<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Neeke &#187; MD5加密</title>
	<atom:link href="http://www.ineeke.com/tag/md5%e5%8a%a0%e5%af%86/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ineeke.com</link>
	<description>悄悄记录点点滴滴</description>
	<lastBuildDate>Sat, 07 Jan 2012 13:04:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>企业网站密码加密算法</title>
		<link>http://www.ineeke.com/archives/842/</link>
		<comments>http://www.ineeke.com/archives/842/#comments</comments>
		<pubDate>Sat, 24 Jan 2009 11:39:37 +0000</pubDate>
		<dc:creator>Neeke</dc:creator>
				<category><![CDATA[网络拾遗]]></category>
		<category><![CDATA[MD5加密]]></category>

		<guid isPermaLink="false">http://ineeke.com/archives/%e4%bc%81%e4%b8%9a%e7%bd%91%e7%ab%99%e5%af%86%e7%a0%81%e5%8a%a0%e5%af%86%e7%ae%97%e6%b3%95/</guid>
		<description><![CDATA[<p>呵呵，无意中看到某人在某网站发了个入侵新浪海口站的动画，感觉很搞笑。网站数据库用的是access，注入得到管理员帐号和密码，密码是&#8220;mz}6=&#62;9&#62;&#60;C=&#8221;，打眼一看就知道这肯定不是MD5加密的了，但是那人还是去CMD5上破解。找到了一个网站的管理后台，又说是怕警察叔叔请他去喝茶，就没再登陆。我说也是，你明文密码都没有，你拿什么登陆。最后还给自己打了个广告，说自己收费收徒弟。这教程把我看的笑的要死。</p><p><img title="" alt="" onload="ResizeImage(this,480)" src="http://www.ineeke.com/upload/2009/1/200901241943405046.jpg" /></p>
<table class="wumii-related-items" cellspacing="0" cellpadding="3" border="0"  style="clear: both;">
    
    <tr>
        <td colspan="5"><b><font size="-1"  style="display: block !important; padding: 20px 0 5px !important;">您可能也喜欢：</font></b></td>
    </tr>
    
        <tr>
                <td width="101" valign="top" style="padding: 5px !important; margin: 0 !important;">
                    <a target="_blank" title="入侵检测网站" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F464%2F&from=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F842%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 95px !important; height: 95px !important;" src="http://static.wumii.com/images/blogWidget/wordpress_default.gif" width="95px" height="95px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 101px !important; font: 12px/15px arial !important; height: 60px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">入侵检测网站</font>
                    </a>
                </td>
                <td width="101" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="MD5如今不堪一击" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F519%2F&from=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F842%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 95px !important; height: 95px !important;" src="http://static.wumii.com/images/blogWidget/wordpress_default.gif" width="95px" height="95px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 101px !important; font: 12px/15px arial !important; height: 60px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">MD5如今不堪一击</font>
                    </a>
                </td>
                <td width="101" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="教你压缩JavaScript代码" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F649%2F&from=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F842%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 95px !important; height: 95px !important;" src="http://static.wumii.com/images/blogWidget/wordpress_default.gif" width="95px" height="95px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 101px !important; font: 12px/15px arial !important; height: 60px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">教你压缩JavaScript代码</font>
                    </a>
                </td>
                <td width="101" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="JavaScript动态时钟" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F1224%2F&from=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F842%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 95px !important; height: 95px !important;" src="http://static.wumii.com/site_images/2011/05/06/7752177.png" width="95px" height="95px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 101px !important; font: 12px/15px arial !important; height: 60px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">JavaScript动态时钟</font>
                    </a>
                </td>
                <td width="101" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="JavaScript绘制笑脸" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F1222%2F&from=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F842%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 95px !important; height: 95px !important;" src="http://static.wumii.com/site_images/2011/06/07/11304948.png" width="95px" height="95px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 101px !important; font: 12px/15px arial !important; height: 60px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">JavaScript绘制笑脸</font>
                    </a>
                </td>
        </tr>
    
