<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>空想枫 &#187; security</title>
	<atom:link href="http://blog.it580.com/tag/security/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.it580.com</link>
	<description>一个IT从业者的枫言枫语</description>
	<lastBuildDate>Tue, 09 Mar 2010 07:03:58 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>zh</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/>		<item>
		<title>开源防SQL注入工具-GreenSQL</title>
		<link>http://blog.it580.com/2097</link>
		<comments>http://blog.it580.com/2097#comments</comments>
		<pubDate>Wed, 09 Dec 2009 14:16:07 +0000</pubDate>
		<dc:creator>David</dc:creator>
				<category><![CDATA[新闻]]></category>
		<category><![CDATA[greensql]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.it580.com/2097</guid>
		<description><![CDATA[ 
GreenSQL最近出了1.2.0版本。目前只支持MySQL和PostgreSQL的保护。
采用如上架构图的代理方式，代理默认运行于3305端口，由于MySQL默认运行于3306端口，原应用只需要修改数据库端口就可以。 

&#160; GreenSQL的web管理界面

© David for 空想枫, 2009. &#124;
Permalink &#124;
One comment &#124;
Add to
del.icio.us


	Tags: greensql, security

	Related posts
	
	iPhone破解手机请立即修改密码 (0)
	微软紧急安全补丁(MS08-067) (0)
	DNS漏洞大问题 (0)
	ratproxy Web应用安全审计工具 (0)
	WordPress 漏洞扫描插件 (0)


]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.it580.com/wp-content/uploads/2009/12/logo2.gif"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="logo[2]" border="0" alt="logo[2]" src="http://blog.it580.com/wp-content/uploads/2009/12/logo2_thumb.gif" width="100" height="65" /></a> </p>
<p><a href="http://www.greensql.net/" target="_blank">GreenSQL</a>最近出了1.2.0版本。目前只支持MySQL和PostgreSQL的保护。</p>
<p><a href="http://blog.it580.com/wp-content/uploads/2009/12/greensqlarchitecture.preview1.jpg"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="greensql-architecture.preview[1]" border="0" alt="greensql-architecture.preview[1]" src="http://blog.it580.com/wp-content/uploads/2009/12/greensqlarchitecture.preview1_thumb.jpg" width="484" height="134" /></a>采用如上架构图的代理方式，代理默认运行于3305端口，由于MySQL默认运行于3306端口，原应用只需要修改数据库端口就可以。 </p>
</p>
<p><a href="http://blog.it580.com/wp-content/uploads/2009/12/image3.png"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://blog.it580.com/wp-content/uploads/2009/12/image_thumb3.png" width="484" height="364" /></a>&#160; <br />GreenSQL的web管理界面</p>
<img src="http://blog.it580.com/?ak_action=api_record_view&id=2097&type=feed" alt="" /><hr />
<p><small>© David for <a href="http://blog.it580.com">空想枫</a>, 2009. |
<a href="http://blog.it580.com/2097">Permalink</a> |
<a href="http://blog.it580.com/2097#comments">One comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://blog.it580.com/2097&title=开源防SQL注入工具-GreenSQL">del.icio.us</a>
<br/>
</small></p>
	Tags: <a href="http://blog.it580.com/tag/greensql" title="greensql" rel="tag nofollow">greensql</a>, <a href="http://blog.it580.com/tag/security" title="security" rel="tag nofollow">security</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.it580.com/2073" title="iPhone破解手机请立即修改密码 (2009 11-3)">iPhone破解手机请立即修改密码</a> (0)</li>
	<li><a href="http://blog.it580.com/1472" title="微软紧急安全补丁(MS08-067) (2008 10-24)">微软紧急安全补丁(MS08-067)</a> (0)</li>
	<li><a href="http://blog.it580.com/1279" title="DNS漏洞大问题 (2008 7-9)">DNS漏洞大问题</a> (0)</li>
	<li><a href="http://blog.it580.com/1232" title="ratproxy Web应用安全审计工具 (2008 7-3)">ratproxy Web应用安全审计工具</a> (0)</li>
	<li><a href="http://blog.it580.com/1189" title="WordPress 漏洞扫描插件 (2008 6-29)">WordPress 漏洞扫描插件</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.it580.com/2097/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>iPhone破解手机请立即修改密码</title>
		<link>http://blog.it580.com/2073</link>
		<comments>http://blog.it580.com/2073#comments</comments>
		<pubDate>Tue, 03 Nov 2009 03:01:34 +0000</pubDate>
		<dc:creator>David</dc:creator>
				<category><![CDATA[iPhone]]></category>
		<category><![CDATA[jailbreak]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.it580.com/2073</guid>
		<description><![CDATA[国内的iPhone手机用户们，为解决破解版本iPhone的巨大安全漏洞，请立即修改iPhone 手机的root和mobile用户的密码。
&#160;
1.安装mobileterminal，如果你的机器上没有这个App的话。
2.打开该App后，逐条运行如下命令：
passwd root
passwd mobile

