<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>FreeXploiT - 溢出研究</title><link>http://blog.csdn.net/freexploit/category/56806.aspx</link><description>溢出研究</description><dc:language>zh-CN</dc:language><lastUpdateTime>Fri, 11 Jan 2008 22:43:21 GMT</lastUpdateTime><ttl>60</ttl><item><dc:creator>FreeXploiT</dc:creator><title>FreeXploiT 成立三年感言！</title><link>http://blog.csdn.net/freexploit/archive/2008/01/11/2038442.aspx</link><pubDate>Fri, 11 Jan 2008 22:43:00 GMT</pubDate><guid>http://blog.csdn.net/freexploit/archive/2008/01/11/2038442.aspx</guid><wfw:comment>http://blog.csdn.net/freexploit/comments/2038442.aspx</wfw:comment><comments>http://blog.csdn.net/freexploit/archive/2008/01/11/2038442.aspx#Feedback</comments><slash:comments>8</slash:comments><wfw:commentRss>http://blog.csdn.net/freexploit/comments/commentRss/2038442.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=2038442</trackback:ping><description>FreeXploiT&lt;img src ="http://blog.csdn.net/freexploit/aggbug/2038442.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>FreeXploiT</dc:creator><title>【紧急通告】马云否认支付宝出现漏洞 淘宝大量用户现金被盗 今日支付宝强制升级补丁</title><link>http://blog.csdn.net/freexploit/archive/2007/02/07/1504953.aspx</link><pubDate>Wed, 07 Feb 2007 23:59:00 GMT</pubDate><guid>http://blog.csdn.net/freexploit/archive/2007/02/07/1504953.aspx</guid><wfw:comment>http://blog.csdn.net/freexploit/comments/1504953.aspx</wfw:comment><comments>http://blog.csdn.net/freexploit/archive/2007/02/07/1504953.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/freexploit/comments/commentRss/1504953.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=1504953</trackback:ping><description>在支付宝密码输入控件中存在一个远程代码执行漏洞，远程攻击者可利用此漏洞在被攻击者系统上执行任意代码，进而可安装木马以及间谍程序，窃取相关敏感信息比如淘宝帐号/密码，或者支付宝帐号/密码。
&lt;img src ="http://blog.csdn.net/freexploit/aggbug/1504953.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>FreeXploiT</dc:creator><title>迎接2007元旦QQ漏洞（远程可执行） </title><link>http://blog.csdn.net/freexploit/archive/2007/01/03/1473159.aspx</link><pubDate>Wed, 03 Jan 2007 21:26:00 GMT</pubDate><guid>http://blog.csdn.net/freexploit/archive/2007/01/03/1473159.aspx</guid><wfw:comment>http://blog.csdn.net/freexploit/comments/1473159.aspx</wfw:comment><comments>http://blog.csdn.net/freexploit/archive/2007/01/03/1473159.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/freexploit/comments/commentRss/1473159.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=1473159</trackback:ping><description>QQ是由Tencent公司开发的一个IM软件，在中国有着非常广泛的用户。DSW Avert在200612.31发现了QQ的几个0day漏洞，并通知了QQ官方。QQ在2007.1.1进行了升级。事实上，在此之前，幻影旅团(ph4nt0m)的axis就已经发现了这些漏洞，出于一些原因未曾公布，现在漏洞被公开了，所以将细节和可利用的POC公布如下：&lt;img src ="http://blog.csdn.net/freexploit/aggbug/1473159.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>FreeXploiT</dc:creator><title>又一个0day EXP出现 【希望大家不要用来攻击网站】</title><link>http://blog.csdn.net/freexploit/archive/2006/05/24/752368.aspx</link><pubDate>Wed, 24 May 2006 10:06:00 GMT</pubDate><guid>http://blog.csdn.net/freexploit/archive/2006/05/24/752368.aspx</guid><wfw:comment>http://blog.csdn.net/freexploit/comments/752368.aspx</wfw:comment><comments>http://blog.csdn.net/freexploit/archive/2006/05/24/752368.aspx#Feedback</comments><slash:comments>4</slash:comments><wfw:commentRss>http://blog.csdn.net/freexploit/comments/commentRss/752368.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=752368</trackback:ping><description>我连忙安慰kaka说：“kaka，您别着急，您说说看，您丢的0day是啥样的，说不定我能帮您找到呢！”

         kaka答道：“我的0day是iis的，通杀iis5.0,iis 6.0。iis 默认配置，是个未公布的，成功率达到100%"

        她又补充着说道：“有时候端口号输入错误，还能搞定3389呢。”

&lt;img src ="http://blog.csdn.net/freexploit/aggbug/752368.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>FreeXploiT</dc:creator><title>MS Windows Services Access List Checker / Modifier PoC</title><link>http://blog.csdn.net/freexploit/archive/2006/02/03/591253.aspx</link><pubDate>Fri, 03 Feb 2006 12:07:00 GMT</pubDate><guid>http://blog.csdn.net/freexploit/archive/2006/02/03/591253.aspx</guid><wfw:comment>http://blog.csdn.net/freexploit/comments/591253.aspx</wfw:comment><comments>http://blog.csdn.net/freexploit/archive/2006/02/03/591253.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/freexploit/comments/commentRss/591253.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=591253</trackback:ping><description> * usage:
