Ê×Ò³ | Óʼþ×ÊѶ | ¼¼Êõ½Ì³Ì | ½â¾ö·½°¸ | ²úÆ·ÆÀ²â | ÓʼþÈ˲Š| Óʼþ²©¿Í | ÓʼþϵͳÂÛ̳ | Èí¼þÏÂÔØ | ÓʼþÖÜ¿¯ | ÈȵãרÌâ | ¹¤¾ß
ÍøÂç¼¼Êõ | ²Ù×÷ϵͳ | Óʼþϵͳ | ¿Í»§¶Ë | µç×ÓÓÊÏä | ·´À¬»øÓʼþ | Óʼþ°²È« | ÓʼþÓªÏú | ÒÆ¶¯µçÓÊ | ÓʼþÈí¼þÏÂÔØ | µç×ÓÊéÏÂÔØ

ÓʼþÍøÂ簲ȫ

ϵͳ°²È« | ÓʼþÈí¼þ©¶´ | °²È«»ù´¡ | Êý×ÖÇ©Ãû | ¹¥·À¼¼Êõ | ²¡¶¾¹«¸æ | ²¡¶¾²éɱ | ISA Server | ·À»ðǽ |
Ê×Ò³ > ÓʼþÍøÂ簲ȫ > ¹¥·À¼¼Êõ > ̸һ̸עÈ빤¾ßµÄÔ­ÀíºÍ¿ª·¢ > ÕýÎÄ

̸һ̸עÈ빤¾ßµÄÔ­ÀíºÍ¿ª·¢

³ö´¦£ºhackbase ×÷ÕߣºCC ʱ¼ä£º2006-1-21 0:31:00

¡°×¢È롱ÕâÒ»´ÊÑÛÏ¿ÉËãµÃÉÏʱ÷Ö£¬¡°´ó½ÖСÏµ½´¦¶¼ÄÜ¡°Ìý¡±µ½¿´µ½¡£ÕâÒ»´ÊÔø¾­ÈÃÎÞÊýÈË¡°ÎÅÃûÉ«±ä¡±£¬½ñÌìÎÒÃǵϰÌâÈÔÊÇ×¢Èë¡£²»¹ý½ñÌìÎÒÃÇÕâÀïµÄÕâ¸ö×¢È벻ͬÓÚÒÔÍùµÄ£¬ËüÓбðÓÚͨ³£µÄSQL×¢È룬¿ÉÒÔ˵ÊÇÒ»ÖÖÐÂÐ͵ġ£Æ½ÈÕÀÈËÃÇÔÚÌá½»Êý¾ÝµÄʱºò¶¼ÊDzÉÓÃÒ³ÃæÐÎʽ¡£µ«ÊÇ£¬½ñÌìÎÒÃÇÕâÀï¾ÍÒª´òÆÆÕâÒ»´«Í³¹ÛÄî¡£ÕâÖÖ·½·¨ÊÇͨ¹ý×Ô¼º¹¹ÔìHTTPÇëÇó±¨ÎÄ£¬ÒÔ³ÌÐòµÄ·½Ê½´úÌæ´«Í³µÄ·½·¨£¬ÊµÏÖÊý¾ÝµÄ×Ô¶¯Ìá½»¡£