每执行一条命令后，需要重复输入两次你想设置的密码(新设密码建议包含字母大小写及数字)。如果提示没有权限的信息。请先执行如下命令:
su root

3.完成，并记住自己重新设置的密码。

© David for 空想枫, 2009. &#124;
Permalink &#124;
No comment &#124;
Add to
del.icio.us


	Tags: iPhone, jailbreak, security

	Related posts
	
	redsn0w 0.9 发布-iPhone破解及解锁工具 (0)
	iPad 越狱照片出现 (0)
	开源防SQL注入工具-GreenSQL (1)
	Ultrasn0w 0.6(iPhone 3G解锁发布) (0)
	iPhone 3.0固件放出 (0)


]]></description>
			<content:encoded><![CDATA[<p>国内的iPhone手机用户们，为解决破解版本iPhone的巨大安全漏洞，请立即修改iPhone 手机的root和mobile用户的密码。</p>
<p>&#160;</p>
<p>1.安装<a href="http://code.google.com/p/mobileterminal/">mobileterminal</a>，如果你的机器上没有这个App的话。</p>
<p>2.打开该App后，逐条运行如下命令：</p>
<blockquote><p>passwd root</p>
<p>passwd mobile</p>
</blockquote>
<p>每执行一条命令后，需要重复输入两次你想设置的密码(新设密码建议包含字母大小写及数字)。如果提示没有权限的信息。请先执行如下命令:</p>
<blockquote><p>su root</p>
</blockquote>
<p>3.完成，并记住自己重新设置的密码。</p>
<img src="http://blog.it580.com/?ak_action=api_record_view&id=2073&type=feed" alt="" /><hr />
<p><small>© David for <a href="http://blog.it580.com">空想枫</a>, 2009. |
<a href="http://blog.it580.com/2073">Permalink</a> |
<a href="http://blog.it580.com/2073#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://blog.it580.com/2073&title=iPhone破解手机请立即修改密码">del.icio.us</a>
<br/>
</small></p>
	Tags: <a href="http://blog.it580.com/tag/iphone" title="iPhone" rel="tag nofollow">iPhone</a>, <a href="http://blog.it580.com/tag/jailbreak" title="jailbreak" rel="tag nofollow">jailbreak</a>, <a href="http://blog.it580.com/tag/security" title="security" rel="tag nofollow">security</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.it580.com/2142" title="redsn0w 0.9 发布-iPhone破解及解锁工具 (2010 1-31)">redsn0w 0.9 发布-iPhone破解及解锁工具</a> (0)</li>
	<li><a href="http://blog.it580.com/2141" title="iPad 越狱照片出现 (2010 1-28)">iPad 越狱照片出现</a> (0)</li>
	<li><a href="http://blog.it580.com/2097" title="开源防SQL注入工具-GreenSQL (2009 12-9)">开源防SQL注入工具-GreenSQL</a> (1)</li>
	<li><a href="http://blog.it580.com/2027" title="Ultrasn0w 0.6(iPhone 3G解锁发布) (2009 6-23)">Ultrasn0w 0.6(iPhone 3G解锁发布)</a> (0)</li>
	<li><a href="http://blog.it580.com/2017" title="iPhone 3.0固件放出 (2009 6-18)">iPhone 3.0固件放出</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.it580.com/2073/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>微软紧急安全补丁(MS08-067)</title>
		<link>http://blog.it580.com/1472</link>
		<comments>http://blog.it580.com/1472#comments</comments>
		<pubDate>Fri, 24 Oct 2008 08:28:53 +0000</pubDate>
		<dc:creator>David</dc:creator>
				<category><![CDATA[手记]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://blog.it580.com/1472</guid>
		<description><![CDATA[该补丁修正了Windows Server服务在处理RPC请求时的漏洞，该漏洞属于“紧急”级别。远程攻击者可以利用该漏洞远程入侵并完全控制系统。请立即更新该补丁！
该漏洞基本影响主流微软操作系统，包含:Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista,Windows Server 2008.
漏洞信息相关链接:   US-CERT Vulnerability Note: VU#827267    XF win-server-rpc-code-execution(46040)    FRSIRT ADV-2008-2902    SECUNIA 32326    CVE-2008-4250    Microsoft Knowledge Base Article 958644
英文系统下载补丁链接:   Microsoft Windows 2000 Service Pack 4  [...]]]></description>