    <tr>
        <td colspan="5" align="right">
            <a style="text-decoration: none !important;" href="http://www.wumii.com/widget/relatedItems.htm" target="_blank" title="无觅相关文章插件">
                <font size="-1" color="#bbbbbb" style="display: block !important; font-family: arial !important; padding: 5px 0 !important; font-size: 12px !important; color: #bbb !important;">无觅</font>
            </a>
        </td>
    </tr>
</table>]]></description>
			<content:encoded><![CDATA[<p>呵呵，无意中看到某人在某网站发了个入侵新浪海口站的动画，感觉很搞笑。网站数据库用的是access，注入得到管理员帐号和密码，密码是“mz}6=>9><C=”，打眼一看就知道这肯定不是MD5加密的了，但是那人还是去CMD5上破解。找到了一个网站的管理后台，又说是怕警察叔叔请他去喝茶，就没再登陆。我说也是，你明文密码都没有，你拿什么登陆。最后还给自己打了个广告，说自己收费收徒弟。这教程把我看的笑的要死。<br />
其实这种密码可以说很常见的，尤其是在一些企业网站中，很多都是这种加密方式。记得当初自己第一次碰到这种密码也很郁闷，我当时还在想这管理员的密码可真复杂啊，而且还不是MD5加密的，以为是明文呢，可是登陆不了，提示密码错误（突然感觉自己有点以五十步笑百步了╮(╯▽╰)╭）。<br />
后来换了N个关键字百度了一番，找到了它的加密算法。原来就是将原始字符串中逐个字符转成ASCII码然后加该字符所在的位置数（从左数起），接着再转回到字符型并拼接成字符串，得到的就是加密后的密码了。<br />
加密算法很简单，所以可以很快的写出个解密程序来。</p>

<div class="wp_syntax"><div class="code"><pre class="java" style="font-family:monospace;"><span style="color: #000000; font-weight: bold;">public</span> <span style="color: #000000; font-weight: bold;">static</span> <span style="color: #000066; font-weight: bold;">void</span> main<span style="color: #009900;">&#40;</span><span style="color: #003399;">String</span><span style="color: #009900;">&#91;</span><span style="color: #009900;">&#93;</span> args<span style="color: #009900;">&#41;</span> <span style="color: #009900;">&#123;</span>
<span style="color: #003399;">String</span> pwd1 <span style="color: #339933;">=</span> <span style="color: #0000ff;">&quot;mz}6=&gt;9&gt;&lt;C=&quot;</span><span style="color: #339933;">;</span>
<span style="color: #003399;">String</span> pwd2 <span style="color: #339933;">=</span> <span style="color: #0000ff;">&quot;&quot;</span><span style="color: #339933;">;</span>
<span style="color: #000000; font-weight: bold;">for</span> <span style="color: #009900;">&#40;</span><span style="color: #000066; font-weight: bold;">int</span> i <span style="color: #339933;">=</span> <span style="color: #cc66cc;">0</span><span style="color: #339933;">;</span> i <span style="color: #339933;">&lt;</span> pwd1.<span style="color: #006633;">length</span><span style="color: #009900;">&#40;</span><span style="color: #009900;">&#41;</span><span style="color: #339933;">;</span> i<span style="color: #339933;">++</span><span style="color: #009900;">&#41;</span> <span style="color: #009900;">&#123;</span>
<span style="color: #000066; font-weight: bold;">int</span> temp <span style="color: #339933;">=</span> <span style="color: #009900;">&#40;</span><span style="color: #000066; font-weight: bold;">int</span><span style="color: #009900;">&#41;</span>pwd1.<span style="color: #006633;">charAt</span><span style="color: #009900;">&#40;</span>i<span style="color: #009900;">&#41;</span><span style="color: #339933;">-</span>i<span style="color: #339933;">-</span><span style="color: #cc66cc;">1</span><span style="color: #339933;">;</span>
pwd2 <span style="color: #339933;">+=</span> <span style="color: #009900;">&#40;</span><span style="color: #000066; font-weight: bold;">char</span><span style="color: #009900;">&#41;</span>temp<span style="color: #339933;">;</span>
<span style="color: #009900;">&#125;</span>
<span style="color: #003399;">System</span>.<span style="color: #006633;">out</span>.<span style="color: #006633;">println</span><span style="color: #009900;">&#40;</span>pwd2<span style="color: #009900;">&#41;</span><span style="color: #339933;">;</span>
<span style="color: #009900;">&#125;</span></pre></div></div>

<p>用上面的程序解密“mz}6=>9><C=”得到的是“lxz28826392”。呵呵，我又闲着无聊，拿着这个密码去登了一下那个后台，提示错误。郁闷了，不过我感觉这个密码不是对应那个后台的，整个网站应该是几个程序合并起来的。</p>
<p>呵呵，管他呢，主要是这个算法，当初百度出来后自己也没怎么记，现在把它写出来，以免以后又忘了。</p>
<table class="wumii-related-items" cellspacing="0" cellpadding="3" border="0"  style="clear: both;">
    
    <tr>
        <td colspan="5"><b><font size="-1"  style="display: block !important; padding: 20px 0 5px !important;">您可能也喜欢：</font></b></td>
    </tr>
    
