摘要:
// 0x000 This may be a "bomb was set"
// 0x001 Please, do not try to run this process.
// 0x002 Otherwise, all the consequences will not be responsible for !
// 0x003 Perhaps this is not a new game . 阅读全文
摘要:
4月8号microsoft再次发布了一个系统内核的补丁(KB941693),
微软对该漏洞的描述为: 此安全更新解决 Windows 内核中一个秘密
报告的漏洞。 成功利用此漏洞的本地攻击者可以完全控制受影响的
系统。 攻击者可随后安装程序;查看、更改或删除数据;或者创建
新帐户。这是用于 Windows 2000、Windows XP、Windows Server 2003、
Windows Vista 和 Windows Server 2008 所有受支持版本的重要安全
更新。此安全更新通过修改 Windows 内核验证从用户模式传递过来的
输入的方式来解决此漏洞。
从这个介绍中我们看到这个漏洞影响非常广,从2000到2008。为了
能一睹这个漏洞的细节,我分析了ms08-025的补丁,发现该漏洞存在于 阅读全文
摘要:
主题: [NT] MailEnable Professional/Enterprise Multiple Vulnerabilities The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.s... 阅读全文
摘要:
Inside an enterprise lives an IT security professional responsible for website security. He takes his job seriously because if his employer’s websites get hacked, he gets the late night call from the ... 阅读全文
摘要:
Silverlight and the rich client browser By Dino Esposito, Dr. Dobb's Journal 09, 2008 URL:http://www.ddj.com/security/206902613 size=2 width="100%" align=center> Traditional Web applications are... 阅读全文
摘要:
For the past few weeks, I've been doing some pen-testing for a friend, after hours. His client is an Internet business with no staging/qa systems, so I was testing production web apps. For one particu... 阅读全文