<?xml version="1.0" encoding="UTF-8" ?><rss version="2.0" xmlns:content="http://purl.org/Rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/"><channel><title>demonalex的狂人日记</title><link>http://www.i170.com/user/demonalex/Rss</link><description></description><language>zh-cn</language><pubDate>Sun, 06 Jul 2008 22:05:59  +0800</pubDate><generator>i170.com</generator><image><title>demonalex的狂人日记</title><url>http://www.i170.comattavatar_1/demonalex_4659.JPG</url><link>http://www.i170.com/user/demonalex/Rss</link></image> <item><link>http://www.i170.com/Article/107882</link><title><![CDATA[［转载］[Ubuntu资料]Apt-get使用指南]]></title><author>demonalex</author><category>安全技术,胡言乱语</category><pubDate>Thu, 26 Jun 2008 15:58:39  +0800</pubDate><description><![CDATA[<div class="tit">[Ubuntu资料]Apt-get使用指南</div>
<div class="date">2008年04月18日 10:30</div>
<div class="w">Apt-get使用指南 - Ubuntu中文</div>
<p><a href=
"http://wiki.ubuntu.org.cn/Apt-get%E4%BD%BF%E7%94%A8%E6%8C%87%E5%8D%97"
class=
"nc">wiki.ubuntu.org.cn/Apt-get%E4%BD%BF%E7%94%A8%E6...</a></p>
<div class="w">Ubuntu中文 论坛 :: 阅读主题 - [原创]apt-get等命令行介绍</div>
<p><a href=
"http://forum.ubuntu.com.cn/viewtopic.php?t=65707&amp;highlight=dist-upgrade"
class=
"nc">forum.ubuntu.com.cn/viewtopic.php?t=65707&amp;highl...</a></p>
<h3>&nbsp;</h3>
<h3><span>命令</span></h3>
<p>
下面将要介绍的所有命令都需要sudo！使用时请将“packagename”和“string”替换成您想要安装或者查找的程序。</p>
<ul>
<li>apt-get
update——在修改/etc/apt/sources.list或者/etc/apt/preferences之後运行该命令。此外您需要定期运行这一命令以确保您的软件包列表是最新的。</li>
<li>apt-get install packagename——安装一个新软件包（参见下文的aptitude）</li>
<li>apt-get remove packagename——卸载一个已安装的软件包（保留配置文件）</li>
<li>apt-get --purge remove packagename——卸载一个已安装的软件包（删除配置文件）</li>
<li>dpkg --force-all --purge packagename
有些软件很难卸载，而且还阻止了别的软件的应用，就可以用这个，不过有点冒险。</li>
<li>apt-get autoclean
apt会把已装或已卸的软件都备份在硬盘上，所以如果需要空间的话，可以让这个命令来删除你已经删掉的软件</li>
<li>apt-get clean 这个命令会把安装的软件的备份也删除，不过这样不会影响软件的使用的。</li>
<li>apt-get upgrade——更新所有已安装的软件包</li>
<li>apt-get dist-upgrade——将系统升级到新版本</li>
<li>apt-cache search string——在软件包列表中搜索字符串</li>
<li>dpkg -l
package-name-pattern——列出所有与模式相匹配的软件包。如果您不知道软件包的全名，您可以使用“*package-name-pattern*”。</li>
<li>
aptitude——详细查看已安装或可用的软件包。与apt-get类似，aptitude可以通过命令行方式调用，但仅限于某些命令——最常见的有安装和卸载命令。由于aptitude比apt-get了解更多信息，可以说它更适合用来进行安装和卸载。</li>
<li>apt-cache showpkg pkgs——显示软件包信息。</li>
<li>apt-cache dumpavail——打印可用软件包列表。</li>
<li>apt-cache show pkgs——显示软件包记录，类似于dpkg –print-avail。</li>
<li>apt-cache pkgnames——打印软件包列表中所有软件包的名称。</li>
<li>dpkg -S file——这个文件属于哪个已安装软件包。</li>
<li>dpkg -L package——列出软件包中的所有文件。</li>
<li>apt-file search
filename——查找包含特定文件的软件包（不一定是已安装的），这些文件的文件名中含有指定的字符串。apt-file是一个独立的软件包。您必须
先使用apt-get install来安装它，然後运行apt-file update。如果apt-file search
filename输出的内容太多，您可以尝试使用apt-file search filename | grep -w
filename（只显示指定字符串作为完整的单词出现在其中的那些文件名）或者类似方法，例如：apt-file search
filename | grep
/bin/（只显示位于诸如/bin或/usr/bin这些文件夹中的文件，如果您要查找的是某个特定的执行文件的话，这样做是有帮助的）。</li>
</ul>
<p>＊ apt-get
autoclean——定期运行这个命令来清除那些已经卸载的软件包的.deb文件。通过这种方式，您可以释放大量的磁盘空间。如果您的需求十分迫切，可
以使用apt-get
clean以释放更多空间。这个命令会将已安装软件包裹的.deb文件一并删除。大多数情况下您不会再用到这些.debs文件，因此如果您为磁盘空间不足
而感到焦头烂额，这个办法也许值得一试。</p>
<p><br>
<strong>常用的APT命令参数<br></strong><br>
apt-cache search package 搜索包<br>
<br>
apt-cache show package 获取包的相关信息，如说明、大小、版本等<br>
<br>
sudo apt-get install package 安装包<br>
<br>
sudo apt-get install package - - reinstall 重新安装包<br>
<br>
sudo apt-get -f install 修复安装"-f = --fix-missing"<br>
<br>
sudo apt-get remove package 删除包<br>
<br>
sudo apt-get remove package - - purge 删除包，包括删除配置文件等<br>
<br>
sudo apt-get update 更新源<br>
<br>
sudo apt-get upgrade 更新已安装的包<br>
<br>
sudo apt-get <strong>dist-upgrade</strong> 升级系统<br>
<br>
sudo apt-get dselect-upgrade 使用 dselect 升级<br>
<br>
apt-cache depends package 了解使用依赖<br>
<br>
apt-cache rdepends package 是查看该包被哪些包依赖<br>
<br>
sudo apt-get build-dep package 安装相关的编译环境<br>
<br>
apt-get source package 下载该包的源代码<br>
<br>
sudo apt-get clean &amp;&amp; sudo apt-get autoclean 清理无用的包<br>
<br>
sudo apt-get check 检查是否有损坏的依赖</p>

