<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.2.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Chinese hackers Blog</title>
	<link>http://www.china-hacker.com</link>
	<description>Chinese hackers Union English website. Including technical articles and network security information.</description>
	<pubDate>Sat, 09 Aug 2008 05:18:59 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.2</generator>
	<language>en</language>
			<item>
		<title>Microsoft announced the new Windows 7 Resource Information</title>
		<link>http://www.china-hacker.com/2008/08/microsoft-announced-the-new-windows-7-resource-information.html</link>
		<comments>http://www.china-hacker.com/2008/08/microsoft-announced-the-new-windows-7-resource-information.html#comments</comments>
		<pubDate>Sat, 09 Aug 2008 05:18:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://www.china-hacker.com/2008/08/microsoft-announced-the-new-windows-7-resource-information.html</guid>
		<description><![CDATA[According to Windows7 official blog reported that Microsoft would be prepared to share with the users of the next generation operating system more information. Even if the company continues to Windows7 theme of the details remain silent, and quickly tryi... ]]></description>
			<content:encoded><![CDATA[<p>According to Windows7 official blog reported that Microsoft would be prepared to share with the users of the next generation operating system more information. Even if the company continues to Windows7 theme of the details remain silent, and quickly trying to cover up his leak of the data, not to disclose any details of Windows7 platform, but there are more and more information on Windows7 was released from.<br />
 <br />
Microsoft will be its upcoming 2008 Windows Hardware Engineering Conference, issued on Windows7 the new resources of information.<br />
 <br />
Microsoft said: &#8220;We will in 2008 the November 5 - 7 in Los Angeles held a large company boards, the focus of this Council is how to design computer equipment and its drive to make the Windows operating system to run well. Then We will further familiarize themselves with the new generation of the Windows operating system have the opportunity, innovation and technology direction, Windows7 this year will be the Windows Hardware Engineering Conference, the main topic. &#8221;<br />
 <br />
In 2008 the Windows Hardware Engineering Conference will be October 27 - 30 in the Los Angeles Convention Center will be held, Microsoft will Windows7 a heated discussion, according to the agenda for the meeting, discussion will include: &#8220;Web hosting services Code &#8220;,&#8221; optimize energy efficiency &#8220;and&#8221; touch-computer &#8220;and&#8221; improve the graphics algorithm. &#8220;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.china-hacker.com/2008/08/microsoft-announced-the-new-windows-7-resource-information.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Analysis of the loopholes in the firewall</title>
		<link>http://www.china-hacker.com/2008/08/analysis-of-the-loopholes-in-the-firewall.html</link>
		<comments>http://www.china-hacker.com/2008/08/analysis-of-the-loopholes-in-the-firewall.html#comments</comments>
		<pubDate>Fri, 08 Aug 2008 12:58:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Loophole]]></category>

		<guid isPermaLink="false">http://www.china-hacker.com/2008/08/analysis-of-the-loopholes-in-the-firewall.html</guid>
		<description><![CDATA[Firewall alone can not protect online assets. Now, hackers and their attack is very smart strategy, more and more dangerous. At present a major threat is that application-level attacks, such attacks can sneak into the firewall until sneaked into Web appl... ]]></description>
			<content:encoded><![CDATA[<p>Firewall alone can not protect online assets. Now, hackers and their attack is very smart strategy, more and more dangerous. At present a major threat is that application-level attacks, such attacks can sneak into the firewall until sneaked into Web applications. Yes, there are many such attacks like to valuable customer data as the targets.</p>
<p>Why, then, ordinary firewall Zuzhibule such attacks?  Because such attacks disguised as normal traffic, not particularly large data packets, address, and no suspicious contents do not match, so it will not trigger alarms. Most people fear is an example of SQL commands embedded attacks (SQL injection). In such attacks, hackers use one of your own HTML form, unauthorized query the database. Another threat is that the Executive Order. As long as Web applications to send commands to the shell program, the crafty hackers on the server can be arbitrary enforcement of the order.</p>
<p>Some other attacks is relatively simple. For example, HTML Notes inside often contain sensitive information, including imprudent programmers left login. Thus, for application-level attacks, tampering with cookies from the changes to HTML form, the hidden field, depends entirely on the imagination of hackers. But the good news is that most of these attacks is completely blocked.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.china-hacker.com/2008/08/analysis-of-the-loopholes-in-the-firewall.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>China and Beijing the security risks</title>
