;ture&amp;amp;quot;){//缓存必须开启   $lastflesh = @filemtime($kd_cachedir.&amp;amp;quot;/book$shuid.html&amp;amp;quot;);  // echo $lastflesh;     if(!file_&lt;img src=&quot;http://www1.feedsky.com/t1/581163861/sbgl/feedsky/s.gif?r=http://www.haik8.com/haikejishu/2011-11-26/soft_11330.html&quot; border=&quot;0&quot; height=&quot;0&quot; width=&quot;0&quot; style=&quot;position:absolute&quot; /&gt;</description><category>最新漏洞</category><pubDate>Sat, 26 Nov 2011 13:05:11 +0800</pubDate><guid isPermaLink="false">http://www.haik8.com/haikejishu/2011-11-26/soft_11330.html</guid><fs:srclink>http://www.haik8.com/haikejishu/2011-11-26/soft_11330.html</fs:srclink><fs:srcfeed>http://www.haik8.com/e/web/?type=rss2&amp;classid=0</fs:srcfeed><fs:itemid>feedsky/sbgl/~8077107/581163861/5776797</fs:itemid></item><item><title>要哇导航网建站系统 v3.2 注入漏洞</title><link>http://www.haik8.com/haikejishu/2011-11-26/soft_11329.html</link><description>继续看代码。。 search.php$keyword=$_GET&amp;amp;#039;keyword&amp;amp;#039;;/*$keyword = trim(iconv(&amp;amp;#039;UTF-8&amp;amp;#039;, &amp;amp;#039;GBK&amp;amp;#039;, (empty($_GET&amp;amp;#039;keyword&amp;amp;#039;)) ? &amp;amp;#039;&amp;amp;#039; : $_GET&amp;amp;#039;keyword&amp;amp;#039;));*/if (empty($keyword)){ ?&amp;amp;gt;&amp;amp;amp;hellip;省略若干&amp;amp;&lt;img src=&quot;http://www1.feedsky.com/t1/581163862/sbgl/feedsky/s.gif?r=http://www.haik8.com/haikejishu/2011-11-26/soft_11329.html&quot; border=&quot;0&quot; height=&quot;0&quot; width=&quot;0&quot; style=&quot;position:absolute&quot; /&gt;</description><category>最新漏洞</category><pubDate>Sat, 26 Nov 2011 13:01:57 +0800</pubDate><guid isPermaLink="false">http://www.haik8.com/haikejishu/2011-11-26/soft_11329.html</guid><fs:srclink>http://www.haik8.com/haikejishu/2011-11-26/soft_11329.html</fs:srclink><fs:srcfeed>http://www.haik8.com/e/web/?type=rss2&amp;classid=0</fs:srcfeed><fs:itemid>feedsky/sbgl/~8077107/581163862/5776797</fs:itemid></item><item><title>126cms后台登陆注入漏洞</title><link>http://www.haik8.com/haikejishu/2011-11-26/soft_11328.html</link><description>看代码。。&amp;amp;amp;hellip;&amp;amp;amp;hellip;若干&amp;amp;amp;hellip;&amp;amp;amp;hellip;if( !$postdb&amp;amp;quot;userid&amp;amp;quot; || !$postdb&amp;amp;quot;pwd&amp;amp;quot; ){ echo &amp;amp;quot;&amp;amp;lt;div align=\&amp;amp;quot;center\&amp;amp;quot; class=\&amp;amp;quot;style1\&amp;amp;quot;&amp;amp;gt;&amp;amp;quot;; echo &amp;amp;quot;您输入的用户名或密码有误！!!&amp;amp;quot;; echo &amp;amp;quot;&amp;amp;l&lt;img src=&quot;http://www1.feedsky.com/t1/581163863/sbgl/feedsky/s.gif?r=http://www.haik8.com/haikejishu/2011-11-26/soft_11328.html&quot; border=&quot;0&quot; height=&quot;0&quot; width=&quot;0&quot; style=&quot;position:absolute&quot; /&gt;</description><category>最新漏洞</category><pubDate>Sat, 26 Nov 2011 12:59:20 +0800</pubDate><guid isPermaLink="false">http://www.haik8.com/haikejishu/2011-11-26/soft_11328.html</guid><fs:srclink>http://www.haik8.com/haikejishu/2011-11-26/soft_11328.html</fs:srclink><fs:srcfeed>http://www.haik8.com/e/web/?type=rss2&amp;classid=0</fs:srcfeed><fs:itemid>feedsky/sbgl/~8077107/581163863/5776797</fs:itemid></item><item><title>星网互动建站系统上传漏洞</title><link>http://www.haik8.com/haikejishu/2011-11-23/soft_11327.html</link><description>星网互动建站系统上传漏洞出现在INC文件夹下的upfile_flash.asp中我们可以直接用明小子自带的动感上传 虽然这个洞比较低级,但是站有很多,危害很大,以下是upfile_flash.asp的源码 &amp;amp;lt;!