]]></description><guid>http://www.i170.com/Article/107882</guid><trackback:ping>http://www.i170.com/Article/107882/trackback</trackback:ping><comments>http://www.i170.com/Article/107882#comment</comments><wfw:commentRss>http://www.i170.com/Article/107882/commentRss</wfw:commentRss></item> <item><link>http://www.i170.com/Article/107878</link><title><![CDATA[ubuntu8.04下播放rmvb]]></title><author>demonalex</author><category>胡言乱语</category><pubDate>Thu, 26 Jun 2008 14:56:56  +0800</pubDate><description><![CDATA[<p>#apt-get install totem-xine<br>
#apt-get install w32codecs<br>
#apt-get install libxine1-ffmpeg<br>
#apt-get install alsa-oss<br>
#apt-get install realplayer</p>

]]></description><guid>http://www.i170.com/Article/107878</guid><trackback:ping>http://www.i170.com/Article/107878/trackback</trackback:ping><comments>http://www.i170.com/Article/107878#comment</comments><wfw:commentRss>http://www.i170.com/Article/107878/commentRss</wfw:commentRss></item> <item><link>http://www.i170.com/Article/107854</link><title><![CDATA[[论文]无线安全运维支撑平台]]></title><author>demonalex</author><category>安全技术</category><pubDate>Wed, 25 Jun 2008 20:38:37  +0800</pubDate><description><![CDATA[<p><a href=
"http://www.venustech.com.cn/Case/183/121.Html">http://www.venustech.com.cn/Case/183/121.Html</a></p>

]]></description><guid>http://www.i170.com/Article/107854</guid><trackback:ping>http://www.i170.com/Article/107854/trackback</trackback:ping><comments>http://www.i170.com/Article/107854#comment</comments><wfw:commentRss>http://www.i170.com/Article/107854/commentRss</wfw:commentRss></item> <item><link>http://www.i170.com/Article/107369</link><title><![CDATA[祝愿天下的父亲父亲节快乐：）]]></title><author>demonalex</author><category>胡言乱语</category><pubDate>Sat, 14 Jun 2008 22:35:11  +0800</pubDate><description><![CDATA[<p>祝愿天下的父亲父亲节快乐~</p>
<p>
希望天堂的父亲也快乐，回想起一年前的父亲节，父亲一直在病床上渡过，而我却什么都做不了...下周因为工作的关系，周末可能要加班，不能再去看父亲了，希望他能理解，，，，爸爸，下周再来看您了^_^</p>

]]></description><guid>http://www.i170.com/Article/107369</guid><trackback:ping>http://www.i170.com/Article/107369/trackback</trackback:ping><comments>http://www.i170.com/Article/107369#comment</comments><wfw:commentRss>http://www.i170.com/Article/107369/commentRss</wfw:commentRss></item> <item><link>http://www.i170.com/Article/107147</link><title><![CDATA[暴力破解NEEAO的防范注入管理界面的WVS 4 FUZZER脚本]]></title><author>demonalex</author><category>安全技术</category><pubDate>Tue, 10 Jun 2008 02:54:27  +0800</pubDate><description><![CDATA[<p><a href=
"http://www.i170.com/Attach/299482A7-37F5-4C65-A133-95BFB09FF5F4">弄了个暴力破解neeao的防范SQL注入管理界面的WVS4
FUZZER脚本（不要忘了改目标IP地址），在这里，还是很暴力：）</a></p>
<p>截图：</p>
<p>&nbsp;<img width="640" height="402" src=
"http://www.i170.com/Attach/BE852E95-2628-4E54-9BD6-CBDF80CE1BB0"
alt=""></p>