ÔÚÎÄÕ»¹Î´½øÈëÕýÌâµÄʱºò£¬ÎÒ¾ÍHTTPЭÒéÕâ¸ö¶«Î÷¸ø´ó¼ÒÔÙÂÞàÂÁ½¾ä¡£Æäʵ¹ØÓÚHTTPЭÒéÕâ¸ö¶«Î÷ÎÒ±¾À´¶¼²»Ïë˵µÄ¡£µ«ÊÇ£¬ÎªÁËÕչ˴ó¶àÊýÅóÓÑ¡£Æ½ÈÕÀµ±ÎÒÃÇÔÚ´ò¿ªÒ»¸öÍøÕ¾µÄʱºò£¬±ÈÈç˵http://www.36963.cn/£¬Êµ¼ÊÉÏIE×÷Ϊһ¸ö¿Í»§¶Ë£¬Ëü½«Ïò·þÎñÆ÷·¢Ë͵ÄÊÇÈçϵÄÇëÇó±¨ÎÄ£º
GET / HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/vnd.ms-
powerpoint, application/vnd.ms-excel, application/msword, application/x-shockwave-flash, */*
Accept-Language: zh-cn
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
Host: www.36963.cn
Connection: Keep-Alive
Cookie: NETEASE_SSN=hinrof; NETEASE_ADV=11&22; Province=0; City=0; NTES_UV_COOKIE=YES
´ÓÒÔÉϵı¨ÎÄÖУ¬ÎÒÃÇ¿ÉÒÔ¿´µ½ºÜ¶à×ֶΣ¬²»¹ýÆäÖÐÓкܶಢ²»ÊDZØÐëµÄ£¬Èç¹ûÎÒÃÇ×Ô¼º±à³Ì£¬Ö»¹ØÐıØÒªµÄ¾ÍÐÐÁË¡£ÔÚHTTP/1.1ЭÒéÖй涨ÁË×îСÇëÇóÏûÏ¢ÓÉ·½·¨×ֶΣ¨GET/POST/HEAD£©ºÍÖ÷»ú×ֶΣ¨HOST£©¹¹³É¡£ÈçÉÏÃæµÄ
GET /HTTP/1.1
HOST:www.36963.cn
µ«ÔÚHTTP/1.0ÖУ¬HOST×ֶβ¢²»ÊDZØÐëµÄ£¬ÖÁÓÚÕâÀïΪʲô²»ÄÜÊ¡£¬¼ÌÐøÍùÏ¿´¡£
GETºÍPOSTÊÇä¯ÀÀÆ÷Ïò·þÎñÆ÷Ìá½»±¨ÎÄͨ³£Ëù²ÉÓõÄÁ½ÖÖ·½·¨¡£·þÎñÆ÷ÔÚÊÕµ½±¨ÎÄÖ®ºó£¬½âÂë·ÖÎö³öËùÐèµÄÊý¾Ý²¢½øÐд¦Àí£¬×îºó·µ»Ø½á¹û¡£Í¨³£ÎÒÃÇ¿ÉÒÔ¿´µ½µÄ¶¼ÊÇÏñhttp://***.***.***.***/list.asp?id=***ÕâÑùµÄURLÇëÇó£¬ÎÒÃÇ¿ÉÒÔ×Ô¼º¹¹ÔìÈçϵı¨ÎÄÀ´Íê³É ¡£
GET /list.asp?id=*** HTTP/1.1
HOST:***.***.***.***
ÓÉÓÚÊÜURL³¤¶È1024µÄÏÞÖÆ£¬ËùÒÔGET·½·¨Í¨³£ÊÇÓÃÔÚÌύһЩСÊý¾ÝµÄÇé¿öÏ¡£Èç¹ûÊý¾Ý±È½Ï´ó¾ÍÖ»ÄܲÉÓÃPOST·½·¨¡£ÔÚ½²½âPOST·½·¨µÄһЩҪµã֮ǰ£¬´ó¼Ò»¹ÊÇÏÈÀ´¿´Ò»¶ÎPOSTÇëÇó±¨ÎÄ¡£

POST /huace/add.php HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/vnd.ms-
powerpoint, application/vnd.ms-excel, application/msword, application/x-shockwav
e-flash, */*
Referer: http://202.147.125.36/huace/add.php
Accept-Language: zh-cn
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
Host: 202.147.125.36
Content-Length: 115
Connection: Keep-Alive