			<content:encoded><![CDATA[<p>该补丁修正了Windows Server服务在处理RPC请求时的漏洞，该漏洞属于“紧急”级别。远程攻击者可以利用该漏洞远程入侵并完全控制系统。<font color="#ff0000">请立即更新该补丁！</font></p>
<p>该漏洞基本影响主流微软操作系统，包含:Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista,Windows Server 2008.</p>
<p>漏洞信息相关链接:   <br /><a href="http://www.kb.cert.org/vuls/id/827267" target="_blank">US-CERT Vulnerability Note: VU#827267</a>    <br /><a href="http://xforce.iss.net/xforce/xfdb/46040" target="_blank">XF win-server-rpc-code-execution(46040)</a>    <br /><a href="http://www.frsirt.com/english/advisories/2008/2902" target="_blank">FRSIRT ADV-2008-2902</a>    <br /><a href="http://secunia.com/advisories/32326" target="_blank">SECUNIA 32326</a>    <br /><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4250" target="_blank">CVE-2008-4250</a>    <br /><a href="http://support.microsoft.com/kb/958644">Microsoft Knowledge Base Article 958644</a></p>
<p>英文系统下载补丁链接:   <br /><a href="http://www.microsoft.com/downloads/details.aspx?familyid=E22EB3AE-1295-4FE2-9775-6F43C5C2AED3">Microsoft Windows 2000 Service Pack 4</a>    <br /><a href="http://www.microsoft.com/downloads/details.aspx?familyid=0D5F9B6E-9265-44B9-A376-2067B73D6A03">Windows XP Service Pack 2</a>    <br /><a href="http://www.microsoft.com/downloads/details.aspx?familyid=0D5F9B6E-9265-44B9-A376-2067B73D6A03">Windows XP Service Pack 3</a>    <br /><a href="http://www.microsoft.com/downloads/details.aspx?familyid=4C16A372-7BF8-4571-B982-DAC6B2992B25">Windows XP Professional x64 Edition</a>    <br /><a href="http://www.microsoft.com/downloads/details.aspx?familyid=4C16A372-7BF8-4571-B982-DAC6B2992B25">Windows XP Professional x64 Edition Service Pack 2</a>    <br /><a href="http://www.microsoft.com/downloads/details.aspx?familyid=F26D395D-2459-4E40-8C92-3DE1C52C390D">Windows Server 2003 Service Pack 1</a>    <br /><a href="http://www.microsoft.com/downloads/details.aspx?familyid=F26D395D-2459-4E40-8C92-3DE1C52C390D">Windows Server 2003 Service Pack 2</a>    <br /><a href="http://www.microsoft.com/downloads/details.aspx?familyid=C04D2AFB-F9D0-4E42-9E1F-4B944A2DE400">Windows Server 2003 x64 Edition</a>    <br /><a href="http://www.microsoft.com/downloads/details.aspx?familyid=C04D2AFB-F9D0-4E42-9E1F-4B944A2DE400">Windows Server 2003 x64 Edition Service Pack 2</a>    <br /><a href="http://www.microsoft.com/downloads/details.aspx?familyid=AB590756-F11F-43C9-9DCC-A85A43077ACF">Windows Server 2003 with SP1 for Itanium-based Systems</a>    <br /><a href="http://www.microsoft.com/downloads/details.aspx?familyid=AB590756-F11F-43C9-9DCC-A85A43077ACF">Windows Server 2003 with SP2 for Itanium-based Systems</a>    <br /><a href="http://www.microsoft.com/downloads/details.aspx?familyid=18FDFF67-C723-42BD-AC5C-CAC7D8713B21">Windows Vista and Windows Vista Service Pack 1</a>    <br /><a href="http://www.microsoft.com/downloads/details.aspx?familyid=A976999D-264F-4E6A-9BD6-3AD9D214A4BD">Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1</a>    <br /><a href="http://www.microsoft.com/downloads/details.aspx?familyid=25C17B07-1EFE-43D7-9B01-3DFDF1CE0BD7">Windows Server 2008 for 32-bit Systems</a>    <br /><a href="http://www.microsoft.com/downloads/details.aspx?familyid=7B12018E-0CC1-4136-A68C-BE4E1633C8DF">Windows Server 2008 for x64-based Systems</a>    <br /><a href="http://www.microsoft.com/downloads/details.aspx?familyid=2BCF89EF-6446-406C-9C53-222E0F0BAF7A">Windows Server 2008 for Itanium-based Systems</a></p>