]]></description><guid>http://www.i170.com/Article/107147</guid><trackback:ping>http://www.i170.com/Article/107147/trackback</trackback:ping><comments>http://www.i170.com/Article/107147#comment</comments><wfw:commentRss>http://www.i170.com/Article/107147/commentRss</wfw:commentRss></item> <item><link>http://www.i170.com/Article/107071</link><title><![CDATA[上海之旅2]]></title><author>demonalex</author><category>写真图鉴</category><pubDate>Sun, 08 Jun 2008 16:10:52  +0800</pubDate><description><![CDATA[<p><img width="360" height="480" src=
"http://www.i170.com/Attach/CBB144DB-15B6-47A0-89CD-C817A209E2FD"
alt=""></p>
<p>车水马龙的静安寺</p>
<p><img width="360" height="480" src=
"http://www.i170.com/Attach/74CFADC6-B458-4987-893F-25E1681C078E"
alt=""></p>
<p>拍得有点黑，唉。。。</p>
<p><img width="360" height="480" src=
"http://www.i170.com/Attach/F31C5A96-FE92-47A2-BFCE-18C60E2B2BA4"
alt=""></p>
<p>传说中上海滩的“百乐门”，现在好象是购物商场了。。。</p>
<p><img width="360" height="480" src=
"http://www.i170.com/Attach/A804523E-FB14-4E7C-B99E-C22F2D0D9066"
alt=""></p>
<p>旧上海的房子--“弄”</p>
<p><img width="502" height="376" src=
"http://www.i170.com/Attach/FFD4C8D1-E12E-4ADD-A6A6-E8C5EE61F844"
alt=""></p>
<p>阳台的部分。</p>
<p><img width="475" height="356" src=
"http://www.i170.com/Attach/8EB58D6C-9EBD-4866-BC40-5563928FB4A4"
alt=""></p>
<p>最后这张是‘近期陪伴着我的家伙’，仔细看看“大前门”，够前卫吧？！：D</p>
<p>&nbsp;</p>

]]></description><guid>http://www.i170.com/Article/107071</guid><trackback:ping>http://www.i170.com/Article/107071/trackback</trackback:ping><comments>http://www.i170.com/Article/107071#comment</comments><wfw:commentRss>http://www.i170.com/Article/107071/commentRss</wfw:commentRss></item> <item><link>http://www.i170.com/Article/107069</link><title><![CDATA[上海之旅：）]]></title><author>demonalex</author><category>写真图鉴</category><pubDate>Sun, 08 Jun 2008 15:57:09  +0800</pubDate><description><![CDATA[<p><img width="522" height="392" src=
"http://www.i170.com/Attach/F90F2417-E807-4AE4-9D9C-DA315AE21209"
alt=""></p>
<p>情有独钟的东方明珠：）</p>
<p><img width="528" height="396" src=
"http://www.i170.com/Attach/7A43A180-61C7-41E9-92A4-326E0A8AD842"
alt=""></p>
<p>传说中的“小日本军刀”式建筑。。。</p>
<p><img width="511" height="384" src=
"http://www.i170.com/Attach/5B1112BD-9391-494E-96BC-A7F117840FEA"
alt=""></p>
<p>上海名胜--新天地</p>
<p><img width="474" height="355" src=
"http://www.i170.com/Attach/18C495D3-AEB4-41DA-8C1D-A625C527D288"
alt=""></p>
<p>人不少，，，，</p>
<p><img width="360" height="480" src=
"http://www.i170.com/Attach/4CA6AF35-281C-4746-8289-C4FB1EBCD4AE"
alt=""></p>
<p>挺有情调的。。。</p>
<p><img width="360" height="480" src=
"http://www.i170.com/Attach/1EDACB1A-1CE3-4F0D-889F-DBF9E7DF4922"
alt=""></p>
<p>旧上海的阳台。</p>
<p><img width="448" height="336" src=
"http://www.i170.com/Attach/FC5E1F85-B6B8-4AAB-9987-52E011F3FAB5"
alt=""></p>
<p>在新天地里二分之一都是老外（顾客与服务生都是）。。。</p>

]]></description><guid>http://www.i170.com/Article/107069</guid><trackback:ping>http://www.i170.com/Article/107069/trackback</trackback:ping><comments>http://www.i170.com/Article/107069#comment</comments><wfw:commentRss>http://www.i170.com/Article/107069/commentRss</wfw:commentRss></item> <item><link>http://www.i170.com/Article/106851</link><title><![CDATA[上海东方明珠]]></title><author>demonalex</author><category>写真图鉴</category><pubDate>Wed, 04 Jun 2008 01:36:57  +0800</pubDate><description><![CDATA[<p>感觉比较有趣的建筑，一直都是在海报里看到，P了一张，很难看，挂上来纪念一下：）</p>
<p>PS：猜猜我是在什么地方拍得：P</p>
<p><img width="320" height="240" src=
"http://www.i170.com/Attach/B1C764F9-58D6-4D6F-9CBB-F76706F90456"
alt=""></p>

]]></description><guid>http://www.i170.com/Article/106851</guid><trackback:ping>http://www.i170.com/Article/106851/trackback</trackback:ping><comments>http://www.i170.com/Article/106851#comment</comments><wfw:commentRss>http://www.i170.com/Article/106851/commentRss</wfw:commentRss></item> <item><link>http://www.i170.com/Article/106719</link><title><![CDATA[最近又碰到瓶颈~]]></title><author>demonalex</author><category>胡言乱语</category><pubDate>Sun, 01 Jun 2008 13:17:46  +0800</pubDate><description><![CDATA[<p>
身体上，胃酸又犯了...经常想吐；工作上，最近的实验不太顺利，需要灵感，应该是还缺些什么，怪自己比较笨...；昨天，梦见两只形态完全不一样的凤凰，不知道这代表什么，有人能给我解解梦吗？：P</p>
<p>&nbsp;</p>
<p>
PS：最近的样子像生意失败的人似的，两天没刷牙和洗澡，胡子一个星期没刮--像俄国的大胡子，昏，照片就不放上来了--怕把大家都吓怕了，后天去客户培训--现在去刮刮胡子吧^@@^</p>