name=test&email=&comefrom=&homepage=&icq=&oicq=&image=say.gif&comment=test&password=&doadd=%B7%A2%CB%CD%C1%F4%D1%D4
ÓëGET·½·¨Ïà±È£¬ÔÚ×Ö¶ÎÏÂÃæ¶àÁËÒ»¶ÎÄÚÈÝ£¬Õâ¾ÍÊÇÎÒÃÇÌá½»µÄÊý¾Ý£¬Èç¹ûÓÐÖÐÎÄÐë¾­¹ýurlencode±àÂ롣ͬÑùÈÃÎÒÃÇʡȥ²»±ØÒªµÄ×ֶΣ¬¹¹ÔìÒ»¸ö×îСµÄPOSTÇëÇó¡£
POST /huace/add.php HTTP/1.1
Host: 202.147.125.36
Content-Type: application/x-www-form-urlencoded
Content-Length: 115
name=test&email=&comefrom=&homepage=&icq=&oicq=&image=say.gif&comment=test&password=&doadd=%B7%A2%CB%CD%C1%F4%D1%D4
ÉÏÃæµÄContent-Type×ֶαíʾΪPOST±íµ¥Ð͵ģ¬Content-Lengthµ±È»¾ÍÊDZíʾʵÌåÊý¾ÝµÄ³¤¶ÈÁË£¬ÕâÀï¶¼²»ÄÜÉÙ£¬²»È»¾ÍÎÞ·¨ÕýÈ·½ÓÊÕÁË¡£ÕâÑù£¬·þÎñÆ÷¶Ë´¦ÀíÒ³Ãæ¾Í»áÊÕµ½Ìá½»µÄÊý¾Ý£¬²¢½ÓÊÕ´¦Àí¡£
ÉÏÃæ²»Öª²»¾õµÄ½²ÁËÒ»´ó¶Ñ¹ØÓÚ¿Í»§¶ËµÄ¶«Î÷£¬½ÓÏÂÀ´¿´·þÎñÆ÷·½Ãæ¡£µ±±¨ÎÄÊý¾Ýµ½´ï·þÎñÆ÷ºó£¬·þÎñÆ÷µ×²ã½ø³Ì½øÐнÓÊÕ²¢·ÅÈëÌØ¶¨µÄ»º³åÇø£¬Í¬Ê±ÉèÖÃһЩ»·¾³±äÁ¿£¬Èç¡°CONTENT_LENGTH¡°¡¢¡±QUERY_STRING¡°µÈ£¬µ±È»ÕâÆä¼ä»¹ÊÇÆÁ±ÎÁËһЩµ×²ãϸ½ÚµÄ£¬Èç¿Í»§¶ËÌá½»µÄÊý¾ÝÊÇÔõô±»ÖØÖõ½±»ÇëÇóÒ³µÄ±ê×¼ÊäÈëµÄ£¬ÔÚ´ËÎÒÃǾͲ»×ö¹ý¶àµÄ¿¼ÂÇ¡£Ö®ºó¸ß²ãÓ¦ÓóÌÐòÈçCGI¡¢ASP¡¢PHPµÈ¶ÔÆä½øÐÐÊý¾ÝÌáÈ¡£¬ÆäÖÐCGI»¹Ðë×Ô¼º½øÐÐUnencode½âÂëºÍ×Ö·û´®ÌáÈ¡¡£¼ÙÈçÏòÒ»¸öASP³ÌÐòÌá½»Êý¾Ý£¬ÎÒÌá½»ÁËnameºÍbody×ֶΣ¬ÇÒ²ÉÓÃPOST±íµ¥·½Ê½Ìá½»£¬ÔÚASP³ÌÐòÖÐÓ¦ÈçϽøÐнÓÊÕ£º
name=request.form("name")
body=request.form("body")
²¢Ìí¼Óµ½Êý¾Ý¿âÖÐ
rs.addnew
rs("name")=name
rs("body")=body
rs.update
µ½´Ë£¬¸Ã½²µÄÒ²»ù±¾ÉϽ²ÍêÁË£¬Í¬Ê±ÕâÀïÎÒÃÇ»¹Òª×¢ÒâÒ»µã¾ÍÊÇÎÒÃÇÔÚ·¢Ëͱ¨ÎÄʱ£¬¡°name=value¡°URLEncode±àÂëÕâ¸ö¶«Î÷²»ÄÜÉÙ£¬Èç¹ûûÓÐËü£¬ÎÒÃÇÔÚÏòÊý¾Ý¿âд¶«Î÷µÄʱºòÓпÉÄܾͻáʧ°Ü¡£Í¬Ê±ÎÒÃÇÔÚÕâÀﻹҪעÒâÒ»¸öÎÊÌ⣬µ±±àÒëÆ÷´¦ÀíµÄÊÇÖÐÎÄ×Ö·ûʱ£¬Ëü»á×Ô¶¯¸ù¾Ý×Ö·ûµÄλ7À´¶ÁÈëÒ»¸ö»òÁ½¸ö×Ö·û£¬Õâʱ¿ÉÒÔÇ¿ÖÆ²ÉÓÃunsigned char *À´¶ÁÈëÒ»¸ö×Ö·û¡£

