<?xml version="1.0" encoding="gb2312" ?>
<rss version="2.0">
<channel>
<title>安全指南</title>
<link>http://www.cnpaf.nethttp://www.cnpaf.net/Class/SecurityTutorial/</link>
<description>网络安全 / / 安全指南</description>
<language>zh-cn</language>
<generator><![CDATA[    &lt;p&gt;版权所有 &lt;a href=&quot;http://www.cnpaf.net&quot;&gt;协议分析网&lt;/a&gt; 信箱:wayky#126.com(把&quot;#&quot;改成&quot;@&quot;)&lt;br /&gt;
Copyright (C)&lt;span style=&quot;FONT-WEIGHT: bold; FONT-SIZE: 8.5pt; FONT-STYLE: italic; FONT-FAMILY: Arial&quot;&gt;
&lt;span style=&quot;COLOR: #f26522&quot;&gt;www.&lt;span style=&quot;COLOR: #006699&quot;&gt;Cnpaf.&lt;/span&gt;N&lt;/span&gt;et &lt;span style=&quot;COLOR: #f26522&quot;&gt;2004-2013&lt;/span&gt; &lt;/span&gt; All Rights Reserved.京公网安备110105010524]]></generator>
<webmaster>wayky@126.com</webmaster>
<item>
    <title><![CDATA[密码学之密码分析]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200810/23077.html</link>
    <description><![CDATA[密码分析（英语：cryptanalysis，来源于希腊语krypts，即隐藏，以及analein，即解开），是一门研究在不知道通常解密所需要的秘密信息的情况下对加密的信息进行解密的学问。通常，这需要寻找一个秘密的钥匙。用不是很正规的话来说，这就是所谓的破解密码。 密码分析这个]]></description>
    <pubDate>2008-10-23</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[网络安全之入侵检测技术]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200810/23071.html</link>
    <description><![CDATA[入侵检测技术是为保证计算机系统的安全而设计与配置的一种能够及时发现并报告系统中未授权或异常现象的技术，是一种用于检测计算机网络中违反安全策略行为的技术。 入侵检测被认为是防火墙之后的第二道安全闸门。IDS主要用来监视和分析用户及系统的活动，可以识别反映]]></description>
    <pubDate>2008-10-23</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[最不称职网络管理员]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200610/16326.html</link>
    <description><![CDATA[大多数网络管理员对工作游刃有余，并且可以在一个具有高度挑战和技术难度的任务中，使工作顺利进行。然而，有时他们中的某些人会变得很难缠，并会阻碍事情的顺利进行。所以，我定义了一份最新的类别名单，在这里，我们将看到七种最不安全的网络管理员，并且总结了我观]]></description>
    <pubDate>2006-10-19</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Juniper NSM中远程拒绝服务漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12881.html</link>
    <description><![CDATA[]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Cisco CallManager拒绝服务漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12880.html</link>
    <description><![CDATA[详细描述： Cisco CallManager（CCM）是Cisco IP电话解决方案的基于软件的呼叫处理组件。 一些CCM版本没有主动管理TCP连接和Windows消息，导致一些公开的发布端口受拒绝服务攻击影响： 1 CCM没有足够主动的超时到2000端口的TCP连接，导致足够多的开放连接会耗尽内存和C]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Linux Kernel本地拒绝服务漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12879.html</link>
    <description><![CDATA[受影响系统： Linux kernel 不受影响系统： Linux kernel 2.6.12.5 详细描述： Linux Kernel是开放源码操作系统Linux所使用的内核。 Linux Kernel的zlib例程的inflate.c中存在漏洞。如果用户打开了特制的压缩文件的话，就可能导致kernel崩溃。 厂商补丁： Linux -----]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Oracle Reports文件覆盖漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12878.html</link>
    <description><![CDATA[描述： Oracle是一款大型的商业数据库系统，Oracle Reports是Oracle的一款企业报表工具。 Oracle Reports Server的Web界面存在任意文件覆盖漏洞，攻击者可能利用此漏洞获取对主机的控制。 攻击者可以通过指定desname的特殊参数值导致Oracle Reports覆盖应用服务器上的]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Util-Linux脚本命令覆盖漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12877.html</link>