		<link>http://www.china-hacker.com/2008/08/china-and-beijing-the-security-risks.html</link>
		<comments>http://www.china-hacker.com/2008/08/china-and-beijing-the-security-risks.html#comments</comments>
		<pubDate>Fri, 08 Aug 2008 03:05:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://www.china-hacker.com/2008/08/china-and-beijing-the-security-risks.html</guid>
		<description><![CDATA[In the world anti-terrorism situation grim circumstances, China&#8217;s security problems are very prominent, 2008 in Lhasa, Tibet what happened to many Chinese people in China feel that the security problems faced. Beijing to host the Olympic Games, Bei... ]]></description>
			<content:encoded><![CDATA[<p>In the world anti-terrorism situation grim circumstances, China&#8217;s security problems are very prominent, 2008 in Lhasa, Tibet what happened to many Chinese people in China feel that the security problems faced. Beijing to host the Olympic Games, Beijing is also the safety of many people worried.</p>
<p>The Chinese government on the confidence of the Beijing Olympic Games, the issue of security into a huge human and material resources, but Beijing people now in private discussions with many people attacked Beijing on the topic, the Chinese Government has not come forward to explain this issue. For example, many people in the last debate about more than 5,000 kilograms of explosives were transported into Beijing in early August, attacks have taken place in Xinjiang and Chinese soldiers in the incident, about 16 Chinese soldiers died. China&#8217;s Yunnan and Guizhou have taken place in the public riots.</p>
<p>Beijing Olympic Games in such a complex moment organized, and we look forward to the success of the organization, attacked the Olympic Games, I think the world of any peace-loving people will oppose and condemn. It is now - at 11:00 on August 8, 2008, where the world will never wrote to the wishes of peace and quiet.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.china-hacker.com/2008/08/china-and-beijing-the-security-risks.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>China Internet to winter</title>
		<link>http://www.china-hacker.com/2008/08/china-internet-to-winter.html</link>
		<comments>http://www.china-hacker.com/2008/08/china-internet-to-winter.html#comments</comments>
		<pubDate>Fri, 08 Aug 2008 02:39:41 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Internet]]></category>

		<guid isPermaLink="false">http://www.china-hacker.com/2008/08/china-internet-to-winter.html</guid>
		<description><![CDATA[Beijing Olympic Games is that many people think that Beijing or China&#8217;s economic turning point. At present, China&#8217;s Internet industry many people in China&#8217;s Internet discussion winter&#8217;s arrival. China&#8217;s economy appears to be... ]]></description>
			<content:encoded><![CDATA[<p>Beijing Olympic Games is that many people think that Beijing or China&#8217;s economic turning point. At present, China&#8217;s Internet industry many people in China&#8217;s Internet discussion winter&#8217;s arrival. China&#8217;s economy appears to be in the Olympics after a number of changes that will affect China&#8217;s Internet economy.</p>
<p>We found several problems exist Chinese website, CN domain names had reached the incredible price point, a large number of viruses and spam have a website in China, so China&#8217;s Internet Wuyanzhangqi, Chinese website traffic has increasingly valuable, many individuals Webmaster difficult.</p>
<p>The Chinese government intervention in the network has been growing, the site requires registration, e-shop requirement of registration, licenses and other video sites need. Large Chinese website of copyright is a serious problem, leading Chinese Internet content on a high degree of duplication.</p>
<p>China&#8217;s telecommunications network is also very serious intervention, many of the room suddenly closed down, suspended, over more than 2,000 servers were closed off gateway processing, network for this incident, I also have the concept of wait-and-see attitude. In China, ordinary people have to speak to the right, no right to discuss the government and the monopoly of right or wrong.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.china-hacker.com/2008/08/china-internet-to-winter.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Windows 7 operating system-depth study of new technologies</title>
		<link>http://www.china-hacker.com/2008/08/windows-7-operating-system-depth-study-of-new-technologies.html</link>
		<comments>http://www.china-hacker.com/2008/08/windows-7-operating-system-depth-study-of-new-technologies.html#comments</comments>
		<pubDate>Thu, 07 Aug 2008 14:58:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://www.china-hacker.com/2008/08/windows-7-operating-system-depth-study-of-new-technologies.html</guid>
		<description><![CDATA[Perhaps you have not noticed that at the end of last month Vista has released an entire year of the. From November 30, 2006 for business users to publish, to January 30, 2007 to the general public.