 * You should execute this tool without Admin privileges on the target system
 * using for example an user account
 *
 * srvcheck.exe -l              - show vulnerable services
 * srvcheck.exe -m Service PATH - modify service configuration (install backdoor)
 *
 * Example for Windows XP SP2 computer
&lt;img src ="http://blog.csdn.net/freexploit/aggbug/591253.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>FreeXploiT</dc:creator><title>BitComet_Torrent_URI处理缓冲区溢出漏洞分析备忘</title><link>http://blog.csdn.net/freexploit/archive/2006/01/25/587917.aspx</link><pubDate>Wed, 25 Jan 2006 02:21:00 GMT</pubDate><guid>http://blog.csdn.net/freexploit/archive/2006/01/25/587917.aspx</guid><wfw:comment>http://blog.csdn.net/freexploit/comments/587917.aspx</wfw:comment><comments>http://blog.csdn.net/freexploit/archive/2006/01/25/587917.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/freexploit/comments/commentRss/587917.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=587917</trackback:ping><description>安全检查原理：
在函数开始地方，分配局部变量(记为szWinExecParam[0x414])后即设置szWinExecParam的最后4字节为一随机值，然后在函数ret前检查这个值是否被更改，如更改表示被溢出直接弹出警告对话框并退出进程。由于栈溢出覆盖ret地址前必然要完全覆盖完局部变量和ebp，因此此种检查机制简单有效，值得推荐。&lt;img src ="http://blog.csdn.net/freexploit/aggbug/587917.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>FreeXploiT</dc:creator><title>[分享]QQ对字库没有严格过滤导致你崩溃漏洞 </title><link>http://blog.csdn.net/freexploit/archive/2005/08/27/466563.aspx</link><pubDate>Sat, 27 Aug 2005 19:49:00 GMT</pubDate><guid>http://blog.csdn.net/freexploit/archive/2005/08/27/466563.aspx</guid><wfw:comment>http://blog.csdn.net/freexploit/comments/466563.aspx</wfw:comment><comments>http://blog.csdn.net/freexploit/archive/2005/08/27/466563.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/freexploit/comments/commentRss/466563.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=466563</trackback:ping><description>详细描述
QQ对字库过滤不严,黑客如果使用精心构造的字符可以导致你崩溃.&lt;img src ="http://blog.csdn.net/freexploit/aggbug/466563.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>FreeXploiT</dc:creator><title>Metasploit Framework all part 1-3</title><link>http://blog.csdn.net/freexploit/archive/2005/06/26/403247.aspx</link><pubDate>Sun, 26 Jun 2005 03:11:00 GMT</pubDate><guid>http://blog.csdn.net/freexploit/archive/2005/06/26/403247.aspx</guid><wfw:comment>http://blog.csdn.net/freexploit/comments/403247.aspx</wfw:comment><comments>http://blog.csdn.net/freexploit/archive/2005/06/26/403247.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/freexploit/comments/commentRss/403247.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=403247</trackback:ping><description>Metasploit Framework all part 1-3&lt;img src ="http://blog.csdn.net/freexploit/aggbug/403247.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>FreeXploiT</dc:creator><title>强大溢出工具包：Metasploit命令行下的使用 （转至77169）</title><link>http://blog.csdn.net/freexploit/archive/2005/06/22/400711.aspx</link><pubDate>Wed, 22 Jun 2005 23:26:00 GMT</pubDate><guid>http://blog.csdn.net/freexploit/archive/2005/06/22/400711.aspx</guid><wfw:comment>http://blog.csdn.net/freexploit/comments/400711.aspx</wfw:comment><comments>http://blog.csdn.net/freexploit/archive/2005/06/22/400711.aspx#Feedback</comments><slash:comments>3</slash:comments><wfw:commentRss>http://blog.csdn.net/freexploit/comments/commentRss/400711.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=400711</trackback:ping><description>强大溢出工具包：Metasploit命令行下的使用 （转至77169）&lt;img src ="http://blog.csdn.net/freexploit/aggbug/400711.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>FreeXploiT</dc:creator><title>已经失效的QQ exploit 喜欢就拿来研究看看吧 【ALLyeSNO】</title><link>http://blog.csdn.net/freexploit/archive/2005/06/14/394174.aspx</link><pubDate>Tue, 14 Jun 2005 15:24:00 GMT</pubDate><guid>http://blog.csdn.net/freexploit/archive/2005/06/14/394174.aspx</guid><wfw:comment>http://blog.csdn.net/freexploit/comments/394174.aspx</wfw:comment><comments>http://blog.csdn.net/freexploit/archive/2005/06/14/394174.aspx#Feedback</comments><slash:comments>1</slash:comments><wfw:commentRss>http://blog.csdn.net/freexploit/comments/commentRss/394174.