int isT(char ch) 
{ 
if(ch==¡¯ ¡¯||ch==¡¯%¡¯||ch==¡¯/¡¯||ch&0x80) return 1; 
else return 0; 
} 

int encode(char *s,char *d) 
{ 
if(!s||!d) return 0; 
for(;*s!=0;s++) 
{ 
unsigned char *p=(unsigned char*)s; 
if(*p==¡¯ ¡¯) 
{ 
*d=¡¯%¡¯; 
*(d+1)=¡¯2¡¯; 
*(d+2)=¡¯0¡¯; 
d+=3; 
} 
else if(isT(*p)) 
{ 
char a[3]; 
*d=¡¯%¡¯; 
sprintf(a,"%02x",*p); 
*(d+1)=a[0]; 
*(d+2)=a[1]; 
d+=3; 
} 
else 
{ 
*d=*p; 
d++; 
} 
} 
*d=0; 
return 1; 
}



 

ÒÔÏÂÊÇUnencode URL½âÂ뺯Êý£º
int unencode(char *s,char *d) 
{ 
if(!s||!d) return 0; 
for(;*s!=0;s++) 
{ 
if(*s==¡¯+¡¯) 
{ 
*d=¡¯ ¡¯; 
d++; 
} 
else if(*s==¡¯%¡¯) 
{ 
int code; 
if(sscanf(s+1,"%02x",&code)!=1) code=¡¯?¡¯; 
*d=code; 
s+=2; 
d++; 
} 
else 
{ 
*d=*s; 
d++; 
} 
} 
*d=0; 
return 1; 
}
Ïà¹ØÎÄÕ ÈÈÃÅÎÄÕÂ
  • Ïê½âCRLF×¢Èë¹¥»÷µÄÔ­ÀíºÍÆä·À·¶´ëÊ©
  • Microsoft Outlook Web AccessÔ¶³Ì½Å±¾×¢Èë©¶´£¨MS07-026£©
  • IBM Lotus Domino Web AccessÓʼþÏûÏ¢HTML×¢Èë©¶´
  • Hastymail IMAP/SMTPÔ¶³ÌÃüÁî×¢Èë©¶´
  • Microsoft Exchange Server OWA½Å±¾×¢Èë©¶´
  • Exchange Server ÖеÄ©¶´¿ÉÄÜÔÊÐí½Å±¾×¢Èë
  • SquirrelMail IMAP/SMTPÃüÁî×¢Èë©¶´
  • ArGoSoft Mail viewheaders½Å±¾´úÂë×¢Èë©¶´
  • IBM Lotus Domino iNotes¿Í»§¶Ë½Å±¾×¢Èë©¶´
  • Horde MIMEä¯ÀÀÆ÷ǶÈ븽¼þHTML×¢Èë©¶´
  • Horde IMPÓʼþ¸½¼þHTML×¢Èë©¶´
  • WebAdmin 3.0.2 ¿çÕ¾½Å±¾¡¢HTML×¢È밲ȫ©¶´
  • ¿í´øADSLÃÜÂëÆÆ½â´óÈ«
  • ADSLÕʺű»µÁ´¦ÀíÈ«³Ì
  • Á÷ÐеÄ©¶´ÈëÇÖ(Ò»)
  • IEÖ÷Ò³±»Ç¿ÐÐÐ޸ĵĽâ¾ö°ì·¨
  • ½ÌÄãÔõÑùÇáËÉÆÆ½âÃÜÂë
  • QQ±»µÁµÄÔ­Òò¼°·À·¶ÊÖ¶Î
  • ÎåÖÖwindowsÃÜÂëÉèÖü°ÆÆ½â
  • IISµÄÊ®Æß¸ö³£¼û©¶´
  • ½ÒÃØµÁÈ¡QQÃÜÂëľÂí
  • 12ÖÖ³£ÓÃÃÜÂëÆÆ½â·½·¨Ïê½â
  • ÆÆ½âemailÕ˺ŵķ½·¨(²ËÄñƪ)
  • MACµØÖ·È«½Ó´¥Ö®ºÀ¡°¶á¡±
  • ×ÔÓÉ¹ã¸æÇø
    ¡¡
     