    <description><![CDATA[漏洞信息 util-linux包含大量底层系统工具。 util-linux script命令存在一个硬链接错误，本地攻击者可以利用漏洞覆盖系统文件。 如果本地用户在目录中放置一个typescript硬链接文件，那么运行script时可导致目标文件被覆盖，造成拒绝服务问题。 BUGTRAQ ID: 16280 C]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Oracle Database SQL注入漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12876.html</link>
    <description><![CDATA[漏洞信息 Oracle是一款商业性质功能强大的数据库。 Oracle SYS.KUPV$FT_INT包含多个SQL注入问题，远程攻击者可以利用漏洞获得敏感信息。 SYS.KUPV$FT_INT包在函数UPDATE_JOB, ACTIVE_JOB, ATTACH_POSSIBLE, ATTACH_TO_JOB, CREATE_NEW_JOB, DELETE_JOB, DELETE_MASTER_]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Toshiba蓝牙栈文件目录遍历漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12875.html</link>
    <description><![CDATA[]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Honeyd远程虚拟主机检测漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12874.html</link>
    <description><![CDATA[漏洞信息 Honeyd是一款小型的守护程序, 可以在网络上创建虚拟主机。 Honeyd处理IP重组代码存在问题，远程攻击者可以利用漏洞检测虚拟主机。 成功的攻击可允许远程攻击者枚举Honeyd主机并对这些目标机器进行攻击。目前没有详细漏洞细节提供。 BUGTRAQ ID: 16595 CNCAN I]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[微软 Media Player惊曝高危漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12873.html</link>
    <description><![CDATA[]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[微软声称明年再补IE新曝漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12872.html</link>
    <description><![CDATA[【eNet硅谷动力消息】2月14日记者获悉，反病毒软件厂商江民科技反病毒研究中心监测到，微软IE浏览器的一个最新文件安装漏洞被公布在互联网上。利用该漏洞，可以制作特殊的网页，借助于用户的操作，能够将网络文件下载到用户本地磁盘，而没有任何安全提示信息。受影响的]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[FLASH管理程序存在多个安全漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12871.html</link>
    <description><![CDATA[漏洞信息 ImageVue是一款基于PHP的FLASH管理程序。 ImageVue上传脚本对用户提交的文件缺少正确处理，远程攻击者可以利用漏洞上传恶意文件并执行。 由于文件脚本对上传文件的扩展缺少正确过滤。可上传文件到文件夹并执行。 另外存在可查看目录列表等问题。 BUGTRAQ ID:]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[HiveMail邮件程序多个安全漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12870.html</link>
    <description><![CDATA[漏洞信息 HiveMail是一款基于PHP的WEB邮件程序。 HiveMail多个脚本对用户提交的URI数据缺少过滤，远程攻击者可以利用漏洞获得敏感信息或以WEB权限执行任意命令。 addressbook.update.php脚本对用户提交给$contactgroupid参数缺少过滤，提交恶意参数可导致以WEB权限]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[RunCMS内容程序代码执行漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12869.html</link>
    <description><![CDATA[漏洞信息 RunCMS是一款基于WEB的内容管理程序。 RunCMS不充分过滤用户提交URI数据，远程攻击者可以利用漏洞以WEB权限执行任意命令。 问题一是通过FCKEDITOR连接器可上传任意文件，导致可上传任意PHP文件如(.php.txt )，并可以WEB权限执行。 问题二是class.forumpost]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[IBM目录服务程序内存破坏漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12868.html</link>
    <description><![CDATA[BUGTRAQ ID: 16593 CNCAN ID:CNCAN-2006021308 漏洞消息时间:2006-02-11 漏洞起因 访问验证错误 影响系统 IBM Directory Server 6.0 .0 危害 远程攻击者可以利用漏洞进行拒绝服务或任意指令执行攻击 攻击所需条件 攻击者必须访问IBM Tivoli Directory Server。 漏洞信]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[PHPStatus统计程序多个输入漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12867.html</link>