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=394174</trackback:ping><description>已经失效的QQ exploit 喜欢就拿来研究看看吧&lt;img src ="http://blog.csdn.net/freexploit/aggbug/394174.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>FreeXploiT</dc:creator><title>浅析mcafee的“缓冲区溢出保护”及绕过方法【安焦Leven】</title><link>http://blog.csdn.net/freexploit/archive/2005/04/13/345259.aspx</link><pubDate>Wed, 13 Apr 2005 03:39:00 GMT</pubDate><guid>http://blog.csdn.net/freexploit/archive/2005/04/13/345259.aspx</guid><wfw:comment>http://blog.csdn.net/freexploit/comments/345259.aspx</wfw:comment><comments>http://blog.csdn.net/freexploit/archive/2005/04/13/345259.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/freexploit/comments/commentRss/345259.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=345259</trackback:ping><description>浅析mcafee的“缓冲区溢出保护”及绕过方法【安焦Leven】&lt;img src ="http://blog.csdn.net/freexploit/aggbug/345259.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>FreeXploiT</dc:creator><title>iis和apache的exploit一个是kevin1986写的 一个是我写的 呵呵</title><link>http://blog.csdn.net/freexploit/archive/2005/04/03/335204.aspx</link><pubDate>Sun, 03 Apr 2005 09:41:00 GMT</pubDate><guid>http://blog.csdn.net/freexploit/archive/2005/04/03/335204.aspx</guid><wfw:comment>http://blog.csdn.net/freexploit/comments/335204.aspx</wfw:comment><comments>http://blog.csdn.net/freexploit/archive/2005/04/03/335204.aspx#Feedback</comments><slash:comments>1</slash:comments><wfw:commentRss>http://blog.csdn.net/freexploit/comments/commentRss/335204.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=335204</trackback:ping><description>iis和apache的exploit一个是kevin1986写的 一个是我写的 呵呵&lt;img src ="http://blog.csdn.net/freexploit/aggbug/335204.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>FreeXploiT</dc:creator><title>【例子】WIN平台缓冲溢出程序编写</title><link>http://blog.csdn.net/freexploit/archive/2005/03/30/334260.aspx</link><pubDate>Wed, 30 Mar 2005 17:04:00 GMT</pubDate><guid>http://blog.csdn.net/freexploit/archive/2005/03/30/334260.aspx</guid><wfw:comment>http://blog.csdn.net/freexploit/comments/334260.aspx</wfw:comment><comments>http://blog.csdn.net/freexploit/archive/2005/03/30/334260.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/freexploit/comments/commentRss/334260.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=334260</trackback:ping><description>【例子】WIN平台缓冲溢出程序编写&lt;img src ="http://blog.csdn.net/freexploit/aggbug/334260.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>FreeXploiT</dc:creator><title>【原理】UNF &amp;&amp; pr1 present: Writing Linux/x86 shellcodes for dum dums.</title><link>http://blog.csdn.net/freexploit/archive/2005/03/30/334232.aspx</link><pubDate>Wed, 30 Mar 2005 16:28:00 GMT</pubDate><guid>http://blog.csdn.net/freexploit/archive/2005/03/30/334232.aspx</guid><wfw:comment>http://blog.csdn.net/freexploit/comments/334232.aspx</wfw:comment><comments>http://blog.csdn.net/freexploit/archive/2005/03/30/334232.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/freexploit/comments/commentRss/334232.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=334232</trackback:ping><description>【原理】UNF &amp;&amp; pr1 present: Writing Linux/x86 shellcodes for dum dums.&lt;img src ="http://blog.csdn.net/freexploit/aggbug/334232.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>FreeXploiT</dc:creator><title>【原理】浅析格式化串漏洞</title><link>http://blog.csdn.net/freexploit/archive/2005/03/30/334212.aspx</link><pubDate>Wed, 30 Mar 2005 15:52:00 GMT</pubDate><guid>http://blog.csdn.net/freexploit/archive/2005/03/30/334212.aspx</guid><wfw:comment>http://blog.csdn.net/freexploit/comments/334212.aspx</wfw:comment><comments>http://blog.csdn.net/freexploit/archive/2005/03/30/334212.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/freexploit/comments/commentRss/334212.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=334212</trackback:ping><description>【原理】浅析格式化串漏洞&lt;img src ="http://blog.csdn.net/freexploit/aggbug/334212.aspx" width = "1" height = "1" /&gt;</description></item></channel></rss>