<p>注:根据你的操作系统版本点击相应的链接下载。   </p>
<p>如果你的系统是中文的直接看下面部分:    <br /><a href="http://www.microsoft.com/downloads/details.aspx?displaylang=zh-cn&amp;FamilyID=0d5f9b6e-9265-44b9-a376-2067b73d6a03" target="_blank">Windows XP 安全更新程序 (KB958644)</a>    <br /><a href="http://www.microsoft.com/downloads/details.aspx?displaylang=zh-cn&amp;FamilyID=e22eb3ae-1295-4fe2-9775-6f43c5c2aed3" target="_blank">Windows 2000 安全更新程序 (KB958644)</a>    <br /><a href="http://www.microsoft.com/downloads/details.aspx?displaylang=zh-cn&amp;FamilyID=f26d395d-2459-4e40-8c92-3de1c52c390d" target="_blank">Windows Server 2003 安全更新程序 (KB958644)</a></p>
<img src="http://blog.it580.com/?ak_action=api_record_view&id=1472&type=feed" alt="" /><hr />
<p><small>© David for <a href="http://blog.it580.com">空想枫</a>, 2008. |
<a href="http://blog.it580.com/1472">Permalink</a> |
<a href="http://blog.it580.com/1472#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://blog.it580.com/1472&title=微软紧急安全补丁(MS08-067)">del.icio.us</a>
<br/>
</small></p>
	Tags: <a href="http://blog.it580.com/tag/microsoft" title="microsoft" rel="tag nofollow">microsoft</a>, <a href="http://blog.it580.com/tag/security" title="security" rel="tag nofollow">security</a>, <a href="http://blog.it580.com/tag/windows" title="windows" rel="tag nofollow">windows</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.it580.com/2097" title="开源防SQL注入工具-GreenSQL (2009 12-9)">开源防SQL注入工具-GreenSQL</a> (1)</li>
	<li><a href="http://blog.it580.com/2073" title="iPhone破解手机请立即修改密码 (2009 11-3)">iPhone破解手机请立即修改密码</a> (0)</li>
	<li><a href="http://blog.it580.com/1986" title="微软确认Windows 7将于10月22日发布 (2009 6-3)">微软确认Windows 7将于10月22日发布</a> (1)</li>
	<li><a href="http://blog.it580.com/1979" title="从Windows7 退回Windows XP (2009 5-27)">从Windows7 退回Windows XP</a> (0)</li>
	<li><a href="http://blog.it580.com/1973" title="Windows 7和Windows XP、Windows Vista的详细技术对比 (2009 5-15)">Windows 7和Windows XP、Windows Vista的详细技术对比</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.it580.com/1472/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DNS漏洞大问题</title>
		<link>http://blog.it580.com/1279</link>
		<comments>http://blog.it580.com/1279#comments</comments>
		<pubDate>Wed, 09 Jul 2008 10:42:38 +0000</pubDate>
		<dc:creator>David</dc:creator>
				<category><![CDATA[新闻]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.it580.com/1279</guid>
		<description><![CDATA[当全球的各类安全站点都在介绍最近的DNS漏洞问题时,今天检查了电信和网通的几个DNS Server,还没有一个服务器被更新。
简单描述一下问题严重性,本次的漏洞可能导致我们的整个域名系统被欺骗,重定向任何域名到虚假地址。
CVE信息:CVE-2008-1447,可参考US-CERT的Vulnerability Note VU#800113(Multiple DNS implementations vulnerable to cache poisoning) 进行相应的处理。
今天大部分的厂商都发布了相应的补丁或升级,麻烦更新一下吧,各位DNS的网管。