]]></description><guid>http://www.i170.com/Article/106719</guid><trackback:ping>http://www.i170.com/Article/106719/trackback</trackback:ping><comments>http://www.i170.com/Article/106719#comment</comments><wfw:commentRss>http://www.i170.com/Article/106719/commentRss</wfw:commentRss></item> <item><link>http://www.i170.com/Article/105267</link><title><![CDATA[nasl maker version 1.5]]></title><author>demonalex</author><category>安全技术</category><pubDate>Tue, 06 May 2008 22:20:16  +0800</pubDate><description><![CDATA[<p><a href=
"http://www.i170.com/Attach/BEA8BFC6-98AB-4264-A16C-BA755922F9A8">www.i170.com/Attach/BEA8BFC6-98AB-4264-A16C-BA755922F9A8<br>
</a></p>

]]></description><guid>http://www.i170.com/Article/105267</guid><trackback:ping>http://www.i170.com/Article/105267/trackback</trackback:ping><comments>http://www.i170.com/Article/105267#comment</comments><wfw:commentRss>http://www.i170.com/Article/105267/commentRss</wfw:commentRss></item> <item><link>http://www.i170.com/Article/104990</link><title><![CDATA[nasl maker version 1.2]]></title><author>demonalex</author><category>安全技术</category><pubDate>Thu, 01 May 2008 20:16:28  +0800</pubDate><description><![CDATA[<p><img width="575" height="450" src=
"http://www.i170.com/Attach/F92E790A-C09C-4781-90AE-6427AEA36553"
alt=""></p>
<p>修复了原有的一些BUG，加入脚本导入功能，也更兼容标准了（与NESSUS、X-SCAN书写方式兼容）。</p>
<p>带源代码，下载地址在：</p>
<p><a href=
"http://www.i170.com/Attach/8977369D-C691-4270-8AB7-85FFDB27A4D3">www.i170.com/Attach/8977369D-C691-4270-8AB7-85FFDB27A4D3</a></p>

]]></description><guid>http://www.i170.com/Article/104990</guid><trackback:ping>http://www.i170.com/Article/104990/trackback</trackback:ping><comments>http://www.i170.com/Article/104990#comment</comments><wfw:commentRss>http://www.i170.com/Article/104990/commentRss</wfw:commentRss></item> <item><link>http://www.i170.com/Article/104830</link><title><![CDATA[还“技术”一片净土...]]></title><author>demonalex</author><category>胡言乱语</category><pubDate>Tue, 29 Apr 2008 08:45:09  +0800</pubDate><description><![CDATA[<p>无法否认，若技术不能放在社会生产当中的话，多么高的技术都是白费的，，，，，因此只有技术与市场挂钩才是王道。。。。</p>
<p>
但现在的技术领域非常的浮躁、浮夸（不能排除我自己也在其中。。。），但其实我希望的不是这样，昨天与朋友们出来聊天时才发现了这点：我本来是希望朋友能大家真诚的对话，能集思广益达至讨论出一个方向的，但结果变成了“攀比”，回家后落笔写文档时却发现比未去聚会时思绪更乱，很明显，集思广益无法达到预期的效果同时更增添了一份惆怅。</p>
<p>&nbsp;</p>
<p>
后来总结了一下原因，除由于自己无法控制情绪外还需要保持一份对原始技术的探索思路--谦虚与“求同存异”的精神。是否因为时间的关系使我慢慢淡忘了这种“乞丐不停地向人乞讨”的‘低下精神’了呢？另外如果我更具备一种可以讨人喜欢的性格，那该多好呢？--世界会更加和谐。。。。。。OVER，上班去喏：）</p>

]]></description><guid>http://www.i170.com/Article/104830</guid><trackback:ping>http://www.i170.com/Article/104830/trackback</trackback:ping><comments>http://www.i170.com/Article/104830#comment</comments><wfw:commentRss>http://www.i170.com/Article/104830/commentRss</wfw:commentRss></item> <item><link>http://www.i170.com/Article/104655</link><title><![CDATA[nasl插件生成器（带源码）]]></title><author>demonalex</author><category>安全技术</category><pubDate>Sat, 26 Apr 2008 23:28:39  +0800</pubDate><description><![CDATA[<p><img width="575" height="450" alt="" src=
"http://www.i170.com/Attach/90927542-9519-4C12-9118-10CC76C4707A"></p>
<p>下载地址：<a href=
"http://www.i170.com/Attach/473E8321-8D19-412D-93CC-3C2095172DC1">www.i170.com/Attach/473E8321-8D19-412D-93CC-3C2095172DC1</a></p>

