2010-05-21 │nginx文件类型错误解析漏洞+IIS源码泄露及文件类型解析错误
作者:逍遥乾坤 | 发表时间:2010-05-21 21:10:15 | 分类:网络随笔 | 阅读:11153
| 评论:4578
事情起因是今天在群里的一个朋友说当当网被黑了,我查看了一下貌似是t00ls的人集体“路过”的。
不过我大致的看了一下了解到时论坛的问题,跟主站没有任何关系,后来群里又有人说是nginx的事。
随后看到80sec公布了其nginx的漏洞,感觉这个漏洞的范围还是比较广的,而且利用方法较为简单,并且后果严重。
详细的信息我就不转载了,大家可以登录80sec查看:http://www.80sec.com/nginx-securit.html
我个人感觉,利用这个漏洞拿下的站应该都是大服务器,呵呵,反正应该是比较重要的,毕竟一般的不用nginx。
貌似现在也已经有牛人写出了扫描器了。只是暂时还没有几个人拿到呢。
漏洞的发现者是第一波测试,核心圈里第二波分享,我还算比较早的,估计也要是第三波了,虽然说出来没几个人知道,不过还是感觉自己out了。
今天80sec在半年都没有更新的情况下突然一天发布了两个漏洞,感觉挺吃惊的!
IIS源码泄露及文件类型解析错误,这个洞貌似以前就听说过,我看80sec上也没有过多的说明漏洞的形成原因和利用方法,感觉不太好,既然公布了,还是原创,就应该写的详细一些,否则有什么用呢?
网络一天比一天复杂,安全一天比一天严重!
不过我大致的看了一下了解到时论坛的问题,跟主站没有任何关系,后来群里又有人说是nginx的事。
随后看到80sec公布了其nginx的漏洞,感觉这个漏洞的范围还是比较广的,而且利用方法较为简单,并且后果严重。
详细的信息我就不转载了,大家可以登录80sec查看:http://www.80sec.com/nginx-securit.html
我个人感觉,利用这个漏洞拿下的站应该都是大服务器,呵呵,反正应该是比较重要的,毕竟一般的不用nginx。
貌似现在也已经有牛人写出了扫描器了。只是暂时还没有几个人拿到呢。
漏洞的发现者是第一波测试,核心圈里第二波分享,我还算比较早的,估计也要是第三波了,虽然说出来没几个人知道,不过还是感觉自己out了。
今天80sec在半年都没有更新的情况下突然一天发布了两个漏洞,感觉挺吃惊的!
IIS源码泄露及文件类型解析错误,这个洞貌似以前就听说过,我看80sec上也没有过多的说明漏洞的形成原因和利用方法,感觉不太好,既然公布了,还是原创,就应该写的详细一些,否则有什么用呢?
网络一天比一天复杂,安全一天比一天严重!
tobiconnors http://www.tobiconnors.com/(2022-08-13 07:53:17)
milumba http://www.milumba.com/(2022-07-12 05:04:41)
belljen http://www.belljen.net/(2022-07-02 09:01:02)
flatlandip http://www.flatlandip.com/(2022-06-30 03:19:18)
nnz-home http://www.nnz-home.net/(2022-06-18 02:58:04)
blminter http://www.blminter.net/(2022-05-04 08:08:45)
bibliowine http://www.bibliowine.com/(2022-04-22 15:05:32)
jazmarketingllc https://demo.jazmarketingllc.com/(2022-04-17 02:55:22)
innovafeline https://demo.innovafeline.com/(2022-04-17 02:55:22)
kacadodl https://demo.kacadodl.com/(2022-04-17 02:55:21)
eschoolman https://demo.eschoolman.com/(2022-04-17 02:54:57)
saponions http://www.saponions.com/(2022-04-16 09:56:43)
nevaktar https://www.nevaktar.com/(2022-04-15 20:20:20)
texhort https://www.texhort.com/(2022-04-15 20:20:18)
dubai-developer https://www.dubai-developer.com/(2022-04-15 20:20:17)
lottoguesses https://www.lottoguesses.com/(2022-04-15 20:20:12)
sureshbursu http://www.sureshbursu.com/(2022-04-09 08:08:45)
brownfont https://www.brownfont.com/(2022-04-05 03:57:16)
artemissuit https://www.artemissuit.com/(2022-04-05 03:57:15)
saharbeautytips https://www.saharbeautytips.com/(2022-04-05 03:57:15)
swejan https://www.swejan.com/(2022-04-05 03:56:51)
tzpoker http://www.tzpoker.com/(2022-03-11 10:07:00)
fabelkart https://demo.fabelkart.com/(2022-03-09 12:24:34)
eachenhome https://demo.eachenhome.com/(2022-03-09 12:24:33)
n-norton https://demo.n-norton.com/(2022-03-09 12:24:33)
basignon https://demo.basignon.com/(2022-03-09 12:24:32)