    <description><![CDATA[漏洞信息 PHPStatus是一款基于PHP的站点统计程序。 PHPStatus不充分过滤用户提交URI数据，远程攻击者可以利用漏洞获得敏感信息或绕过验证访问应用程序。 问题一是check.php脚本对username参数缺少过滤，可导致SQL注入攻击。 问题二是check.php存在验证绕过问题，]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[QNX Neutrino RTOS参数溢出漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12866.html</link>
    <description><![CDATA[]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[IBM Tivoli Access 目录漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12865.html</link>
    <description><![CDATA[漏洞信息 IBM Tivoli Access Manager是一款商业性质企业和电子商务应用程序策略访问控制解决方案。 IBM Tivoli Access Manager的TAM插件不充分用户提交的URI数据，远程攻击者可以利用漏洞以WEB权限查看系统文件内容。 问题是插件包含的pkmslogout对用户提交给filename]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Lotus Domino远程拒绝服务漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12864.html</link>
    <description><![CDATA[漏洞信息 Lotus Domino是集电子邮件、文档数据库、快速应用开发技术以及Web技术为一体的电子邮件与群件平台。 Lotus Domino的LDAP协议存在安全问题，远程攻击者可以利用漏洞对系统进行拒绝服务攻击。 由于LDAP服务器不正确处理畸形请求，攻击者发送畸形包可导致应用程]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Nokia N70手机远程拒绝服务漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12863.html</link>
    <description><![CDATA[漏洞信息 Nokia N70是一款的移动电话。 Nokia N70蓝牙存在拒绝服务问题，远程攻击者可以利用漏洞使手机停止响应。 提交恶意包给手机的蓝牙服务，成功的一次攻击允许攻击者破坏内存并触发拒绝服务攻击。 影响系统 Nokia N70 危害 远程攻击者可以利用漏洞使手机停止响应]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[索爱手机蓝牙服务存在安全漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12862.html</link>
    <description><![CDATA[2月10日消息，相继有两家安全机构日前表示，索尼爱立信的四款手机存在安全漏洞，容易遭受“拒绝服务”式攻击。 据CNET报道，法国安全突发事件响应小组（FrSIRT）日前表示，包括K600i和T68i在内的索尼爱立信手机存在安全漏洞，该漏洞主要存在于蓝牙服务中。而丹麦安全公]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[PHP日历程序远程文件包含漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12861.html</link>
    <description><![CDATA[漏洞信息 PHP ICalendar是一款基于PHP的日历程序。 PHP ICalendar不充分过滤用户提交的URI输入，远程攻击者可以利用漏洞以WEB权限执行任意PHP命令。 问题存在于Template.PHP脚本中，函数parse($file)调用include($file)对$file变量缺少过滤。指定远程服务上的任意文]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[三星E730手机远程拒绝服务漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12860.html</link>
    <description><![CDATA[漏洞信息 Samsung E730是一款的移动电话。 Samsung E730蓝牙存在拒绝服务问题，远程攻击者可以利用漏洞使手机停止响应。 提交恶意包给手机的蓝牙服务，成功的一次攻击允许攻击者破坏内存并触发拒绝服务攻击。 BUGTRAQ ID: 16517 CNCAN ID:CNCAN-2006020813 漏洞消息时]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Lexmark打印机远程代码执行漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12859.html</link>
    <description><![CDATA[]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Linux Kernel拒绝服务漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12858.html</link>
    <description><![CDATA[描述： Linux Kernel是开放源码操作系统Linux所使用的内核。 Linux Kernel的IPv6协议处理存在问题，本地攻击者可能利用此漏洞对系统执行拒绝服务攻击。 Linux Kernel的IPv6流标签处理代码（ip6_flowlabel.c）在某些环境中可能修改错误的变量，这允许本地攻击者通过释放]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Windows系统又出现新的WMF漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12857.html</link>
    <description><![CDATA[2月9日消息，微软称Windows操作系统中最新发现了两项安全漏洞，并且表示目前还存在第三项安全漏洞的可能性。 news.com.com报道，其中一项安全漏洞存在于Windows ME和2000操作系统平台，在IE浏览器处理Windows Meta格式图像的过程中，存在安全漏洞，并且可能被黑客利用]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Sun发补丁修补Java“高危”漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12856.html</link>
