导航

Web安全手册

业精于勤而荒于嬉 行成于思而毁于随

[置顶] 悲剧啊

[置顶] 技术过关游戏

[置顶] 免责声明

命令行下一种新的加帐号的方法

今天研究了一下用户控制面板文件nusrmgr.cpl,发现调用的是Shell.Users来加用户,它还同时调用了 wscript.shell、Shell.Application、Shell.LocalMachine这三个组件。不过加用户的话,这一个 Shell.Users就足够了。那么可能在删掉了net.exe和不用adsi之外,这也可能是一种新的加用户的方法。

Orcale TNS listener support for nmap

Trace注: NMAP最新版支持判断Oracle TNS Listener版本。

Remote CMD With WMI[2009-6-26 更新,请下载新版本覆盖。]

NP写的一个vbs,渗透内网用的。

JCZ3 0.2 BETA

很久以前的东西了.这份是用C++写的...因为JC已经逝去了,升天了~z3又XX了10个月..没办法完成了.

pmaPWN! - phpMyAdmin Code Injection RCE Scanner & Exploit

phpMyAdmin Code Injection RCE Scanner & Exploit
 

Scanning Windows Deeper With the Nmap Scanning Engine

Scanning Windows Deeper With the Nmap Scanning Engine

QQmail Multiple Xss Vulnerabilities

2009.4.17-18发现漏洞
2009.4.18 通知腾讯安全中心
2009.5.x 修补以上漏洞

phpMyAdmin Remote Code Execution Proof of Concept

All the documentation you need is in the script comments. I recommend you to go through it, before you actually run the script.

After reading the public advisory and patched code, and playing around for a while, I managed to have a working PoC bash script. The script will allow you to remotely run shell commands and PHP code against vulnerable targets. Although in principle the vulnerability sounds quite simple, it actually took me a while to go from advisory to working attack code.

I’m providing the script with the hope that it will help pentesters and security researchers. Please only test the script against your own systems, or systems you have been given permission to pentest! Don’t be evil, it’s not worth it.

使用低权限Oracle数据库账户得到OS访问权限

使用低权限Oracle数据库账户得到OS访问权限

Core impact 7.5

download Sheriff SDK from google i dont have its but i will post that soon
actuly i have version 2.2 but i cant find sysgen.ini file in this 2.2 version if i will got this then i will post its no more question if you have any problam for activation do or try its by yr self because i am not inventer of this cracking its allready cracked by some another intelegent person thanks

 

分页:«123456789101112131415»

Powered By Z-Blog .Theme from Google黑板报 By Washun

Copyright 2008-2009 Pcsec.org. Some Rights Reserved.苏ICP备08110306号

Search

图标汇集

  • 本站支持WAP访问
  • 订阅本站的 RSS 2.0 新闻聚合