srsearthing https://demo.srsearthing.com/(2022-03-09 12:24:10)
kaisarbandar https://demo.kaisarbandar.com/(2022-03-09 05:41:04)
theopenmark https://demo.theopenmark.com/(2022-03-09 05:41:04)
abaa-salon https://demo.abaa-salon.com/(2022-03-09 05:41:03)
cerocreativos https://demo.cerocreativos.com/(2022-03-09 05:41:02)
n-norton https://demo.n-norton.com/(2022-03-09 05:40:39)
saemmit http://www.saemmit.com/(2022-03-08 23:04:26)
codexivetech https://demo.codexivetech.com/(2022-02-27 00:39:51)
mihaipascal https://demo.mihaipascal.com/(2022-02-27 00:39:50)
ahuela https://demo.ahuela.com/(2022-02-27 00:39:28)
hbstimes https://demo.hbstimes.com/(2022-02-23 18:52:09)
younglifenorthdekalb https://demo.younglifenorthdekalb.com/(2022-02-23 18:52:09)
ejobstore https://demo.ejobstore.com/(2022-02-23 18:52:08)
gorselzeka https://demo.gorselzeka.com/(2022-02-23 18:51:46)
nexiasjokergaming https://www.nexiasjokergaming.com/(2022-02-20 20:06:12)
roadrunneremaill https://www.roadrunneremaill.com/(2022-02-20 20:06:11)
ieltstoabroad https://www.ieltstoabroad.com/(2022-02-20 20:06:11)
justoneknow https://www.justoneknow.com/(2022-02-20 20:06:10)
dooduangmanman88 https://www.dooduangmanman88.com/(2022-02-20 20:05:46)
be-timeless-hair https://www.be-timeless-hair.com/(2022-02-20 00:37:02)
homestorymarket https://www.homestorymarket.com/(2022-02-20 00:37:01)
quickloan-24 https://www.quickloan-24.com/(2022-02-20 00:36:52)
seninandroidin https://www.seninandroidin.com/(2022-02-20 00:36:51)
mydayinlosangeles https://www.mydayinlosangeles.com/(2022-02-20 00:36:50)
mysummervilleford https://www.mysummervilleford.com/(2022-02-15 02:46:06)
getesionow https://www.getesionow.com/(2022-02-15 02:46:05)
uvabrand https://www.uvabrand.com/(2022-02-15 02:46:04)
simmonslabtop https://www.simmonslabtop.com/(2022-02-15 02:45:42)
rightwaysport https://demo.rightwaysport.com/(2022-02-11 18:15:41)
villahomeinteriors https://demo.villahomeinteriors.com/(2022-02-11 18:15:40)
enduratexuk https://demo.enduratexuk.com/(2022-02-11 18:15:40)
sigsalesinc https://demo.sigsalesinc.com/(2022-02-11 18:15:18)
draculovely https://www.draculovely.xyz/(2022-02-10 09:22:29)
liseliresimarsivi https://www.liseliresimarsivi.xyz/(2022-02-10 09:22:27)
tiancaic https://www.tiancaic.xyz/(2022-02-10 09:22:26)
buy-atarax https://www.buy-atarax.xyz/(2022-02-10 09:22:26)
levelxxx https://www.levelxxx.xyz/(2022-02-10 09:22:04)
temasyazilim https://www.temasyazilim.com/(2022-02-10 02:26:41)
buy-stealth-account https://www.buy-stealth-account.com/(2022-02-10 02:26:40)
katalog-nasa https://www.katalog-nasa.com/(2022-02-10 02:26:39)
tigerjed https://www.tigerjed.com/(2022-02-10 02:26:39)
kiddreamisdream https://www.kiddreamisdream.com/(2022-02-10 02:26:17)