    <description><![CDATA[2月9日消息 Sun微系统公司周二发布补丁程序修补Java Runtime Environment（JRE）上存在的7个“高危”漏洞。这些漏洞可使一个恶意黑客取得对用户系统的远程控制。 据zdnet网站引用安全专家的话称，这些漏洞影响到使用Sun公司的JDK1.5、SDK1.3和1.4、JRE 1.3, 1.4, 1.5和]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[EmuLinker处理畸形包存在漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12855.html</link>
    <description><![CDATA[漏洞信息 Emulinker是一款模拟器联网对战建服工具。 Emulinker处理畸形网络包存在问题，远程攻击者可以利用漏洞对服务程序进行拒绝服务攻击。 目前没有详细漏洞细节提供。 BUGTRAQ ID: 16733 CNCAN ID:CNCAN-2006022101 漏洞消息时间:2006-02-20 漏洞起因 异常条件处理]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[苹果Safari浏览器 惊曝危险漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12854.html</link>
    <description><![CDATA[2月23日消息 苹果电脑公司Safari浏览器一个新的严重级安全漏洞的发现以及新的针对苹果OS X操作系统蠕虫的接连出现，不禁使人们意识到，运行非Windows操作系统的电脑在也无法高枕无忧了。 据PCmag网站报道，安全和反病毒公司2月21日发出警告称，Safari新发现的一个严重]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Fedora目录服务器信息泄露漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12853.html</link>
    <description><![CDATA[]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[南极星字体处理缓冲区溢出漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12852.html</link>
    <description><![CDATA[描述： 南极星是一款流行的中文文字处理系统，具有繁简自动多内码识别/转换功能。 南极星在处理文档文件时存在缓冲区溢出漏洞，远程攻击者可能利用此漏洞在用户机器上执行任意指令。 南极星在读取NJStar文档文件（.njx）的字体名称时存在边界检查错误，可能导致栈溢]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Cisco Guard存在认证绕过的漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12851.html</link>
    <description><![CDATA[描述： Cisco Guard和Cisco Traffic Anomaly Detector设备都是缓解分布式拒绝服务（DDoS）攻击的设备，可以检测是否存在潜在的DDoS攻击，并转移流向所监控网络的攻击流量而不会影响合法通讯流。 Cisco Guard和Cisco Anomaly Traffic Detector对访问认证处理上存在漏洞]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[微软IE浏览器发现严重安全漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12850.html</link>
    <description><![CDATA[]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Google新版搜索工具存在漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12849.html</link>
    <description><![CDATA[【eNet硅谷动力消息】2月21日外电报道，市场研究机构Gartner对企业发出警告，Google最新推出的桌面软件测试版本存在安全风险，而Google对此也表示同意。 2月9日，Google推出了Google Desktop 3测试版本。这是一种免费下载的软件，用户可以选择对多个电脑进行搜索。这种]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Sun Solaris本地权限提升漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12848.html</link>
    <description><![CDATA[描述： Solaris是一款由Sun开发和维护的商业性质UNIX操作系统。 Solaris in.rexecd(1M)守护程序存在安全漏洞，本地非特权用户可以在Kerberos系统上以提升的权限执行任意命令。 受影响系统： Sun Solaris 10_x86 Sun Solaris 10.0 不受影响系统： Sun Solaris 9.0_x86 S]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[QNX RTOS 本地拒绝服务漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12847.html</link>
    <description><![CDATA[漏洞信息 QNX Neutrino RTOS (QNX)是一款设计用于嵌入系统的实时操作系统。 QNX Neutrino RTOS (QNX)不正确处理恶意命令，本地攻击者可以利用漏洞对系统进行拒绝服务攻击。 本地攻击者执行如下命令： echo -e break *0xb032d59f\nr\ncont\ncont gdb gdb 可导致操作系]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[PHP Link Directory存安全漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12846.html</link>
    <description><![CDATA[漏洞信息 PHP Link Directory是一款基于PHP的目录收录程序。 PHP Link Directory不安全使用ADOdb和PHPMailer，远程攻击者可以利用漏洞获得敏感信息。 由于ADOdb和PHPMailer存在SQL等攻击，因此影响调用这两个应用的PHP Link Directory，恶意用户可以获得敏感信息，执行]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[BCB编译器SIZEOF操作符漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12845.html</link>