]]></description><guid>http://www.i170.com/Article/104655</guid><trackback:ping>http://www.i170.com/Article/104655/trackback</trackback:ping><comments>http://www.i170.com/Article/104655#comment</comments><wfw:commentRss>http://www.i170.com/Article/104655/commentRss</wfw:commentRss></item> <item><link>http://www.i170.com/Article/104174</link><title><![CDATA[4月16日]]></title><author>demonalex</author><category>写真图鉴</category><pubDate>Thu, 17 Apr 2008 01:45:47  +0800</pubDate><description><![CDATA[<p>中午匆匆找了个快餐店，吃了个手撕鸡饭，很难吃，居然还要30块。。。套餐，纳闷。。。</p>
<p><img width="320" height="240" alt="" src=
"http://www.i170.com/Attach/FF6C3B90-9A0B-460D-A795-CAF58CCB358C"></p>
<p>下午见到一台1.5G的家伙--趋势的垃圾邮件过滤系统：</p>
<p><img width="320" height="240" alt="" src=
"http://www.i170.com/Attach/F4891460-B82C-48F1-8F11-CAD4962E2BD1"></p>
<p>x86,看看型号：</p>
<p><img width="320" height="240" alt="" src=
"http://www.i170.com/Attach/72B918B9-D076-4F08-A408-83E8B4B83FC1"></p>
<p>测试者告诉我一个字，至于是什么字，聪明的你一定想得到，，，，，我什么也没说过：P</p>