Unfortunately, the number of users to buy Vista is not s... ]]></description>
			<content:encoded><![CDATA[<p>Perhaps you have not noticed that at the end of last month Vista has released an entire year of the. From November 30, 2006 for business users to publish, to January 30, 2007 to the general public.</p>
<p>Unfortunately, the number of users to buy Vista is not satisfied with the Microsoft, Vista&#8217;s main sales from Microsoft&#8217;s OEM partners pre-installed systems. Even so many companies still choose to have your own decision to install Vista or XP, many users unwilling to give up because they are familiar with the old operating system, especially the software and they all still work perfectly functioning of the time.</p>
<p>Clock at the Windows 7.0 ─ ─ Vista (based on the NT kernel is known as Windows 6.0) successor. Windows 7 still usher in time, but some preliminary characteristics has gradually surfaced: The new streamlined core, built-in virtual machine to run the old software, the revised and simplified the user interface &#8230;&#8230;</p>
<p>Perhaps you would say not have a name is Vienna Mody » Forget it bar, the new Microsoft vice president Steven Sinofsky has stopped in accordance with the scenery of the past, the city named after the way. So Windows 7 in what name will eventually appear in public, is still unknown, especially in the experienced Me, XP, Vista these strange name.</p>
<p>But as we look at the news, Sinofsky might return to the most primitive in accordance with the naming of the year, so as Windows95. After all, Microsoft&#8217;s other products are in accordance with the rules of, such as Office software, such naming is no bad.</p>
<p>If this speculation, then it will be the name of Windows 2010. Windows 7 the first time since the official in the mouth, is in Orlando in July of Microsoft Exchange global sales meeting. A spokesman said: Microsoft has made Windows 7 for the three-year development plan. This means that the earliest it will have to wait until 2010 will be published.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.china-hacker.com/2008/08/windows-7-operating-system-depth-study-of-new-technologies.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Chinese hackers attacked the United States Government</title>
		<link>http://www.china-hacker.com/2008/08/chinese-hackers-attacked-the-united-states-government%ef%bc%9f.html</link>
		<comments>http://www.china-hacker.com/2008/08/chinese-hackers-attacked-the-united-states-government%ef%bc%9f.html#comments</comments>
		<pubDate>Thu, 07 Aug 2008 14:39:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://www.china-hacker.com/2008/08/chinese-hackers-attacked-the-united-states-government%ef%bc%9f.html</guid>
		<description><![CDATA[Last Wednesday, said the United States two Republican&#8217;s office by the Chinese computer hackers penetrated the disclosure of information, network warfare official landing Capitol Hill. Chinese hackers on U.S. computer networks long march began in 20... ]]></description>
			<content:encoded><![CDATA[<p>Last Wednesday, said the United States two Republican&#8217;s office by the Chinese computer hackers penetrated the disclosure of information, network warfare official landing Capitol Hill. Chinese hackers on U.S. computer networks long march began in 2000. Since then, the number of hacker attacks on the rise, and means to improve, Chinese hackers hackers and the United States has many times the contest.</p>
<p>U.S. media reported that the United States and the West, China adopted a &#8220;human sea tactics.&#8221; Spies who are amateur spies, general by the Chinese overseas students or overseas Chinese living in member. China will require them to any military, science and technology or the information back to the domestic economy, no matter how low-level intelligence. Its purpose is the collection of such information together is likely to become an important intelligence. Security expert John Pike said: &#8220;The Chinese should not fight homers and their theory is that if you do enough, will one day be big results.&#8221; Some people predict that about 100,000 people involved in the &#8221; Human sea tactics. &#8221;</p>