        <tr>
                <td width="101" valign="top" style="padding: 5px !important; margin: 0 !important;">
                    <a target="_blank" title="入侵检测网站" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F464%2F&from=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F842%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 95px !important; height: 95px !important;" src="http://static.wumii.com/images/blogWidget/wordpress_default.gif" width="95px" height="95px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 101px !important; font: 12px/15px arial !important; height: 60px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">入侵检测网站</font>
                    </a>
                </td>
                <td width="101" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="MD5如今不堪一击" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F519%2F&from=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F842%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 95px !important; height: 95px !important;" src="http://static.wumii.com/images/blogWidget/wordpress_default.gif" width="95px" height="95px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 101px !important; font: 12px/15px arial !important; height: 60px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">MD5如今不堪一击</font>
                    </a>
                </td>
                <td width="101" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="教你压缩JavaScript代码" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F649%2F&from=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F842%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 95px !important; height: 95px !important;" src="http://static.wumii.com/images/blogWidget/wordpress_default.gif" width="95px" height="95px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 101px !important; font: 12px/15px arial !important; height: 60px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">教你压缩JavaScript代码</font>
                    </a>
                </td>
                <td width="101" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="JavaScript动态时钟" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F1224%2F&from=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F842%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 95px !important; height: 95px !important;" src="http://static.wumii.com/site_images/2011/05/06/7752177.png" width="95px" height="95px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 101px !important; font: 12px/15px arial !important; height: 60px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">JavaScript动态时钟</font>
                    </a>
                </td>
                <td width="101" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="JavaScript绘制笑脸" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F1222%2F&from=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F842%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 95px !important; height: 95px !important;" src="http://static.wumii.com/site_images/2011/06/07/11304948.png" width="95px" height="95px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 101px !important; font: 12px/15px arial !important; height: 60px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">JavaScript绘制笑脸</font>
                    </a>
                </td>
        </tr>
    
    <tr>
        <td colspan="5" align="right">
            <a style="text-decoration: none !important;" href="http://www.wumii.com/widget/relatedItems.htm" target="_blank" title="无觅相关文章插件">
                <font size="-1" color="#bbbbbb" style="display: block !important; font-family: arial !important; padding: 5px 0 !important; font-size: 12px !important; color: #bbb !important;">无觅</font>
            </a>
        </td>
    </tr>
</table>]]></content:encoded>
			<wfw:commentRss>http://www.ineeke.com/archives/842/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>入侵检测网站</title>
		<link>http://www.ineeke.com/archives/464/</link>
		<comments>http://www.ineeke.com/archives/464/#comments</comments>
		<pubDate>Sat, 07 Jun 2008 10:49:48 +0000</pubDate>
		<dc:creator>Neeke</dc:creator>
				<category><![CDATA[信息安全]]></category>
		<category><![CDATA[MD5加密]]></category>

		<guid isPermaLink="false">http://ineeke.com/archives/%e5%85%a5%e4%be%b5%e6%a3%80%e6%b5%8b%e7%bd%91%e7%ab%99/</guid>
		<description><![CDATA[整天在家闲着没事干，想找个附近的公司找点活，赚点生活费。百度了一下“西安招聘”，哇~~好多好多网站啊。。。。
翻开几个看看，有个公司要求还挺高的，习惯性的先看看这个公司的网站，于是有了下文。
打开它的网站，首先看了一下是什么程序写的，发现很多html，还有些asp的，没报多大希望。看到有注册用户，于是我也注册了，当鼠标移动到注册按钮上面时，我发现浏览器左下角显示的路径和文件名都很眼熟，是什么呢？啊~~对了，是风讯。
注册过程中发现和以前看到的注册页面不大一样，于是想：系统这么多，同路径同文件名的大有所在。到了注册完毕，终于看到曙光了。果然就是风讯的，赶紧找上传相片那个地方，然后用：
User/CommPages/SelectPic.asp?CurrPath=/UserFiles/注册获得的ID&#038;f_UserNumber=注册获得的ID
打开看看，接着用：
User/CommPages/SelectPic.asp?CurrPath=/UserFiles/020655AC021/test.aspf_UserNumber=020655AC021
访问，选择了个asp马（后缀当然是gif了），上传成功！打开图片地址访问出错了：
<img onload="ResizeImage(this,480)" src="http://www.ineeke.com/upload/2008/6/200806071901301086.jpg" alt="" title=""/>
这个目录没执行权，换一个吧。
<table class="wumii-related-items" cellspacing="0" cellpadding="3" border="0"  style="clear: both;">
    
    <tr>
        <td colspan="5"><b><font size="-1"  style="display: block !important; padding: 20px 0 5px !important;">您可能也喜欢：</font></b></td>
    </tr>
    