--#include file=&amp;amp;quot;upload_wj.inc&amp;amp;quot;-&lt;img src=&quot;http://www1.feedsky.com/t1/581163864/sbgl/feedsky/s.gif?r=http://www.haik8.com/haikejishu/2011-11-23/soft_11327.html&quot; border=&quot;0&quot; height=&quot;0&quot; width=&quot;0&quot; style=&quot;position:absolute&quot; /&gt;</description><category>最新漏洞</category><pubDate>Wed, 23 Nov 2011 11:15:04 +0800</pubDate><guid isPermaLink="false">http://www.haik8.com/haikejishu/2011-11-23/soft_11327.html</guid><fs:srclink>http://www.haik8.com/haikejishu/2011-11-23/soft_11327.html</fs:srclink><fs:srcfeed>http://www.haik8.com/e/web/?type=rss2&amp;classid=0</fs:srcfeed><fs:itemid>feedsky/sbgl/~8077107/581163864/5776797</fs:itemid></item><item><title>万博企业网站管理系统注入漏洞</title><link>http://www.haik8.com/haikejishu/2011-11-23/soft_11326.html</link><description>这个注入漏洞发生在html/MemberLogin.asp文件里，在Include下有NoSqlHack.Asp文件也没调用，呵呵，就有了我们利用的地方了。 MemberLogin.asp源码如下： &amp;amp;lt;%@LANGUAGE=&amp;amp;quot;VBSCRIPT&amp;amp;quot; CODEPAGE=&amp;amp;quot;65001&amp;amp;quot;%&amp;amp;gt;&amp;amp;lt;% Option Explic&lt;img src=&quot;http://www1.feedsky.com/t1/581163865/sbgl/feedsky/s.gif?r=http://www.haik8.com/haikejishu/2011-11-23/soft_11326.html&quot; border=&quot;0&quot; height=&quot;0&quot; width=&quot;0&quot; style=&quot;position:absolute&quot; /&gt;</description><category>最新漏洞</category><pubDate>Wed, 23 Nov 2011 11:12:44 +0800</pubDate><guid isPermaLink="false">http://www.haik8.com/haikejishu/2011-11-23/soft_11326.html</guid><fs:srclink>http://www.haik8.com/haikejishu/2011-11-23/soft_11326.html</fs:srclink><fs:srcfeed>http://www.haik8.com/e/web/?type=rss2&amp;classid=0</fs:srcfeed><fs:itemid>feedsky/sbgl/~8077107/581163865/5776797</fs:itemid></item><item><title>2taoke2.2注入漏洞</title><link>http://www.haik8.com/haikejishu/2011-11-23/soft_11325.html</link><description>if($_REQUEST){                if(get_magic_quotes_gpc()){                        $_REQUEST = tao_strip($_REQUEST);                }else{                        $_POST = tao_check($_POST);&lt;img src=&quot;http://www1.feedsky.com/t1/581163866/sbgl/feedsky/s.gif?r=http://www.haik8.com/haikejishu/2011-11-23/soft_11325.html&quot; border=&quot;0&quot; height=&quot;0&quot; width=&quot;0&quot; style=&quot;position:absolute&quot; /&gt;</description><category>最新漏洞</category><pubDate>Wed, 23 Nov 2011 10:57:53 +0800</pubDate><guid isPermaLink="false">http://www.haik8.com/haikejishu/2011-11-23/soft_11325.html</guid><fs:srclink>http://www.haik8.com/haikejishu/2011-11-23/soft_11325.html</fs:srclink><fs:srcfeed>http://www.haik8.com/e/web/?type=rss2&amp;classid=0</fs:srcfeed><fs:itemid>feedsky/sbgl/~8077107/581163866/5776797</fs:itemid></item><item><title>迅雷看看播放器堆栈溢出漏洞</title><link>http://www.haik8.com/haikejishu/2011-11-19/soft_11324.html</link><description>#!