<p>I think that we are willing to hackers in the United States and technical exchanges, such exchanges are not necessarily attacking one another, I think the political struggle between the countries, and on the network hacker attacks, and must not associate reason.</p>
<p>For U.S. media, CNN reported from Tibet, many Chinese people has lost the trust of the American media, the same people of the United States deal with this report, I do not know what attitude » We believe that China&#8217;s hacking by the Chinese Government does not control, the Chinese government intelligence officer in the action, I believe that most Chinese people are not aware of the hackers.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.china-hacker.com/2008/08/chinese-hackers-attacked-the-united-states-government%ef%bc%9f.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Hackers based portal of knowledge</title>
		<link>http://www.china-hacker.com/2008/08/hackers-based-portal-of-knowledge.html</link>
		<comments>http://www.china-hacker.com/2008/08/hackers-based-portal-of-knowledge.html#comments</comments>
		<pubDate>Thu, 07 Aug 2008 14:22:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.china-hacker.com/2008/08/hackers-based-portal-of-knowledge.html</guid>
		<description><![CDATA[You do not want to be hackers ？Is not often traveled to various hacking sites?  Of hackers is really hard! It requires you have enough patience! Perseverance! Perseverance can only be achieved!
Below started! Note: This article is only suitable for no... ]]></description>
			<content:encoded><![CDATA[<p>You do not want to be hackers ？Is not often traveled to various hacking sites?  Of hackers is really hard! It requires you have enough patience! Perseverance! Perseverance can only be achieved!</p>
<p>Below started! Note: This article is only suitable for novice, has to look at the entry-level technical articles! Below I just used the knowledge to know that you made the first successful! Operating system installed to a windows2000.</p>
<p>Section 1 lesson: the use of order</p>
<p>You have to understand some order to better use! Can not look at one side of the invasion Liwen it, the following look at some commonly used on the orders! Invasion is the basic need to know how to order if you do not see this even if you The school can take your vacation to go!</p>
<p>1.net</p>
<p>NET [ACCOUNTS | COMPUTER | CONFIG | CONTINUE | FILE | GROUP | HELP |<br />
HELPMSG | LOCALGROUP | NAME | PAUSE | PRINT | SEND | SESSION |<br />
SHARE | START | STATISTICS | STOP | TIME | USE | USER | VIEW]</p>
<p>Above that net orders. We look at some commonly used.</p>
<p>net user \ \ list of all users \ \ example: c: \&gt; net user</p>
<p>net localgroup \ \ of the user group \ \ example: c: \&gt; net localgroup administrators guest / add \ \ guest users to add management group. the need for adequate access to operate! \ \</p>
<p>net share \ \ show that the sharing of resources \ \ example: c: \&gt; net share</p>
<p>net start \ \ launch services, has launched a service or display a list of \ \ examples: \&gt; net start examples: \&gt; net start telnet \ \ start telnet \ \</p>
<p>net stop \ \ stop Windows2000 network services \ \ example c: \&gt; net stop telnet \ \ stop telnet services \ \</p>
<p>net time \ \ Show Time \ \ example: c: \&gt; net time 127.0.0.1 \ \ show 127.0.0.1 time \ \</p>
<p>net use \ \ displayed on the computer connected to the information \ \ example: c: \&gt; net use</p>
<p>net view \ \ domain list shows, computer list or by the designated computer is shared resources \ \ example: c: \&gt; net view</p>
<p>The basic order on the net come to the end! However, the order is not to say that others do not have to learn! just my basic teaching (the invasion) the need for such an order is only to help where their windows to look at it! DOS under the Basic order is very important! Such as: copy, and so on. Ftp, and so on are important for various reasons to order you to look at. (Basic courses can not be too complicated, OK ?!!!) a good school ~ ~</p>