    <description><![CDATA[漏洞信息 BCB compiler是一款流行的编译器。 BCB编译器处理sizeof操作符存在问题，本地攻击者可以利用漏洞对系统进行拒绝服务或提升特权攻击。 由于错误使用sizeof操作符，可导致整数溢出，进行拒绝服务攻击。 漏洞消息时间:2006-02-06 漏洞起因 设计错误 影响系统 BCB]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Photoshop惊爆安全漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12844.html</link>
    <description><![CDATA[Adobe近日警告说，该公司的Photoshop CS2等软件暴露出一个文件许可方面的安全漏洞，相应的升级补丁已经提供。 这次受影响的软件包括Windows平台和Mac OS平台的Adobe Creative Suite 2、Adobe Photoshop CS2、Adobe Illustrator CS2等。如果这些程序以多用户共享的方式]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[05年微软操作系统十大漏洞回顾]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12843.html</link>
    <description><![CDATA[众所周知，每次微软的系统漏洞被发现后，针对该漏洞的恶意代码很快就会出现在网上，一系列案例证明，从漏洞被发现到恶意代码出现，中间的时差开始变得越来越短。更为严重的是，从去年至今，微软操作系统接连出现了数个0day漏洞。去年12月底，WMF（图元文件）的0day漏洞]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Kerio WinRoute防火墙存在漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12842.html</link>
    <description><![CDATA[]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Sun Java System本地绕过的漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12841.html</link>
    <description><![CDATA[描述： Sun Java System是流行的Java运行环境。 Sun Java System Access Manager对访问控制的处理上存在漏洞，本地特权用户可能利用此漏洞绕过访问控制非授权获取访问。 本地以root登录的用户可以使用amadmin命令行工具以最高权限管理Access Manager。 受影响系统： Su]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[CAM/CAFT 存在拒绝服务的漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12840.html</link>
    <description><![CDATA[描述： CA Message Queuing (CAM/CAFT)是一种集成于各种CA产品中的应用组件，提供消息存储转发机制的框架。 CAM/CAFT实现上存在两个漏洞，远程攻击者可能利用这些漏洞对服务器进程执行拒绝服务攻击。 第一个漏洞是由于服务器进程在4105端口上收到一个特殊构造的报文，]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[BitComet处理缓冲区溢出漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12839.html</link>
    <description><![CDATA[]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[D-Link无线路由器拒绝服务漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12838.html</link>
    <description><![CDATA[]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Microsoft IE脚本引擎溢出漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12837.html</link>
    <description><![CDATA[]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[WebSPELL程序存在SQL注入漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12836.html</link>
    <description><![CDATA[漏洞信息 webSPELL是一款基于PHP的WEB应用程序。 webSPELL不正确过滤用户提交的URI输入，远程攻击者可以利用漏洞进行SQL注入攻击获得敏感信息。 问题是search.php脚本对用户提交的参数数据缺少过滤，提交恶意SQL查询作为参数数据，可更改原来的SQL逻辑，获得敏感信息]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>
<item>
    <title><![CDATA[Sun Solaris本地特权提升漏洞]]></title>
    <link>http://www.cnpaf.net/Class/SecurityTutorial/200602/12835.html</link>
    <description><![CDATA[漏洞信息 Sun Solaris是一款商业性质操作系统。 Sun Solaris in.rexecd守护进程存在安全问题，本地攻击者可以利用漏洞提升特权。 目前没有详细漏洞细节提供。 BUGTRAQ ID: 16658 CNCAN ID:CNCAN-2006021612 漏洞消息时间:2006-02-15 漏洞起因 未明错误 影响系统 Sun So]]></description>
    <pubDate>2006-02-25</pubDate>
    <category>安全指南</category>
    <author>秩名</author>
    <comments>协议分析网</comments>
</item>

</channel>
</rss>