    ×îÐÂÈí¼þÏÂÔØ
  • ORF Enterprise Edition 4.2 Õýʽ°æ
  • WinWebMail 3.7.7.3 ±ê×¼°æ
  • WinWebMail 3.7.7.3 ÆóÒµ°æ
  • BMailì÷ÓÊ
  • Merak Email Server for Windows 9.3.1..
  • Merak Email Server for Linux 9.3.1 ¼..
  • Merak Email Server 9.3.1 For Windwos..
  • AXIGEN Mail Server 6.1.1 for Windows
  • AXIGEN Mail Server 6.1.0 for Linux
  • ADModify.NETÏÂÔØ
  • symantec10.1»ù±¾°²×°¼°ÅäÖÃÊÓÆµ½Ì³Ì
  • Backup Exec System RecoveryÖ®±¸·ÝÊÓÆ..
  • ½ñÈÕÓʼþ¼¼ÊõÎÄÕÂ
  • ÃÀ´óѧÉúÇÖÈëÅåÁÖÖݳ¤¸öÈËÓʼþÕË»§±»´þ²¶
  • ˼¿ÆIronPort·¢²¼Ðµç×ÓÓʼþ°²È«É豸
  • Éî¸û"Èí¼þ+·þÎñ" ΢Èí300³ÇÊÐѲչî£ÓÊ
  • ´ÓºÚ¿Í³£Óù¥»÷Êֶο´WEBÓ¦Ó÷À»¤
  • ÏûÏ¢ÈËʿ͸¶ÑÅ»¢ÓëAOLºÏ²¢Ï¸½Ú½«ÓÚ±¾Ô..
  • ¹È¸èÌṩµÄµç×ÓÓʼþ´æµµÊ±¼äÑÓ³¤ÎªÊ®Äê
  • ÑÅ»¢½«ÔÚÓÊÏä·þÎñÖÐÕûºÏаæÔÚÏßÈÕÀú
  • 9ÔÂÀ¬»øÓʼþ×ÜÁ¿¼õÉÙ ÓëISPµ¹±ÕÓйØ
  • À¬»øÓʼþ·¢Õ¹µÄËÄ´óÇ÷ÊÆ
  • º«¹úÒéÔ±³ÆÖйúºÚ¿Íð³äÇàÍß̨·¢ËͲ¡¶¾..
  • VistaÄÑ³ÉÆøºò Windows XPÊÙÃü±»ÑÓ³¤
  • ÈüÃÅÌú¿ËÉý¼¶DLP²úÆ·¼°·´À¬»øÓʼþÍø¹Ø
  • ×îÐÂרÌâ
  • Sendmail ÓʼþϵͳÅäÖÃ
  • ×齨Exchange 2003Óʼþϵͳ
  • Windows Server 2008 רÌâ
  • ORF ·´À¬»øÓʼþϵͳ
  • Exchange Server 2007 רÌâ
  • ISA Server 2006 ½Ì³ÌרÌâ
  • Windows Vista ¼¼ÊõרÌâ
  • ¡°ºÚÝ®¡±£¨BlackBerry£©×¨Ìâ
  • ÒÆ¶¯µç×ÓÓʼþרÌâ
  • Apache James רÌâ
  • IMail Server ²Ù×÷Ö¸ÄÏ
  • ISA Server 2004 ʹÓÃרÌâ
  • ·ÖÀർº½
    ÓʼþÐÂÎÅ×ÊѶ:
    ITÒµ½ç | Óʼþ·þÎñÆ÷ | ÓʼþȤÎÅ | ÒÆ¶¯µçÓÊ
