
Exploit
Exploit的英文意思就是利用,它在黑客眼里就是漏洞利用,有漏洞不一定就有Exploit(利用),有Exploit就肯定有漏洞。
我們幾乎每隔幾天就能聽到最近有一個新發(fā)現(xiàn)的可以被利用(exploit)的漏洞(vulnerability),然后給這個漏洞打上補丁。而事實上,這里面的內(nèi)容比你想象的要多,因為你不可能知道所有軟件的漏洞,而且那些可利用的漏洞也只是被少數(shù)人所了解。
漏洞是存在于一個程序、算法或者協(xié)議中的錯誤,可能帶來一定的安全問題。但不是所有的漏洞都是能夠被利用來攻擊(exploitable)的,理論上存在的漏洞,并不代表這個漏洞足以讓攻擊者去威脅你的系統(tǒng)。一個漏洞不能攻擊一個系統(tǒng),并不代表兩個或多個漏洞組合就不能攻擊一個系統(tǒng)。例如:空指針對象引用(null-pointerdereferencing)漏洞可以導(dǎo)致系統(tǒng)崩潰(如果想做拒絕服務(wù)攻擊就足夠了),但是如果組合另外一個漏洞,將空指針指向一個你存放數(shù)據(jù)的地址并執(zhí)行,那么你可能就利用此來控制這個系統(tǒng)了。
一個利用程序(Anexploit)就是一段通過觸發(fā)一個漏洞(或者幾個漏洞)進而控制目標系統(tǒng)的代碼。攻擊代碼通常會釋放攻擊載荷(payload),里面包含了攻擊者想要執(zhí)行的代碼。exploits利用代碼可以在本地也可在遠程進行。一個遠程攻擊利用允許攻擊者遠程操縱計算機,理想狀態(tài)下能夠執(zhí)行任意代碼。遠程攻擊對攻擊者非常重要,因為攻擊者可以遠程控制他/她的主機,不需要通過其它手段(讓受害者訪問網(wǎng)站,點擊一個可執(zhí)行文件,打開一個郵件附件等等),而本地攻擊一般都是用來提升權(quán)限。
Mercury Mail 4.0.1 (LOGIN) Remote IMAP Stack Buffer Overflow Exploit
#!/usr/bin/perl # # http://www.securityfocus.com/bid/11775 # credit to Muts for this vulnerability # acaro [at] jervus.it use IO::Socket::INET; us... 08-10-08Maian Cart 1.1 Insecure Cookie Handling Vulnerability
Author: Saime Date: July 12, 2008 Script: Maian Cart v1.1 Insecure Cookie Handling Vulnerability URL: http://www.maianscriptworld.co.uk Dork: Powered by Maian... 08-10-08Million Pixels 3 (id_cat) Remote SQL Injection Vulnerability
################################################################# # # Million Pixels 3 (id_cat) Remote SQL Injection Vulnerability # #======================... 08-10-08Maian Gallery 2.0 Insecure Cookie Handling Vulnerability
Author: Saime Date: July 12, 2008 Script: Maian Gallery v2.0 Insecure Cookie Handling Vulnerability URL: http://www.maianscriptworld.co.uk Dork: Maian Gallery... 08-10-08Maian Events 2.0 Insecure Cookie Handling Vulnerability
Author: Saime Date: July 12, 2008 Script: Maian Events v2.0 Insecure Cookie Handling Vulnerability URL: http://www.maianscriptworld.co.uk Dork: Maian Events v... 08-10-08Maian Music 1.0 Insecure Cookie Handling Vulnerability
Author: Saime Date: July 12, 2008 Script: Maian Music v1.0 Insecure Cookie Handling Vulnerability URL: http://www.maianscriptworld.co.uk Dork: Maian Music v1.... 08-10-08Maian Greetings 2.1 Insecure Cookie Handling Vulnerability
Author: Saime Date: July 12, 2008 Script: Maian Greetings v2.1 Insecure Cookie Handling Vulnerability URL: http://www.maianscriptworld.co.uk Dork: Powered by:... 08-10-08Joomla Component n-forms 1.01 Blind SQL Injection Exploit
#!/usr/bin/perl use LWP::UserAgent; use Getopt::Long; if(!$ARGV[1]) { print " n&quo... 08-10-08fuzzylime cms 3.01 (polladd.php poll) Remote Code Execution Exploit (php)
#!/usr/bin/php <?php ## ## Fuzzylime 3.01 Remote Code Execution ## Credits: Inphex and real ## ## [C:]# php fuzzylime.php http://www.target.com/fuzzy... 08-10-08fuzzylime cms 3.01 (polladd.php poll) Remote Code Execution Exploit (pl)
#!/usr/bin/perl #!!UPDATED!!!!UPDATED!!!!UPDATED!!!!UPDATED!!!!UPDATED!!!!UPDATED!!!!UPDATED!! #after i noticed that there was a problem changing $cmd,i fixed it.t... 08-10-08WebCMS Portal Edition (id) Remote SQL Injection Vulnerability
############################################################### #################### Viva IslaM Viva IslaM #################### ## ## Remote SQL InjEcti0n Vulner... 08-10-08Avlc Forum (vlc_forum.php id) Remote SQL Injection Vulnerability
==================================================================== Avlc Forum (vlc_forum.php id) Remote SQL Injection Vulnerability ============================... 08-10-08jSite 1.0 OE (SQL/LFI) Multiple Remote Vulnerabilities
--== ================================================================================ ==-- --== jSite 1.0 OE Multiple Remote SQL/LFI Vulnerbility ... 08-10-08fuzzylime cms 3.01 (commrss.php) Remote Code Execution Exploit
<?php ## ## Name: Fuzzylime 3.01 Remote Code Execution Exploit ## Credits: Charles "real" F. <charlesfol[at]hotmail.fr> ## ## C... 08-10-08- -[*] ================================================================================ [*]- -[*] Maian Recipe <= v1.2 Insecure Cookie Handling Vulnerabili... 08-10-08
- -[*] ================================================================================ [*]- -[*] Maian Guestbook <= 3.2 Insecure Cookie Handling Vulnerabil... 08-10-08
- -[*] ================================================================================ [*]- -[*] Maian Weblog <= v4.0 Insecure Cookie Handling Vulnerabili... 08-10-08
- -[*] ================================================================================ [*]- -[*] Maian Search <= v1.1 Insecure Cookie Handling Vulnerabilit... 08-10-08
- -[*] ================================================================================ [*]- -[*] Maian Uploader <= v4.0 Insecure Cookie Handling Vulnerabili... 08-10-08
- #!/usr/bin/perl # # quickbite.pl # # Safari Quicktime <= 7.3 RTSP Content-Type overflow exploit # for Mac OS X (Intel) # # Tested with OS X 10.4... 08-10-08