© David for 空想枫, 2008. &#124;
Permalink &#124;
No comment &#124;
Add to
del.icio.us


	Tags: DNS, security

	Related posts
	
	开源防SQL注入工具-GreenSQL (1)
	iPhone破解手机请立即修改密码 (0)
	微软紧急安全补丁(MS08-067) (0)
	ratproxy Web应用安全审计工具 (0)
	WordPress 漏洞扫描插件 (0)


]]></description>
			<content:encoded><![CDATA[<p>当全球的各类安全站点都在介绍最近的DNS漏洞问题时,今天检查了电信和网通的几个DNS Server,还没有一个服务器被更新。</p>
<p>简单描述一下问题严重性,本次的漏洞可能导致我们的整个域名系统被欺骗,重定向任何域名到虚假地址。</p>
<p>CVE信息:<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447" target="_blank">CVE-2008-1447</a>,可参考US-CERT的<a href="http://www.kb.cert.org/vuls/id/800113" target="_blank">Vulnerability Note VU#800113(Multiple DNS implementations vulnerable to cache poisoning)</a> 进行相应的处理。</p>
<p>今天大部分的厂商都发布了相应的补丁或升级,麻烦更新一下吧,各位DNS的网管。</p>
<img src="http://blog.it580.com/?ak_action=api_record_view&id=1279&type=feed" alt="" /><hr />
<p><small>© David for <a href="http://blog.it580.com">空想枫</a>, 2008. |
<a href="http://blog.it580.com/1279">Permalink</a> |
<a href="http://blog.it580.com/1279#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://blog.it580.com/1279&title=DNS漏洞大问题">del.icio.us</a>
<br/>
</small></p>
	Tags: <a href="http://blog.it580.com/tag/dns" title="DNS" rel="tag nofollow">DNS</a>, <a href="http://blog.it580.com/tag/security" title="security" rel="tag nofollow">security</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.it580.com/2097" title="开源防SQL注入工具-GreenSQL (2009 12-9)">开源防SQL注入工具-GreenSQL</a> (1)</li>
	<li><a href="http://blog.it580.com/2073" title="iPhone破解手机请立即修改密码 (2009 11-3)">iPhone破解手机请立即修改密码</a> (0)</li>
	<li><a href="http://blog.it580.com/1472" title="微软紧急安全补丁(MS08-067) (2008 10-24)">微软紧急安全补丁(MS08-067)</a> (0)</li>
	<li><a href="http://blog.it580.com/1232" title="ratproxy Web应用安全审计工具 (2008 7-3)">ratproxy Web应用安全审计工具</a> (0)</li>
	<li><a href="http://blog.it580.com/1189" title="WordPress 漏洞扫描插件 (2008 6-29)">WordPress 漏洞扫描插件</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.it580.com/1279/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ratproxy Web应用安全审计工具</title>
		<link>http://blog.it580.com/1232</link>
		<comments>http://blog.it580.com/1232#comments</comments>
		<pubDate>Thu, 03 Jul 2008 13:33:45 +0000</pubDate>
		<dc:creator>David</dc:creator>
				<category><![CDATA[手记]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[ratproxy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://blog.it580.com/1232</guid>
		<description><![CDATA[ 
Michal Zalewisk发布于Google Code的开源Web应用安全审计工具,版权归属于Google。
A semi-automated, largely passive web application security audit tool, optimized for an accurate and sensitive detection, and automatic annotation, of potential problems and security-relevant design patterns based on the observation of existing, user-initiated traffic in complex web 2.0 environments.      
&#160;
Detects and prioritizes broad classes of security problems, [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://code.google.com/p/ratproxy/" target="_blank"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="216" alt="ratproxy" src="http://blog.it580.com/wp-content/uploads/2008/07/ratproxy.png" width="352" border="0" /></a> </p>