]]></description><guid>http://www.i170.com/Article/104174</guid><trackback:ping>http://www.i170.com/Article/104174/trackback</trackback:ping><comments>http://www.i170.com/Article/104174#comment</comments><wfw:commentRss>http://www.i170.com/Article/104174/commentRss</wfw:commentRss></item> <item><link>http://www.i170.com/Article/104145</link><title><![CDATA[WEB暴力破解--我用wvs fuzzer]]></title><author>demonalex</author><category>安全技术</category><pubDate>Wed, 16 Apr 2008 00:17:50  +0800</pubDate><description><![CDATA[<p style="" class="MsoNormal"><span lang=
"EN-US">WEB</span><span style=
"font-family: 宋体;">暴力破解</span><span lang=
"EN-US">--</span><span style=
"font-family: 宋体;">我用</span><span lang="EN-US">wvs
fuzzer</span></p>
<p class="MsoNormal"><span lang="EN-US">Writer:
demonalex[at]dark2s[dot]org</span></p>
<p class="MsoNormal"><span lang=
"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span lang=
"EN-US"><o:p>&nbsp;</o:p></span></p>
<p style="text-indent: 21pt;" class="MsoNormal"><span style=
"font-family: 宋体;">讲到</span><span lang=
"EN-US">WEB</span><span style=
"font-family: 宋体;">暴力破解通过大家都会用小榕的溯雪，但并不是所有</span><span lang=
"EN-US">WEB</span><span style=
"font-family: 宋体;">破解溯雪都是应付自如的（不要说我说小榕他老人家的坏话），最近因为工作的关系，碰到一个网管型设备的</span><span lang="EN-US">WEBPORTAL</span><span style="font-family: 宋体;">需要做</span><span lang="EN-US">WEB</span><span style="font-family: 宋体;">破解，看看</span><span lang="EN-US">HTML</span><span style="font-family: 宋体;">的源码：</span></p>
<p class="MsoNormal"><span lang="EN-US">…</span></p>
<p class="MsoNormal"><span lang="EN-US">&lt;script
language=javascript&gt;</span></p>
<p class="MsoNormal"><span lang="EN-US">function
login_send()</span></p>
<p class="MsoNormal"><span lang="EN-US">{</span></p>
<p class="MsoNormal"><span lang="EN-US"><span style=
"">&nbsp;</span> var f, p, page, url, option;</span></p>
<p class="MsoNormal"><span lang="EN-US"><span style=
"">&nbsp;</span> f =
document.form_login.forced_in.value;</span></p>
<p class="MsoNormal"><span lang="EN-US"><span style=
"">&nbsp;</span> u = document.form_login.username.value;</span></p>
<p class="MsoNormal"><span lang="EN-US"><span style=
"">&nbsp;</span> p = document.form_login.passwd.value;</span></p>
<p class="MsoNormal"><span lang="EN-US"><span style=
"">&nbsp;</span> pg = document.form_login.page.value;</span></p>
<p class="MsoNormal"><span lang="EN-US"><span style=
"">&nbsp;</span> url =
"atm_login?username="+u+"&amp;passwd="+p+"&amp;forced_in="+f+"&amp;page="+pg;</span></p>
<p class="MsoNormal"><span lang="EN-US"><span style=
"">&nbsp;</span> option =
"toolbar=no,location=no,directories=no,status=no,menubar=no,scrollbars=no,favorites=no,resizable=no,left=230,width=520,top=120,height=300";</span></p>
<p class="MsoNormal"><span lang="EN-US"><span style=
"">&nbsp;</span> window.open(url, '_blank', option);</span></p>
<p class="MsoNormal"><span lang="EN-US">}</span></p>
<p class="MsoNormal"><span lang="EN-US">&lt;/script&gt;</span></p>
<p class="MsoNormal"><span lang="EN-US">…</span></p>
<p class="MsoNormal"><span lang="EN-US">&lt;form name='form_login'
<span style=
"color: red;">action='___Javascript:login_send();'</span>&gt;</span></p>
<p class="MsoNormal"><span lang="EN-US"><span style=
"">&nbsp;&nbsp;&nbsp;</span> <span style=
"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span> &lt;input
type='hidden' name='forced_in' value='false'&gt;&lt;input
type='hidden' name=page value=''&gt;&lt;input type='hidden'
name='redirect_portal_ip' value=''&gt;</span></p>
<p class="MsoNormal"><span lang="EN-US"><span style=
"">&nbsp;&nbsp;&nbsp;</span> <span style=
"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span> &lt;tr
height=25%&gt;&lt;td colspan='2'&gt;&lt;img
src='images/login-men.gif' width='177'
height='22'&gt;&lt;/td&gt;</span></p>
<p class="MsoNormal"><span lang="EN-US"><span style=
"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span>
&lt;td width='27%' rowspan='4'&gt;&lt;img src='images/l-hand.gif'
width='148' height='141'&gt;&lt;/td&gt;&lt;/tr&gt;</span></p>
<p class="MsoNormal"><span lang="EN-US"><span style=
"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span>
&lt;tr height=25%&gt;&lt;td width='28%'
class='inputlabel'&gt;Username:&lt;/td&gt;</span></p>
<p class="MsoNormal"><span lang="EN-US"><span style=
"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span>
&lt;td width='45%'&gt;&lt;input name='username' type='text'
value='' style='width:120px'
class='inputbox'&gt;&lt;/td&gt;&lt;/tr&gt;</span></p>
<p style="" class="MsoNormal"><span lang="EN-US"><span style=
"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span> &lt;tr
height=25%&gt;&lt;td
class='inputlabel'&gt;Password:&lt;/td&gt;</span></p>
<p class="MsoNormal"><span lang="EN-US"><span style=
"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span>
&lt;td&gt;&lt;input type='password' name='passwd' value=''
style='width:120px'
class='inputbox'&gt;&lt;/td&gt;&lt;/tr&gt;</span></p>
<p style="" class="MsoNormal"><span lang="EN-US"><span style=
"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span> &lt;tr
height=25%&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;</span></p>