        <tr>
                <td width="101" valign="top" style="padding: 5px !important; margin: 0 !important;">
                    <a target="_blank" title="企业网站密码加密算法" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F842%2F&from=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F464%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 95px !important; height: 95px !important;" src="http://static.wumii.com/images/blogWidget/wordpress_default.gif" width="95px" height="95px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 101px !important; font: 12px/15px arial !important; height: 60px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">企业网站密码加密算法</font>
                    </a>
                </td>
                <td width="101" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="对某钢铁公司网站的安全检测" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F804%2F&from=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F464%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 95px !important; height: 95px !important;" src="http://static.wumii.com/images/blogWidget/wordpress_default.gif" width="95px" height="95px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 101px !important; font: 12px/15px arial !important; height: 60px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">对某钢铁公司网站的安全检测</font>
                    </a>
                </td>
                <td width="101" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="无意中入侵一台Windows Server 2008" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F1179%2F&from=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F464%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 95px !important; height: 95px !important;" src="http://static.wumii.com/site_images/2011/05/05/7679200.png" width="95px" height="95px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 101px !important; font: 12px/15px arial !important; height: 60px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">无意中入侵一台Windows Server 2008</font>
                    </a>
                </td>
                <td width="101" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="2小时入侵了3台服务器" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F507%2F&from=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F464%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 95px !important; height: 95px !important;" src="http://static.wumii.com/images/blogWidget/wordpress_default.gif" width="95px" height="95px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 101px !important; font: 12px/15px arial !important; height: 60px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">2小时入侵了3台服务器</font>
                    </a>
                </td>
                <td width="101" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="入侵需要时机和运气" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F839%2F&from=http%3A%2F%2Fwww.ineeke.com%2Farchives%2F464%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 95px !important; height: 95px !important;" src="http://static.wumii.com/images/blogWidget/wordpress_default.gif" width="95px" height="95px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 101px !important; font: 12px/15px arial !important; height: 60px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">入侵需要时机和运气</font>
                    </a>
                </td>
        </tr>
    
    <tr>
        <td colspan="5" align="right">
            <a style="text-decoration: none !important;" href="http://www.wumii.com/widget/relatedItems.htm" target="_blank" title="无觅相关文章插件">
                <font size="-1" color="#bbbbbb" style="display: block !important; font-family: arial !important; padding: 5px 0 !important; font-size: 12px !important; color: #bbb !important;">无觅</font>
            </a>
        </td>
    </tr>
</table>]]></description>
			<content:encoded><![CDATA[<p>整天在家闲着没事干，想找个附近的公司找点活，赚点生活费。百度了一下“西安招聘”，哇~~好多好多网站啊。。。。<br />
翻开几个看看，有个公司要求还挺高的，习惯性的先看看这个公司的网站，于是有了下文。<br />
打开它的网站，首先看了一下是什么程序写的，发现很多html，还有些asp的，没报多大希望。看到有注册用户，于是我也注册了，当鼠标移动到注册按钮上面时，我发现浏览器左下角显示的路径和文件名都很眼熟，是什么呢？啊~~对了，是风讯。<br />
注册过程中发现和以前看到的注册页面不大一样，于是想：系统这么多，同路径同文件名的大有所在。到了注册完毕，终于看到曙光了。果然就是风讯的，赶紧找上传相片那个地方，然后用：<br />
User/CommPages/SelectPic.asp?CurrPath=/UserFiles/注册获得的ID&#038;f_UserNumber=注册获得的ID<br />
打开看看，接着用：<br />
User/CommPages/SelectPic.asp?CurrPath=/UserFiles/020655AC021/test.aspf_UserNumber=020655AC021<br />
访问，选择了个asp马（后缀当然是gif了），上传成功！打开图片地址访问出错了：<br />
<img onload="ResizeImage(this,480)" src="http://www.ineeke.com/upload/2008/6/200806071901301086.jpg" alt="" title=""/><br />
这个目录没执行权，换一个吧。<br />
<span id="more-464"></span>User/CommPages/SelectPic.asp?CurrPath=/UserFiles/test.asp&#038;f_UserNumber=020655AC021<br />
结果：<br />
<img onload="ResizeImage(this,480)" src="http://www.ineeke.com/upload/2008/6/200806071902465081.jpg" alt="" title=""/><br />
晕死了，没搞投了。。。。。<br />
继续浏览一下整个网站看看有什么东西。<br />
User/CommPages/SelectPic.asp?CurrPath=../../f_UserNumber=020655AC021<br />
到网站根目录了：<br />
<img onload="ResizeImage(this,480)" src="http://www.ineeke.com/upload/2008/6/200806071905436245.jpg" alt="" title=""/><br />
找到了数据库目录，然后下载数据库，没想到竟然能下载下来。。。。以前见过的都没权限下载的。倒~<br />
找到管理帐号和密码（当然是从MD5破解得来的），然后又用那个漏洞找到了管理登陆处。进入。。。。<br />
<img onload="ResizeImage(this,480)" src="http://www.ineeke.com/upload/2008/6/200806071907402082.jpg" alt="" title=""/><br />
看了一下配置文件，是MSSQL的，但是不是SA。行了，不搞了。马上加站长QQ通知，有必要了就打他电话，反正都是西安的。</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ineeke.com/archives/464/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