/usr/bin/env pythonprint &amp;amp;quot;&amp;amp;quot;&amp;amp;quot;#1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0#0      ___           ___           ___       ___       ___           ___     1#1     /\__&lt;img src=&quot;http://www1.feedsky.com/t1/581163867/sbgl/feedsky/s.gif?r=http://www.haik8.com/haikejishu/2011-11-19/soft_11324.html&quot; border=&quot;0&quot; height=&quot;0&quot; width=&quot;0&quot; style=&quot;position:absolute&quot; /&gt;</description><category>最新漏洞</category><pubDate>Sat, 19 Nov 2011 23:51:01 +0800</pubDate><guid isPermaLink="false">http://www.haik8.com/haikejishu/2011-11-19/soft_11324.html</guid><fs:srclink>http://www.haik8.com/haikejishu/2011-11-19/soft_11324.html</fs:srclink><fs:srcfeed>http://www.haik8.com/e/web/?type=rss2&amp;classid=0</fs:srcfeed><fs:itemid>feedsky/sbgl/~8077107/581163867/5776797</fs:itemid></item><item><title>tipask问答系统1.3注入漏洞</title><link>http://www.haik8.com/haikejishu/2011-11-19/soft_11323.html</link><description>这个漏洞蛮有趣的... 首先他把post和get给整合了..但是没在意到post和get的区别。。你get %27 gpc会影响吧。。 但是你post %27 gpc不会影响吧..呵呵看代码  function onsearch() {        $navtitle = &amp;amp;#039;搜索问题&amp;amp;#039;;&lt;img src=&quot;http://www1.feedsky.com/t1/581163868/sbgl/feedsky/s.gif?r=http://www.haik8.com/haikejishu/2011-11-19/soft_11323.html&quot; border=&quot;0&quot; height=&quot;0&quot; width=&quot;0&quot; style=&quot;position:absolute&quot; /&gt;</description><category>最新漏洞</category><pubDate>Sat, 19 Nov 2011 13:57:59 +0800</pubDate><guid isPermaLink="false">http://www.haik8.com/haikejishu/2011-11-19/soft_11323.html</guid><fs:srclink>http://www.haik8.com/haikejishu/2011-11-19/soft_11323.html</fs:srclink><fs:srcfeed>http://www.haik8.com/e/web/?type=rss2&amp;classid=0</fs:srcfeed><fs:itemid>feedsky/sbgl/~8077107/581163868/5776797</fs:itemid></item><item><title>AACMS2.4注入漏洞</title><link>http://www.haik8.com/haikejishu/2011-11-19/soft_11322.html</link><description>//user.action.php文本第98行elseif ($act==&amp;amp;#039;repassword&amp;amp;#039;) {                        $uid = $db-&amp;amp;gt;getOne(&amp;amp;quot;SELECT uid FROM $_SCtablepremembers WHERE email=&amp;amp;#039;$_REQUESTemail&amp;amp;#039;&amp;amp;quot;); //明显的。。。&lt;img src=&quot;http://www1.feedsky.com/t1/581163869/sbgl/feedsky/s.gif?r=http://www.haik8.com/haikejishu/2011-11-19/soft_11322.html&quot; border=&quot;0&quot; height=&quot;0&quot; width=&quot;0&quot; style=&quot;position:absolute&quot; /&gt;</description><category>最新漏洞</category><pubDate>Sat, 19 Nov 2011 13:53:22 +0800</pubDate><guid isPermaLink="false">http://www.haik8.com/haikejishu/2011-11-19/soft_11322.html</guid><fs:srclink>http://www.haik8.com/haikejishu/2011-11-19/soft_11322.html</fs:srclink><fs:srcfeed>http://www.haik8.com/e/web/?type=rss2&amp;classid=0</fs:srcfeed><fs:itemid>feedsky/sbgl/~8077107/581163869/5776797</fs:itemid></item><item><title>人人桌面挂马漏洞</title><link>http://www.haik8.com/haikejishu/2011-11-09/soft_11321.html</link><description>简要描述： 人人桌面程序对用户发表的日志中的html代码直接解析，造成攻击者有机会成功进行挂马攻击 详细说明： 在人人中发布一篇日志，期中含有html代码，在人人桌面中就会一网页方式解析这些代码，这样如果发布一&lt;img src=&quot;http://www1.feedsky.com/t1/581163870/sbgl/feedsky/s.gif?r=http://www.haik8.com/haikejishu/2011-11-09/soft_11321.html&quot; border=&quot;0&quot; height=&quot;0&quot; width=&quot;0&quot; style=&quot;position:absolute&quot; /&gt;</description><category>最新漏洞</category><pubDate>Wed, 09 Nov 2011 06:44:40 +0800</pubDate><guid isPermaLink="false">http://www.haik8.com/haikejishu/2011-11-09/soft_11321.html</guid><fs:srclink>http://www.haik8.com/haikejishu/2011-11-09/soft_11321.html</fs:srclink><fs:srcfeed>http://www.haik8.com/e/web/?type=rss2&amp;classid=0</fs:srcfeed><fs:itemid>feedsky/sbgl/~8077107/581163870/5776797</fs:itemid></item></channel></rss>