<p class="MsoNormal"><span lang="EN-US"><span style=
"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span>
&lt;td&gt;&lt;input type=image src=images/login-go.gif width='71'
height='22'&gt;&lt;/td&gt;&lt;/tr&gt;</span></p>
<p style="" class="MsoNormal"><span lang="EN-US"><span style=
"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span>
&lt;/from&gt;</span></p>
<p class="MsoNormal"><span lang="EN-US">…</span></p>
<p class="MsoNormal"><span style=
"font-family: 宋体;">这里</span><span lang=
"EN-US">form</span><span style=
"font-family: 宋体;">的</span><span lang=
"EN-US">action</span><span style=
"font-family: 宋体;">是交给一个本地的</span><span lang="EN-US" style=
"color: red;">javascript</span><span style=
"font-family: 宋体; color: red;">自定义函数</span><span lang="EN-US"
style="color: red;">-- login_send</span><span style=
"font-family: 宋体;">来完成的，用溯雪的话：</span></p>
<p class="MsoNormal"><span style="font-family: 宋体;"><img width=
"640" height="421" src=
"http://www.i170.com/Attach/DB7C2D36-E3BF-43DD-A2C2-85A975D3ACC6"
alt=""></span></p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal"><span style=
"font-family: 宋体;">看来是因为调用了</span><span lang=
"EN-US">javascript</span><span style=
"font-family: 宋体;">的关系吧</span><span lang="EN-US">…</span></p>
<p class="MsoNormal"></p>
<p class="partingline">[separator]</p>
<p style="text-indent: 21pt;" class="MsoNormal"><span style=
"font-family: 宋体;">怎么办？就这样放弃吗？这也大可不必，调出</span><span lang=
"EN-US">wvs</span><span style=
"font-family: 宋体;">（</span><span lang="EN-US">Acunetix Web
Vulnerability Scanner</span><span style=
"font-family: 宋体;">，相信都不少同志都用过它吧？我用的是</span><span lang=
"EN-US">4.0</span><span style=
"font-family: 宋体;">，目前最新的版本是</span><span lang=
"EN-US">5.x</span><span style=
"font-family: 宋体;">），选择它的</span><span lang="EN-US">HTTP
fuzzer</span><span style="font-family: 宋体;">功能：</span></p>
<p><img width="640" height="402" src=
"http://www.i170.com/Attach/0B39DFFC-50A1-4B51-B3F4-FA91E26BCD0C"
alt=""></p>
<p>&nbsp;</p>
<p class="MsoNormal"><span style=
"font-family: 宋体;">然后怎么使用它呢？我整理了一下流程（其实和溯雪的原理差不多，不过可能需要更深入的了解</span><span lang="EN-US">HTTP</span><span style="font-family: 宋体;">的相关知识）：</span></p>
<p class="MsoNormal"><span style=
"font-family: 宋体;">定义</span><span lang=
"EN-US">HTTP</span><span style=
"font-family: 宋体;">请求（</span><span lang=
"EN-US">Request</span><span style=
"font-family: 宋体;">）</span><span lang="EN-US">-</span><span style=
"font-family: 宋体;">》定义暴破运算参数（</span><span lang="EN-US">Add
generator</span><span style="font-family: 宋体;">）</span><span lang=
"EN-US">-</span><span style=
"font-family: 宋体;">》插入暴破运算参数（</span><span lang="EN-US">Insert into
request</span><span style="font-family: 宋体;">）</span><span lang=
"EN-US">-</span><span style=
"font-family: 宋体;">》定义成功触发特征（</span><span lang="EN-US">Fuzzer
Filters</span><span style="font-family: 宋体;">）</span><span lang=
"EN-US">-</span><span style=
"font-family: 宋体;">》扫描（</span><span lang=
"EN-US">Start</span><span style="font-family: 宋体;">）</span></p>
<p style="text-indent: 21.75pt;" class="MsoNormal"><span style=
"font-family: 宋体;">下面讲将具体实操，首先我们从目标的</span><span lang=
"EN-US">HTML</span><span style=
"font-family: 宋体;">代码可以看到，其实登陆过程是通过</span><span lang=
"EN-US">POST</span><span style=
"font-family: 宋体;">的四个参数</span><span lang=
"EN-US">[--</span><span style=
"font-family: 宋体;">两个隐藏参数（</span><span lang=
"EN-US">forced_in</span><span style=
"font-family: 宋体;">与</span><span lang=
"EN-US">page</span><span style=
"font-family: 宋体;">）与两个提交参数（</span><span lang=
"EN-US">username</span><span style=
"font-family: 宋体;">与</span><span lang=
"EN-US">passwd</span><span style=
"font-family: 宋体;">）</span><span lang="EN-US">]</span><span style=
"font-family: 宋体;">至本页的</span><span lang=
"EN-US">login_send</span><span style=
"font-family: 宋体;">函数，然后再通过</span><span lang="EN-US">GET
atm_login</span><span style=
"font-family: 宋体;">这个页面提交认证数据。因此在使用</span><span lang="EN-US">wvs
fuzzer</span><span style=
"font-family: 宋体;">前我们首先需要定义提交</span><span lang=
"EN-US">HTTP</span><span style=
"font-family: 宋体;">请求的内容，具体如：</span></p>
<p align="left" style="text-align: left;" class="MsoNormal">
<span lang="EN-US">GET http://xxx.xxx.xxx.xxx/
atm_login?username=alex&amp;passwd=demon&amp;forced_in=false&amp;page=
HTTP/1.1</span></p>
<p align="left" style="text-align: left;" class="MsoNormal">
<span lang="EN-US">User-Agent: WVS/4.0</span></p>
<p align="left" style="text-align: left;" class="MsoNormal">
<span lang="EN-US">Accept: */*</span></p>
<p class="MsoNormal"><span style=
"font-family: 宋体;">下面是加入暴破运算参数至</span><span lang=
"EN-US">HTTP</span><span style=
"font-family: 宋体;">请求内容中，基于我们本次的目标是帐号（</span><span lang=
"EN-US">username</span><span style=
"font-family: 宋体;">字段）与密码（</span><span lang=
"EN-US">passwd</span><span style=
"font-family: 宋体;">字段），因此需要定义两个运算参数，本例中我打算让</span><span lang=
"EN-US">username</span><span style=
"font-family: 宋体;">进行暴力破解，而</span><span lang=
"EN-US">passwd</span><span style=
"font-family: 宋体;">则进行字典破解。</span></p>
<p style="text-indent: 21pt;" class="MsoNormal"><span style=
"font-family: 宋体;">废话少说，先建立一个基于暴力破解的</span><span lang=
"EN-US">username</span><span style=