desertaerie https://www.desertaerie.com/(2022-02-04 08:38:16)
florusbrazil https://www.florusbrazil.com/(2022-02-04 08:38:16)
luststyle https://www.luststyle.com/(2022-02-04 08:37:53)
thestorypole https://www.thestorypole.com/(2022-02-01 07:41:04)
enduratexuk https://www.enduratexuk.com/(2022-02-01 07:41:03)
tuffease https://www.tuffease.com/(2022-02-01 07:40:41)
celebum http://www.celebum.com/(2022-01-25 08:34:54)
evrimindustry https://www.evrimindustry.com/(2022-01-22 02:48:42)
amanahrasulullah https://www.amanahrasulullah.com/(2022-01-22 02:48:42)
ufundogs https://www.ufundogs.com/(2022-01-22 02:48:41)
teknobam https://www.teknobam.com/(2022-01-22 02:48:19)
ischool-bus https://www.ischool-bus.com/(2022-01-15 01:56:58)
tgiinfo https://www.tgiinfo.com/(2022-01-15 01:56:57)
jxjtncw https://www.jxjtncw.com/(2022-01-15 01:56:57)
curatorstl https://www.curatorstl.com/(2022-01-09 13:23:31)
malatyaneykursu https://www.malatyaneykursu.com/(2022-01-09 13:23:31)
arbogabyggtjanst https://www.arbogabyggtjanst.com/(2022-01-09 13:23:30)
tbaexploration https://www.tbaexploration.com/(2022-01-09 13:23:08)
pergolasense https://www.pergolasense.com/(2022-01-08 17:38:58)
thmeylike https://www.thmeylike.com/(2022-01-08 17:38:57)
sixxtees https://www.sixxtees.com/(2022-01-01 17:28:13)
lhroot https://www.lhroot.com/(2022-01-01 17:28:13)
stene-consulting https://www.stene-consulting.com/(2022-01-01 17:28:12)
vireeshbasavaraj https://www.vireeshbasavaraj.com/(2022-01-01 17:28:12)
curaakademiet https://www.curaakademiet.com/(2022-01-01 17:27:50)
lutaniccreations https://www.lutaniccreations.com/(2021-12-30 04:51:19)
reine-spa https://www.reine-spa.com/(2021-12-30 04:50:55)
debagliano http://www.debagliano.com/(2021-12-28 17:17:41)
desertaerie https://www.desertaerie.com/(2021-12-28 13:00:54)
austinaame https://www.austinaame.com/(2021-12-28 13:00:53)
misterphonie https://www.misterphonie.com/(2021-12-28 13:00:53)
kelleyyachtsales https://www.kelleyyachtsales.com/(2021-12-28 13:00:30)
spurtwelt http://www.spurtwelt.com/(2021-12-19 19:26:13)
thbogota https://www.thbogota.com/(2021-11-20 06:09:19)
gocstech https://www.gocstech.com/(2021-11-20 06:09:19)
oientalrugauction https://www.oientalrugauction.com/(2021-11-20 06:09:18)
loslunasdental https://www.loslunasdental.com/(2021-11-20 06:09:17)
kokomocanoe https://www.kokomocanoe.com/(2021-11-20 06:08:54)
paulbennison http://www.paulbennison.net/(2021-11-07 23:23:58)
eligro http://www.eligro.net/(2021-11-07 23:23:58)
ornyadams http://www.ornyadams.net/(2021-11-07 23:23:56)
midsland http://www.midsland.net/(2021-11-07 23:23:34)
czaterianie http://www.czaterianie.com/(2021-11-06 18:09:08)