<p>Section II Division: port and Trojans</p>
<p>A. Section II to this course of the first lessons we learn through the port! What is the port »computer is connected to the outside world and access! Such as we do with the page is actually 80 ports.</p>
<p>1), telnet sign in the port (23/tcp)<br />
The message log shows that long-distance services are running, where you can log in to the remote host.</p>
<p>2), WWW (80/TCP) port<br />
It shows that the WWW service in the port operation<br />
Do not tell me you do not know what WWW service is oh, that is to say, if a site&#8217;s server has 80 ports.</p>
<p>3), FTP (21/tcp)<br />
ftp services and TELNET services, you can get from FTP server or upload information such as Trojans, some anonymous or landing, but this seems not a good thing.</p>
<p>4), finger (79/tcp) port<br />
finger services on the invaders is a very useful information from its users get information, view the machines running, and so on.</p>
<p>5), remote control (3389)<br />
This port for remote landing.</p>
<p>There are some common ports such as 110135139,25 &#8230;.. and so on and so we need to use the Essentials 23 is the port. Other important because it also cited that out. Remaining to fill your own Meeting. (I am not irresponsible. Courses is the question! Understanding please!) PS: not all the ports are useful.</p>
<p>B. Trojan</p>
<p>Trojan is a great danger! Such as glaciers, and other Trojans can even remote control your computer! Trojans will also open some ports. You can see through ports to see if there is no Trojan horse on your computer running. But Some Trojans are already using the port. This is more trouble. Need to use antivirus software to help the ~ \ \ We do not need to use the curriculum to the Trojans. But I think you deserve a school \ \</p>
<p>Section III classes: ipc invasion.</p>
<p>Better to estimate the basis of so many of you saw something very impatient to have this lesson to you to implement the first invasion! Keke to put aside your AK-47, we do not need that guy &#8230;.</p>
<p>A. What is the ipc?</p>
<p>IPC $ share is &#8220;named pipe&#8221; of resources, its procedures for communication between the very important. In the remote management of computer and view your computer&#8217;s shared use of resources. We can use IPC $ host with the goal of establishing an empty connection (without user name and password), while the use of this air link, we can get on the target host User list. &#8220;Streamer&#8221; IPC $ detection feature, users can get a list and can meet the dictionary, password attempts.</p>
<p>B. OK! You use in the last two lessons learned knowledge with me Chong! Good grasp of your orders to use the right »</p>
<p>The need to use the scanning software: xscan operating system: win2000 (Do not tell me that you or 98 or me, I immediately K you!)</p>
<p>First of all, we use a scanner scan of the IP. Open xscan, select &#8220;Settings&#8221; and then choose &#8220;scanning module&#8221;, and then only weak passwords nt of the election of that. Identified after the election &#8220;set up&#8221;, &#8220;scan parameters&#8221; and then fill in IP Paragraph. 127.0.0.1-127.0.0.255 on! (Note: IP paragraph is purely fictional.)</p>
<p>So we have to assume that a .127.0.0.2 the user name: Administrator Password: Air (Oh really Gao Buqing now to the people so why not safety awareness &#8230;)</p>
<p>Open cmd, enter: net use \ \ 127.0.0.1 \ ipc $ &#8220;&#8221; / user: &#8220;Administrator&#8221; the successful completion of orders. OK! Next ~</p>
<p>at \ \ 127.0.0.1 \ \ this step is purely personal habits because I would like to know that he did not open the AT. did not give up on a bar \ \</p>
<p>Next we need to edit a batch file. Notepad open, enter the following: @ net start telnet and then save it as a a.bat \ \ Note extensions! A bat! \ \</p>