<p><a href="http://lcamtuf.coredump.cx/" target="_blank">Michal Zalewisk</a>发布于Google Code的开源Web应用安全审计工具,版权归属于Google。</p>
<blockquote><p>A semi-automated, largely passive web application security audit tool, optimized for an accurate and sensitive detection, and automatic annotation, of potential problems and security-relevant design patterns based on the observation of existing, user-initiated traffic in complex web 2.0 environments.      </p>
<p>&#160;</p>
<p>Detects and prioritizes broad classes of security problems, such as dynamic cross-site trust model considerations, script inclusion issues, content serving problems, insufficient XSRF and XSS defenses, and much more.</p>
</blockquote>
<p>该工具目前支持Linux,FreeBSD,MacOS X,Windows(Cygwin)。文档链接:<a href="http://code.google.com/p/ratproxy/wiki/RatproxyDoc" target="_blank">ratproxy详细文档</a>.    <br />报告实例见内文:</p>
<p><span id="more-1232"></span></p>
<p><a href="http://blog.it580.com/wp-content/uploads/2008/07/ratproxy-screen.png"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="388" alt="ratproxy-screen" src="http://blog.it580.com/wp-content/uploads/2008/07/ratproxy-screen-thumb.png" width="504" border="0" /></a></p>
<img src="http://blog.it580.com/?ak_action=api_record_view&id=1232&type=feed" alt="" /><hr />
<p><small>© David for <a href="http://blog.it580.com">空想枫</a>, 2008. |
<a href="http://blog.it580.com/1232">Permalink</a> |
<a href="http://blog.it580.com/1232#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://blog.it580.com/1232&title=ratproxy Web应用安全审计工具">del.icio.us</a>
<br/>
</small></p>
	Tags: <a href="http://blog.it580.com/tag/google" title="google" rel="tag nofollow">google</a>, <a href="http://blog.it580.com/tag/ratproxy" title="ratproxy" rel="tag nofollow">ratproxy</a>, <a href="http://blog.it580.com/tag/security" title="security" rel="tag nofollow">security</a>, <a href="http://blog.it580.com/tag/software" title="software" rel="tag nofollow">software</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.it580.com/2146" title="Google Buzz出现 (2010 2-10)">Google Buzz出现</a> (0)</li>
	<li><a href="http://blog.it580.com/2133" title="Google nexus one手机价格泄漏 (2009 12-30)">Google nexus one手机价格泄漏</a> (0)</li>
	<li><a href="http://blog.it580.com/2097" title="开源防SQL注入工具-GreenSQL (2009 12-9)">开源防SQL注入工具-GreenSQL</a> (1)</li>
	<li><a href="http://blog.it580.com/2076" title="Google Wave再次发送30个邀请 (2009 11-11)">Google Wave再次发送30个邀请</a> (42)</li>
	<li><a href="http://blog.it580.com/2073" title="iPhone破解手机请立即修改密码 (2009 11-3)">iPhone破解手机请立即修改密码</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.it580.com/1232/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress 漏洞扫描插件</title>
		<link>http://blog.it580.com/1189</link>
		<comments>http://blog.it580.com/1189#comments</comments>
		<pubDate>Sun, 29 Jun 2008 06:21:17 +0000</pubDate>
		<dc:creator>David</dc:creator>
				<category><![CDATA[手记]]></category>
		<category><![CDATA[plugin]]></category>
		<category><![CDATA[scanner]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://blog.it580.com/1189</guid>
		<description><![CDATA[
这个插件能对你wordpress站点的文件和数据库进行扫描,并发现文件或数据库的可疑行为。