    µç×ÓÓÊÏä | ·´À¬»øÓʼþ|Óʼþ¿Í»§¶Ë|ÍøÂ簲ȫ
    ÐÐÒµÊý¾Ý | ÓʼþÈËÎï | ÍøÕ¾¹«¸æ | ÐÐÒµ·¨¹æ
    ÍøÂç¼¼Êõ:
    ÓʼþÔ­Àí | ÍøÂçЭÒé | ÍøÂç¹ÜÀí | ´«Êä½éÖÊ
    Ïß·½ÓÈë | ·ÓÉ½Ó¿Ú | Óʼþ´æ´¢ | »ªÎª3Com
    CISCO¼¼Êõ | ÍøÂçÓë·þÎñÆ÷Ó²¼þ
    ²Ù×÷ϵͳ:
    Windows 9X | Linux&Uinx | Windows NT
    Windows Vista | FreeBSD | ÆäËü²Ù×÷ϵͳ
    Óʼþ·þÎñÆ÷:
    ³ÌÐòÓ뿪·¢ | Exchange | Qmail | Postfix
    Sendmail | MDaemon | Domino | Foxmail
    KerioMail | JavaMail | Winwebmail |James
    Merak&VisNetic | CMailServer | WinMail
    ½ðµÑÓʼþϵͳ | ÆäËü |
    ·´À¬»øÓʼþ:
    ×ÛÊö| ¿Í»§¶Ë·´À¬»øÓʼþ|·þÎñÆ÷¶Ë·´À¬»øÓʼþ
    Óʼþ¿Í»§¶ËÈí¼þ:
    Outlook | Foxmail | DreamMail| KooMail
    The bat | À×Äñ | Eudora |Becky! |Pegasus
    IncrediMail |ÆäËü
    µç×ÓÓÊÏä: ¸öÈËÓÊÏä | ÆóÒµÓÊÏä |Gmail
    ÒÆ¶¯µç×ÓÓʼþ:·þÎñÆ÷ | ¿Í»§¶Ë | ¼¼ÊõÇ°ÑØ
    ÓʼþÍøÂ簲ȫ:
    Èí¼þ©¶´ | °²È«ÖªÊ¶ | ²¡¶¾¹«¸æ |·À»ðǽ
    ¹¥·À¼¼Êõ | ²¡¶¾²éɱ| ISA | Êý×ÖÇ©Ãû
    ÓʼþÓªÏú:
    EmailÓªÏú | ÍøÂçÓªÏú | ÓªÏú¼¼ÇÉ |ÓªÏú°¸Àý
    ÓʼþÈ˲Å:ÕÐÆ¸ | Ö°³¡ | Åàѵ | Ö¸ÄÏ | Ö°³¡
    ½â¾ö·½°¸:
    Óʼþϵͳ|·´À¬»øÓʼþ |°²È« |ÒÆ¶¯µçÓÊ |Õбê
    ²úÆ·ÆÀ²â:
    Óʼþϵͳ |·´À¬»øÓʼþ |ÓÊÏä |°²È« |¿Í»§¶Ë
    ¹ã¸æÁªÏµ | ºÏ×÷ÁªÏµ | ¹ØÓÚÎÒÃÇ | ÁªÏµÎÒÃÇ | ·±ówÖÐÎÄ
    °æÈ¨ËùÓУºÓʼþ¼¼Êõ×ÊÑ¶Íø©2003-2007 www.5dmail.net, All Rights Reserved
    www.5Dmail.net Web Team   ÔÁICP±¸05009143ºÅ