<p>Edited to continue after it! Copy a.bat \ \ 127.0.0.1 \ admin $ \ \ admin $ winnt is on target the root directory under \ \</p>
<p>net time \ \ 127.0.0.1 \ \ look at the objectives of the time! useful ~ \ \</p>
<p>Assumption is 21:00. Then the next step!</p>
<p>at \ \ 127.0.0.1 20:01 a.bat \ \ goal of an AT command to run a.bat. time to pay attention to the 24-hour system! \ \</p>
<p>net time \ \ 127.0.0.1 \ \ not the time to look at the «\ \</p>
<p>To assume that, we will implement the next step!</p>
<p>telnet 127.0.0.1 \ \ landing on the other side of the machine.&#8217;s just that batch is to open its ports to 23 \ \</p>
<p>Then enter the user name and password \ \ user is Administrator ah! Password is empty. Enter on the line ~ \ \</p>
<p>OK! Every success! Now you can do the things you want to add users, etc. For example, (an order is the use ah! Order so that important!)</p>
<p>Qingtongxuemen attention not to remove other people&#8217;s things! We are just learning techniques. Luandong I immediately who he was expelled.</p>
<p>Well-now you should be able to implement its first invasion to the actual operation of course not all as easy as above. Will be a lot of problems. For example, at the Executive can not. Telnet boost when the need to verify, and so on. This has left Your own solution to the ~</p>
]]></content:encoded>
			<wfw:commentRss>http://www.china-hacker.com/2008/08/hackers-based-portal-of-knowledge.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Chinese e-commerce sites the problems</title>
		<link>http://www.china-hacker.com/2008/08/chinese-e-commerce-sites-the-problems.html</link>
		<comments>http://www.china-hacker.com/2008/08/chinese-e-commerce-sites-the-problems.html#comments</comments>
		<pubDate>Thu, 07 Aug 2008 14:05:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Internet]]></category>

		<guid isPermaLink="false">http://www.china-hacker.com/2008/08/chinese-e-commerce-sites-the-problems.html</guid>
		<description><![CDATA[With China&#8217;s gradual warming of e-commerce, online transactions of the security issue of increasing concern.
China&#8217;s Internet Center (CNNIC) &#8220;issued by the China Internet Development Report&#8221; on e-commerce survey results show that ... ]]></description>
			<content:encoded><![CDATA[<p>With China&#8217;s gradual warming of e-commerce, online transactions of the security issue of increasing concern.</p>
<p>China&#8217;s Internet Center (CNNIC) &#8220;issued by the China Internet Development Report&#8221; on e-commerce survey results show that current users of the problem is most concerned about the safety of online transactions. This shows that e-commerce in China can develop smoothly, is an important prerequisite for the security of online transactions must be guaranteed.</p>
<p>Recently found that many Chinese e-commerce sites, there are some universal serious security flaws, an attacker can easily steal user account, the transaction password, users can use the funds to conduct online transactions. These security loopholes will directly affect the credibility of e-commerce site, the Chinese e-commerce development process will have a significant impact.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.china-hacker.com/2008/08/chinese-e-commerce-sites-the-problems.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>U.S. financial loopholes in the design of the site</title>
		<link>http://www.china-hacker.com/2008/08/us-financial-loopholes-in-the-design-of-the-site.html</link>
		<comments>http://www.china-hacker.com/2008/08/us-financial-loopholes-in-the-design-of-the-site.html#comments</comments>
		<pubDate>Thu, 07 Aug 2008 13:57:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Information]]></category>

		<guid isPermaLink="false">http://www.china-hacker.com/2008/08/us-financial-loopholes-in-the-design-of-the-site.html</guid>
		<description><![CDATA[The so-called loophole different from the traditional design software vulnerabilities, through patch updates. Design loopholes usually appear on the site design stage, such as how to provide security functions.