安装:    1.下载并解压缩该文件。    2.上传exploit-scanner目录到你服务器的plugin目录。    3.访问你的后台Plugins管理页面，激活这个插件。    4.可以在Dashboard看到一个新的菜单项&#34;Exploit Scanner&#34;。
注意:扫描你的站点需要一定的时间，因此请在你的站点服务器比较空闲时使用。
 下载链接:exploit-scanner.0.1.zip   (md5:6a88a18a37c4add7dabd72fc97be13b6) 

© David for 空想枫, 2008. &#124;
Permalink &#124;
No comment &#124;
Add to
del.icio.us


	Tags: plugin, scanner, security, wordpress

	Related posts
	
	升级到2.9 (0)
	开源防SQL注入工具-GreenSQL (1)
	iPhone破解手机请立即修改密码 (0)
	WordPress 中文站点发布 (0)
	微软紧急安全补丁(MS08-067) (0)


]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.it580.com/wp-content/uploads/2008/06/exploit-scanner.gif"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="240" alt="exploit-scanner" src="http://blog.it580.com/wp-content/uploads/2008/06/exploit-scanner-thumb.gif" width="484" border="0" /></a></p>
<p>这个插件能对你wordpress站点的文件和数据库进行扫描,并发现文件或数据库的可疑行为。</p>
<p><span id="more-1189"></span></p>
<p><strong>安装:</strong>    <br />1.下载并解压缩该文件。    <br />2.上传exploit-scanner目录到你服务器的plugin目录。    <br />3.访问你的后台Plugins管理页面，激活这个插件。    <br />4.可以在Dashboard看到一个新的菜单项&quot;Exploit Scanner&quot;。</p>
<p><strong>注意</strong>:扫描你的站点需要一定的时间，因此请在你的站点服务器比较空闲时使用。</p>
<p> 下载链接:<a href="http://downloads.wordpress.org/plugin/exploit-scanner.0.1.zip" target="_blank">exploit-scanner.0.1.zip</a>   <br />(md5:6a88a18a37c4add7dabd72fc97be13b6) </p>
<img src="http://blog.it580.com/?ak_action=api_record_view&id=1189&type=feed" alt="" /><hr />
<p><small>© David for <a href="http://blog.it580.com">空想枫</a>, 2008. |
<a href="http://blog.it580.com/1189">Permalink</a> |
<a href="http://blog.it580.com/1189#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://blog.it580.com/1189&title=WordPress 漏洞扫描插件">del.icio.us</a>
<br/>
</small></p>
	Tags: <a href="http://blog.it580.com/tag/plugin" title="plugin" rel="tag nofollow">plugin</a>, <a href="http://blog.it580.com/tag/scanner" title="scanner" rel="tag nofollow">scanner</a>, <a href="http://blog.it580.com/tag/security" title="security" rel="tag nofollow">security</a>, <a href="http://blog.it580.com/tag/wordpress" title="wordpress" rel="tag nofollow">wordpress</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.it580.com/2104" title="升级到2.9 (2009 12-20)">升级到2.9</a> (0)</li>
	<li><a href="http://blog.it580.com/2097" title="开源防SQL注入工具-GreenSQL (2009 12-9)">开源防SQL注入工具-GreenSQL</a> (1)</li>
	<li><a href="http://blog.it580.com/2073" title="iPhone破解手机请立即修改密码 (2009 11-3)">iPhone破解手机请立即修改密码</a> (0)</li>
	<li><a href="http://blog.it580.com/1810" title="WordPress 中文站点发布 (2008 12-12)">WordPress 中文站点发布</a> (0)</li>
	<li><a href="http://blog.it580.com/1472" title="微软紧急安全补丁(MS08-067) (2008 10-24)">微软紧急安全补丁(MS08-067)</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.it580.com/1189/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>微软建议用于抵御SQL注入的免费工具</title>
		<link>http://blog.it580.com/1173</link>
		<comments>http://blog.it580.com/1173#comments</comments>
		<pubDate>Wed, 25 Jun 2008 03:26:46 +0000</pubDate>
		<dc:creator>David</dc:creator>
				<category><![CDATA[手记]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[sqls]]></category>

		<guid isPermaLink="false">http://blog.it580.com/?p=1173</guid>
		<description><![CDATA[介绍三个免费工具，帮助你来实现SQL注入漏洞的检查，发现SQL注入漏洞，并阻止SQL注入漏洞对你网站的影响。

漏洞检查工具:Scrawlr

功能：
可以实现URL参数上的SQL注入；支持代理；发现漏洞时，将尝试读取数据库表信息。
限制：
最多只支持爬行1500个页面;不支持站点认证(即需要登陆);不能获得数据库内容;不支持JavaScript和Flash;不支持POST方式的检测
 下载：Download Scrawlr
 
源代码检查工具:Microsoft Source Code Analyzer for SQL Injection
功能：
对源代码进行SQL注入漏洞的检测。
限制：
目前只支持VBScript.也不确保能分析所有代码，可能出现分析错误。
需要.NET framework 3.0
下载: Download Microsoft Source Code Analyzer for SQL Injection

 
SQL注入过滤工具:UrlScan
功能：
对指定的http请求进行过滤。
限制：
目前只支持IIS.需要了解现有的SQL注入漏洞，并进行相应的HTTP请求过滤。
下载: DownLoad UrlScan

 参考文章：Microsoft Security Vulnerability Research &#38; Defense

© David for 空想枫, 2008. &#124;
Permalink &#124;
No comment &#124;
Add to
del.icio.us


	Tags: free, security, software, sqls

	Related posts
	
	开源防SQL注入工具-GreenSQL (1)
	iPhone破解手机请立即修改密码 (0)
	Parallels Workstation 2.2 免费许可申请 (1)
	iPhone 3G 软件破解解锁视频发出 (0)
	VirtualBox 2.1.0 发布 (1)