"font-family: 宋体;">运算参数：点击“</span><span lang="EN-US">Add
generator</span><span style="font-family: 宋体;">”</span><span lang=
"EN-US">-</span><span style="font-family: 宋体;">》“</span><span lang=
"EN-US">Random string generator</span><span style=
"font-family: 宋体;">”后得到：</span></p>
<p><img width="447" height="315" src=
"http://www.i170.com/Attach/E13B55C2-5480-4A06-B6EB-C0FF89E65DA8"
alt=""></p>
<p>&nbsp;</p>
<p class="MsoNormal"><span style=
"font-family: 宋体;">在“</span><span lang="EN-US">String
length</span><span style=
"font-family: 宋体;">”中填入值的长度，我这里选择</span><span lang=
"EN-US">5</span><span style="font-family: 宋体;">；“</span><span lang=
"EN-US">Character set</span><span style=
"font-family: 宋体;">”中输入可能需要用到的字符，我这里选择</span><span lang=
"EN-US">26</span><span style=
"font-family: 宋体;">个小写字母；选择“</span><span lang="EN-US">Allow
repetitions</span><span style=
"font-family: 宋体;">”</span><span lang="EN-US">—</span><span style=
"font-family: 宋体;">允许重复使用各字符。</span></p>
<p style="text-indent: 21.75pt;" class="MsoNormal"><span style=
"font-family: 宋体;">然后再加入一个用于通过字典破解</span><span lang=
"EN-US">passwd</span><span style=
"font-family: 宋体;">字段的运算参数：点击“</span><span lang="EN-US">Add
generator</span><span style="font-family: 宋体;">”</span><span lang=
"EN-US">-</span><span style="font-family: 宋体;">》“</span><span lang=
"EN-US">File generator</span><span style=
"font-family: 宋体;">”后得到：</span></p>
<p><img width="446" height="318" src=
"http://www.i170.com/Attach/61D651A4-7E82-4C7F-BE28-21B4C785F02B"
alt=""></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p class="MsoNormal"><span style=
"font-family: 宋体;">“</span><span lang=
"EN-US">Filename</span><span style=
"font-family: 宋体;">”为字典文件的路径；“</span><span lang=
"EN-US">Filetype</span><span style=
"font-family: 宋体;">”则为读取内容的格式，多数为文本（</span><span lang=
"EN-US">Text</span><span style="font-family: 宋体;">）。</span></p>
<p style="text-indent: 21.75pt;" class="MsoNormal"><span style=
"font-family: 宋体;">下面要做的工作就是将两个运算参数加入</span><span lang=
"EN-US">HTTP</span><span style=
"font-family: 宋体;">请求中。首先在选择本例中</span><span lang=
"EN-US">username</span><span style=
"font-family: 宋体;">的值（本例为</span><span lang=
"EN-US">alex</span><span style=
"font-family: 宋体;">），然后选择</span><span lang=
"EN-US">Gen_1</span><span style=
"font-family: 宋体;">，并点击“</span><span lang="EN-US">Insert into
request</span><span style="font-family: 宋体;">”按钮，得到：</span></p>
<p><img width="640" height="402" src=
"http://www.i170.com/Attach/5A4C02E5-869C-4A2C-A235-52958E0B0D4C"
alt=""></p>
<p>&nbsp;</p>
<p class="MsoNormal"><span style=
"font-family: 宋体;">从右上角可以看到，目前的请求数量为</span><span lang=
"EN-US">11881376</span><span style=
"font-family: 宋体;">个（换句话说，有</span><span lang=
"EN-US">11881376</span><span style=
"font-family: 宋体;">个组合）。再以相同的方式用</span><span lang=
"EN-US">Gen_2</span><span style=
"font-family: 宋体;">替换</span><span lang=
"EN-US">passwd</span><span style=
"font-family: 宋体;">字段的值（本例为</span><span lang=
"EN-US">demon</span><span style="font-family: 宋体;">），得到：</span></p>
<p><img width="640" height="402" src=
"http://www.i170.com/Attach/544159B7-22BF-44B6-96C2-FCCB26FB957F"
alt=""></p>
<p>&nbsp;</p>
<p class="MsoNormal"><span style=
"font-family: 宋体;">嘿嘿，现在的请求数大到差不多等于无限了吧？？？</span><span lang=
"EN-US">…</span></p>
<p style="text-indent: 21pt;" class="MsoNormal"><span style=
"font-family: 宋体;">接下来就是定义确认‘登陆成功’的过滤器（</span><span lang=
"EN-US">Fuzzer Filter</span><span style=
"font-family: 宋体;">）。点击“</span><span lang="EN-US">Fuzzer
filters</span><span style=
"font-family: 宋体;">”进入定义过滤器的界面，默认情况下只有“</span><span lang=
"EN-US">200</span><span style=
"font-family: 宋体;">”的过滤器是激活的，去掉它前面的勾勾，然后自己定义一个名为</span><span lang=
"EN-US">success</span><span style=
"font-family: 宋体;">的过滤器，由于本例中若登陆成功的话应该是不会回到原有的登陆界面的，因此只需要定义一个‘排除登陆页面特征’的过滤器并激活就可以了：</span></p>
<p><img width="640" height="404" src=
"http://www.i170.com/Attach/35AD87C8-6833-4514-8750-A2816BF4A04D"
alt=""></p>
<p>&nbsp;</p>
<p class="MsoNormal"><span style=
"font-family: 宋体;">来到这里，按下“</span><span lang=
"EN-US">OK</span><span style=
"font-family: 宋体;">”按钮确认刚刚对过滤器的设置。</span></p>
<p style="text-indent: 21pt;" class="MsoNormal"><span style=
"font-family: 宋体;">最后回到</span><span lang="EN-US">HTTP
Fuzzer</span><span style=
"font-family: 宋体;">主界面点击“</span><span lang="EN-US">Start</span><span style="font-family: 宋体;">”按钮即可启动本</span><span lang="EN-US">fuzz</span><span style="font-family: 宋体;">任务，剩下的工作就是‘守株待兔’了</span><span lang="EN-US">—</span><span style="font-family: 宋体;">等待“</span><span lang="EN-US">Results</span><span style="font-family: 宋体;">”分页的</span><span lang="EN-US">fuzz</span><span style="font-family: 宋体;">结果，嘿嘿，</span><span lang="EN-US">Good
Luck</span><span lang="EN-US" style=
"font-family: Wingdings;"><span style=
"">J</span></span><span style="font-family: 宋体;">。</span></p>
<p style="text-indent: 21pt;" class="MsoNormal">&nbsp;</p>

]]></description><guid>http://www.i170.com/Article/104145</guid><trackback:ping>http://www.i170.com/Article/104145/trackback</trackback:ping><comments>http://www.i170.com/Article/104145#comment</comments><wfw:commentRss>http://www.i170.com/Article/104145/commentRss</wfw:commentRss></item> </channel></rss>