Here classified the five loopholes in the d... ]]></description>
			<content:encoded><![CDATA[<p>The so-called loophole different from the traditional design software vulnerabilities, through patch updates. Design loopholes usually appear on the site design stage, such as how to provide security functions.</p>
<p>Here classified the five loopholes in the design, for example, some Web sites that users to have a different domain name a new page to remind users not, it allows users to not know whether this new page trusted; Some sites will require Users log in from a non-secure Web site to the safety, so that hackers can take advantage of organic, because hackers can modify non-secure web page, go to the login page of insecurity on the page.</p>
<p>Some sites will be safety recommendations or contact information posted on the website of the non-security, hackers can often unsafe counterfeit these pages and provide various recommendations and contact information; some Web sites used by the user&#8217;s personal information on the policies not enough Sound, for example, allows users to set a short password or by e-mail account as the use of account; The study also considered the financial institutions to make use of email passwords is dangerous, because not many users have e-mail security.</p>
<p>Some sites in insecure login page to provide functional, some contacts and other corporate information is published in the pages of insecurity, and some sites allow users to set up e-mail account for the use of account, only a handful of Site no loopholes in the design.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.china-hacker.com/2008/08/us-financial-loopholes-in-the-design-of-the-site.html/feed</wfw:commentRss>
		</item>
		<item>
		<title>Magic Winmail Server number of security flaws</title>
		<link>http://www.china-hacker.com/2008/08/magic-winmail-server-number-of-security-flaws.html</link>
		<comments>http://www.china-hacker.com/2008/08/magic-winmail-server-number-of-security-flaws.html#comments</comments>
		<pubDate>Thu, 07 Aug 2008 13:45:42 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Loophole]]></category>

		<guid isPermaLink="false">http://www.china-hacker.com/2008/08/magic-winmail-server-number-of-security-flaws.html</guid>
		<description><![CDATA[Systems affected: Amax Engineering Corporation Winmail Server 4.0 Build 1112
Description: BUGTRAQ ID: 12388
Magic Winmail Server is a multi-function WEB-based mail service program.
Magic Winmail Server existence of a number of security issues, remote att... ]]></description>
			<content:encoded><![CDATA[<p>Systems affected: Amax Engineering Corporation Winmail Server 4.0 Build 1112<br />
Description: BUGTRAQ ID: 12388</p>
<p>Magic Winmail Server is a multi-function WEB-based mail service program.</p>
<p>Magic Winmail Server existence of a number of security issues, remote attackers can use these loopholes to upload files to download arbitrary conduct cross-site scripting and other attacks.</p>
<p>1, WEBMAIL loopholes</p>
<p>a, download.php allow directory traversal download any file, because of the lack of adequate filtering parameters, the system can lead to download any file.</p>
<p>b, upload.php users because of the lack of full file name filters, available through directory traversal upload any documents to the system.</p>
<p>c, e-mail users showed that personal information when there cross-site scripting vulnerability. &#8216;/ admin / user.php&#8217; script allows WEB administrator user name, full name, description and company name, malicious users can use the script userinfo.php insert malicious script to personal information, see the administrator, can lead to sensitive information Leak.</p>
<p>2, IMAP long-distance services directory traversal vulnerability</p>
<p>IMAP order multiple directory traversal problems exist, can lead to malicious user to read arbitrary board users open e-mail, delete, and the establishment of any directory. These orders include CREATE, EXAMINE, SELECT and DELET.</p>
<p>3, FTP PORT ordered a security issue</p>
<p>Winmail Server service does not correct the FTP PORT order to provide the IP address, can lead to an attacker to use PORT order a port scan.</p>
<p>Manufacturers patch:</p>
<p>At present vendors have released updates to fix this security issue, go to vendors to download the home page: <a href="http://www.magicwinmail.net/">http://www.magicwinmail.net</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.china-hacker.com/2008/08/magic-winmail-server-number-of-security-flaws.html/feed</wfw:commentRss>
		</item>
	</channel>
</rss>