]]></description>
			<content:encoded><![CDATA[<p>介绍三个免费工具，帮助你来实现SQL注入漏洞的检查，发现SQL注入漏洞，并阻止SQL注入漏洞对你网站的影响。</p>
<p><span id="more-1173"></span></p>
<p><strong>漏洞检查工具:Scrawlr</strong><br />
<a href="http://blog.it580.com/wp-content/uploads/2008/06/scrawler-screenshot.png"><img class="alignnone size-medium wp-image-1174" title="scrawler-screenshot" src="http://blog.it580.com/wp-content/uploads/2008/06/scrawler-screenshot-300x204.png" alt="" width="300" height="204" /></a></p>
<p><strong>功能：</strong><br />
可以实现URL参数上的SQL注入；支持代理；发现漏洞时，将尝试读取数据库表信息。<br />
<strong>限制：</strong><br />
最多只支持爬行1500个页面;不支持站点认证(即需要登陆);不能获得数据库内容;不支持JavaScript和Flash;不支持POST方式的检测<br />
<strong> 下载：</strong><a title="Download Scrawlr" href="https://download.spidynamics.com/products/scrawlr/" target="_blank">Download Scrawlr</a></p>
<p> </p>
<p><strong>源代码检查工具:Microsoft Source Code Analyzer for SQL Injection</strong></p>
<p><strong>功能：</strong><br />
对源代码进行SQL注入漏洞的检测。<br />
<strong>限制：</strong><br />
目前只支持VBScript.也不确保能分析所有代码，可能出现分析错误。<br />
需要.NET framework 3.0<br />
<strong>下载: </strong><a title="Download Microsoft Source Code Analyzer for SQL Injection" href="http://www.microsoft.com/downloads/details.aspx?FamilyId=58A7C46E-A599-4FCB-9AB4-A4334146B6BA&amp;displaylang=en" target="_blank">Download Microsoft Source Code Analyzer for SQL Injection</a><br />
<strong></strong></p>
<p> </p>
<p><strong>SQL注入过滤工具:UrlScan</strong></p>
<p><strong>功能：</strong><br />
对指定的http请求进行过滤。<br />
<strong>限制：</strong><br />
目前只支持IIS.需要了解现有的SQL注入漏洞，并进行相应的HTTP请求过滤。<br />
<strong>下载:</strong> <a title="Download UrlScan" href="http://www.microsoft.com/downloads/details.aspx?FamilyId=EE41818F-3363-4E24-9940-321603531989&amp;displaylang=en" target="_blank">DownLoad UrlScan</a></p>
<p><a title="Download UrlScan" href="http://www.microsoft.com/downloads/details.aspx?FamilyId=EE41818F-3363-4E24-9940-321603531989&amp;displaylang=en" target="_blank"></a><br />
 参考文章：<a title="New tools to block and eradicate SQL injection" href="http://blogs.technet.com/swi/archive/2008/06/24/new-tools-to-block-and-eradicate-sql-injection.aspx" target="_blank">Microsoft Security Vulnerability Research &amp; Defense</a></p>
<img src="http://blog.it580.com/?ak_action=api_record_view&id=1173&type=feed" alt="" /><hr />
<p><small>© David for <a href="http://blog.it580.com">空想枫</a>, 2008. |
<a href="http://blog.it580.com/1173">Permalink</a> |
<a href="http://blog.it580.com/1173#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://blog.it580.com/1173&title=微软建议用于抵御SQL注入的免费工具">del.icio.us</a>
<br/>
</small></p>
	Tags: <a href="http://blog.it580.com/tag/free" title="free" rel="tag nofollow">free</a>, <a href="http://blog.it580.com/tag/security" title="security" rel="tag nofollow">security</a>, <a href="http://blog.it580.com/tag/software" title="software" rel="tag nofollow">software</a>, <a href="http://blog.it580.com/tag/sqls" title="sqls" rel="tag nofollow">sqls</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://blog.it580.com/2097" title="开源防SQL注入工具-GreenSQL (2009 12-9)">开源防SQL注入工具-GreenSQL</a> (1)</li>
	<li><a href="http://blog.it580.com/2073" title="iPhone破解手机请立即修改密码 (2009 11-3)">iPhone破解手机请立即修改密码</a> (0)</li>
	<li><a href="http://blog.it580.com/1853" title="Parallels Workstation 2.2 免费许可申请 (2009 1-2)">Parallels Workstation 2.2 免费许可申请</a> (1)</li>
	<li><a href="http://blog.it580.com/1845" title="iPhone 3G 软件破解解锁视频发出 (2008 12-22)">iPhone 3G 软件破解解锁视频发出</a> (0)</li>
	<li><a href="http://blog.it580.com/1841" title="VirtualBox 2.1.0 发布 (2008 12-19)">VirtualBox 2.1.0 发布</a> (1)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://blog.it580.com/1173/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
