免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
楼主: skipjack
打印 上一主题 下一主题

短篇小说《我是一名黑客》讨论 [复制链接]

论坛徽章:
0
91 [报告]
发表于 2006-04-24 09:54 |只看该作者
关于溢出,确实应该是有从用户态安全上下文溢出到root权限的可能的,楼上那位说人buffer overflow没学过的人难免有点诽谤的嫌疑了,作者这篇文章既然是小说了,不可能每个技术细节都符合现实状况,可以允许稍微夸张一些,但总体的技术方向大错误应该是没有太大漏洞的,只是后来军队攻防战那里漏洞比较多,应该是作者为了保证文章悬念迭起,越写越无法收手,导致后来太过于天马行空而脱离技术实现了,可能这也是这篇文章没了下文的原因。

论坛徽章:
0
92 [报告]
发表于 2006-04-24 11:48 |只看该作者
kankan

论坛徽章:
0
93 [报告]
发表于 2006-04-24 15:59 |只看该作者
原帖由 skipjack 于 2006-4-24 09:48 发表


看清楚:
突然灵光一闪,不知他的vsftp用的是虚拟帐号,还是系统帐号


谢谢你的提醒,引用的时候记得把我的“知道了”删掉

论坛徽章:
0
94 [报告]
发表于 2006-04-24 20:37 |只看该作者
真不错,真经典....

论坛徽章:
0
95 [报告]
发表于 2006-04-24 22:26 |只看该作者
原帖由 skipjack 于 2006-4-24 09:13 发表


呵呵...说到HTTP协议认证这东西,咱也顺便提下IE和Mozilla的比较。
仅从协议实现上来看,IE真的比Mozilla差?
我劫持一次TCP会话后,让Mozilla转向会比让IE转向容易的多的多。
如果你感觉兴趣,可以讨论。


Most of IE vulnerabilities come from COM/Activex. A COM object can be initialized even it is not masked as safe for scripting, this has been proved to be very dangerous. Lots of memory corruption vulnerabilites have been found in the recent two years, some of these vulnerabilities can be easily exploited for code execution. For example :
MS06-013 (CVE-2006-1186)

Mozilla family browsers also has its own flaws, But AFAIK, it is relatively safer than IE. BTW, Mozilla has much better security policy than Microsoft, any vulnerability being found will be quickly patched, security issues is discussed through bugzilla portal, this is much better than Microsoft which takes months to fix a simple vuln.

IE and Mizilla Firefox are both HTTP client applications, HTTP is an application level procotol, any thing happens at TCP level, like tcp session hijacking, should not   be taken as a problem of the application, am I right? Or I'm missing your point here? I'm all ears here and I'm eager to learn.

B.T.W, I'm at work, not able to input Chinese Characters.

论坛徽章:
0
96 [报告]
发表于 2006-04-24 22:34 |只看该作者
原帖由 colddawn 于 2006-4-24 09:54 发表
关于溢出,确实应该是有从用户态安全上下文溢出到root权限的可能的,楼上那位说人buffer overflow没学过的人难免有点诽谤的嫌疑了,作者这篇文章既然是小说了,不可能每个技术细节都符合现实状况,可以允许稍微夸 ...

Yes, it's easy to say what a buffer overflow is. But never say unix/linux is unsafe because there's buffer overflow, that sounds extremly ridiculous and miss leading.

Be advised, if you want to talk about BO, you should say something about a specially unknown/unpatched BO vuln exist in a speical application on the certain system.

论坛徽章:
0
97 [报告]
发表于 2006-04-24 22:46 |只看该作者
原帖由 skipjack 于 2006-4-24 09:42 发表


现在看你到是有种“的感觉了。
哈哈...
如果你感觉好,就贴出来吧。
就算我看不懂,也会存档的。

"怀才不遇”?
Don't really know why you said this.

I'm doing very well and I love my security related job , IMO, I'm doing  one of the most exciting job in this  world, seriously.

What I don't like this article is that  the author is trying to make him a genuis while he sounds like an idiot.

One book is really good for those who care about security and hacking:
"The shellcoder's Handbook", by Jack Koziol, David Litchfield, Dave Aitel...

[ 本帖最后由 valentine 于 2006-4-24 22:47 编辑 ]

论坛徽章:
0
98 [报告]
发表于 2006-04-24 22:47 |只看该作者
原帖由 valentine 于 2006-4-24 22:26 发表


Most of IE vulnerabilities come from COM/Activex. A COM object can be initialized even it is not masked as safe for scripting, this has been proved to be very dangerous. Lots of memory corrupti ...


没关系,我知道你现在上班了。呵呵...有时差
http应该属于那种一问一答式的交互协议,浏览器在没有发送request请求时,不应该对response做出反应。但我发现IE和mozilla在协议实现上有很大的不同。当mozilla和http server建立TCP三次握手后,如果这时server返回response信息,mozilla会无条件的去响应它。
我测试的环境是这样的,当我在局域网中截获mozilla与sever的TCP三次握手ack包时,迅速给它发送一个重定向页面(这个包太好构造了,不是吗?),mozilla就会被我吸引过来,但IE不会。
我知道你的工作是漏洞挖掘,在这方面应该会比我有造诣,测试环境也比我这里好。我感觉这是一个不正常的协议实现,你觉的呢?

论坛徽章:
0
99 [报告]
发表于 2006-04-24 22:55 |只看该作者
原帖由 skipjack 于 2006-4-24 22:47 发表


没关系,我知道你现在上班了。呵呵...有时差
http应该属于那种一问一答式的交互协议,浏览器在没有发送request请求时,不应该对response做出反应。但我发现IE和mozilla在协议实现上有很大的不同。当mozilla和 ...

Yes, you really got a good point there. That's an improper protocol implentation and a security flaw.

One mitigating factor of this flaw is that TCP hijacking and Man-in-the-Middle attack is not available to a normal user, and in order to control the victim, you nead to exploit another vulnerability which can lead to code execution.

[ 本帖最后由 valentine 于 2006-4-24 23:32 编辑 ]

论坛徽章:
0
100 [报告]
发表于 2006-04-24 22:56 |只看该作者
原帖由 valentine 于 2006-4-24 22:46 发表

"怀才不遇”?
Don't really know why you said this.

I'm doing very well and I love my security related job , IMO, I'm doing  one of the most exciting job in this  world, seriously.

Wh ...


"怀才不遇”--> 玩笑 <--,我只是说你写小说在写法上不如作者而己。
我知道你的工作性质,也看过你的求职经历。
呵呵...每个人都有可取的地方不是吗?如果我说“漏洞挖掘”不就是“软件测试”吗,你觉的中听吗?
你也看到了,贴这个贴子在这里,并没有你预想的那二个结果。
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP