
照相的:
HANDLE WINAPI CreateToolhelp32Snapshot( DWORD dwFlags, DWORD th32ProcessID );
The snapshot taken by this function is examined by the other tool help functions to provide their results. Access to the snapshot is read only. The snapshot handle acts like an object handle and is subject to the same rules regarding which processes and threads it is valid in.
To enumerate the heap or module states for all processes, specify TH32CS_SNAPALL and set th32ProcessID to zero. Then, for each additional process in the snapshot, call CreateToolhelp32Snapshot again, specifying its process identifier and the TH32CS_SNAPHEAPLIST or TH32_SNAPMODULE value.
跟踪的:
BOOL WINAPI Process32First(
HANDLE hSnapshot,
LPPROCESSENTRY32 lppe
);
The calling application must set the dwSize member of PROCESSENTRY32 to the size, in bytes, of the structure. Process32First changes dwSize to the number of bytes written to the structure. This will never be greater than the initial value of dwSize, but it may be smaller. If the value is smaller, do not rely on the values of any members whose offsets are greater than this value.
To retrieve information about other processes recorded in the same snapshot, use the Process32Next function.
狗仔队的助手:
BOOL WINAPI Process32Next( HANDLE hSnapshot, LPPROCESSENTRY32 lppe );
To retrieve information about the first process recorded in a snapshot, use the Process32First function.
Underground hackers are hawking zero-day exploits for Microsoft's new Windows Vista operating system at $50,000 a pop, according to computer security researchers at Trend Micro.
The Windows Vista exploit—which has not been independently verified—was just one of many zero-days available for sale at an auction-style marketplace infiltrated by the Tokyo-based anti-virus vendor.
In an interview with eWEEK, Trend Micro's chief technology officer, Raimund Genes, said prices for exploits for unpatched code execution flaws are in the $20,000 to $30,000 range, depending on the popularity of the software and the reliability of the attack code.
Bots and Trojan downloaders that typically hijack Windows machines for use in spam-spewing botnets were being sold for about $5,000, Genes said.
The Trend Micro discovery highlights the true financial value of software vulnerability information and serves as further confirmation that a lucrative underground market exists for exploit code targeting unpatched flaws.
Back in December 2005, researchers at Kaspersky Lab in Moscow found evidence that the exploit code used in the WMF (Windows Metafile) attack was being peddled by Russian hacker groups for $4,000.
However, according to Genes, the typical price of a destructive exploit has increased dramatically, driving an underground market that could exceed the value of the legitimate security software business.
"I think the malware industry is making more money than the anti-malware industry," Genes said.
Trend Micro's researchers also found the underground marketplace saturated with personal data stolen in phishing attacks and virtual currency hijacked from online gamers.
Genes said the average prices for credit card and bank log-in data can vary dramatically, depending on the bank's brand and the way the data is mapped to names, Social Security numbers, dates of birth and physical addresses.
A custom Trojan capable of stealing online account information can be bought for between $1,000 and $5,000, while a botnet-building piece of malware can cost between $5,000 and $20,000, Genes said.
B.P.C v3 Beta - Bad Password Checker
Date: 2006-11-21
Screenshot: (press to view large)

ChangeLog:
[3.0.0 BETA]
- feature: Added After Done events.
- feature: Added HttpDebug colors.
- feature: Added LOG autoScroll on/off checkbox.
- feature: Added Magnetic Windows.
- feature: Added [Import] button for Bad Keywords, HQ, UserAgents.
- feature: Changed "Bad Keywords" to "Edit conf Files" with more settings.
- feature: Custom Export Syntax.
- feature: Some New Hot Keys (see hotkeys.txt for more information).
- feature: Http Debug.
- feature: Remove Not HQ Passes function.
- feature: Go to Url/Goto All Url's (IE not supported for ("Goto All Url's"). (Use Opera)) function.
- feature: Paste button for GoodProxyList.
- feature: Sort Option for now it supports Ascending/Descending modes.
- feature: Web Site Rating checker from Google.com.
- feature: Main Options [Load/Save SnapShot, Sound On/Off].
- feature: Drag&Drop function for Login list. (required by a0z)
- feature: Paste list button.
- feature: Minimize to Tray and Exit Buttons. (required by )
- feature: LOG auto clear function after 65535 chars.
- changed: Improved Paste Logins List Parse function, now it's removes junk and duplicates automatically.
- changed: Spitted columns User : Password in good list.
- bugFix: Fixed HQ,BadKw,User Agents recognition function.
- bugFix: Fixed button CheckMouseOver() function crash.
- bugFix: Save/Export Overwrite bugs.
- bugFix: GoodList window resize crash.
- bugFix: Good passes counter engine.
- bugFix: Crash when minimized.
- bugFix: Wrong ProgressBar value.
- bugFix: Multiple stability fixes.
Download:
http://rapidshare.de/files/21562638/WRACKBPC.v3.0.0.Beta.rar.html (beta version)
Mirror (no wait):
http://www.plunder.com/-download-32965.htm (beta version)
在J8黑客群里,superhei和李丰初突然找茬,MD,那本来就是个八卦群,当然娱乐别人了。难道偶骂那些大牛,又践踏了你们那小小的自尊,是我虚荣还是你虚荣。
我只是说了偶知道了,说了下基于rss的DOS,李丰初大牛,突然向偶发难,认为偶的做法像朽木,大有认为偶在吹嘘不太可能的事一样。
偶只想说,不了解我说的西西的人,如果想反驳我的无知,请找到证据。否则就不要向偶炫耀你的知识渊博
附:blackhat关于rss dos的一个论文
Black Hat USA 2006 Topics and Speakers
The Black Hat Briefings Europe 2005 Speakers page. ... Zero Day Subscriptions: Using RSS and Atom feeds As Attack Delivery Systems ...
www.blackhat.com/html/bh-usa-06/bh-usa-06-speakers.html
如果偶娱了的过程践踏让你不爽了,请屏蔽偶的发言(这年头,低调真没好处)
特点:
|
12月13日,是南京人心中永远的痛。1937年的今天,侵华日军攻占南京,大肆屠城,血流成河,30多万同胞惨遭杀戮。
周恩来总理说过:“可以原谅,但是不可以忘却。”
PS:不要和偶说黑什么日本站,那样偶只能给你个中指
Powered by Haiwit