亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來到蟲蟲下載站! | ?? 資源下載 ?? 資源專輯 ?? 關于我們
? 蟲蟲下載站

?? perlfilterlecture.html

?? a collection of mega hacking tools
?? HTML
?? 第 1 頁 / 共 3 頁
字號:


<HTML><HEAD><TITLE>Problems in Perl Filters - by b0iler</TITLE>

</HEAD>

<BODY bgColor=black><FONT color=#ffffff>

<hr color="#808080" width="60%" size="1">

<H1 align="center"><font size="4">Problems in Perl Filters</font></H1>

<p align="center">&nbsp;by <a href="mailto:b0iler@hotmail.com">b0iler</a> <BR>&nbsp; lecture given on 

may 17th in irc.unixhideout.con #bsrf<BR>&nbsp;Written for :<BR>&nbsp;<A 

href="http://b0iler.eyeonsecurity.net/">http://b0iler.eyeonsecurity.net/</A> - 

my site full of other cool tutorials<BR>&nbsp;<A 

href="http://blacksun.box.sk/">http://blacksun.box.sk/</A> - a legendary site 

full of original tutorials </p>

<hr color="#808080" width="60%" size="1">

<p align="left"><BR><BR>--- b0iler has changed the topic to: 

Blacksun Research Facility - <a href="http://blacksun.box.sk">http://blacksun.box.sk</a> - lecture in progress: 

"Problems in Perl Filters" - msg questions during lecture to b0iler. <BR>--- 

b0iler sets modes [#bsrf +m]<BR>

</p>

<TABLE cellSpacing=2 cellPadding=0 width="100%">

  <TBODY>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD width="100%"><FONT color=#ffffff>Common Filtering Problems in 

      Perl.</FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>--intro</FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>This lecture may also be helpful to other 

      languages, but the exact syntax and ideas are for perl.</FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>This lecture will be +m and all questions will be 

      msg'd to me, msg me questions anytime and I will ether answer them at that 

      time, or save it till the end.</FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>This lecture may go at a slow pace, this is so I 

      can think things out.. since my planning of this lecture was pretty weak. 

      If you get bored, too bad XD~</FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>--</FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>The Main Concepts in Evading Perl Filters 

      Are:</FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>Complete lack of filters.</FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>Filters that forget characters.</FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>Filters that are in the wrong order.</FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>Filters that filter previous filters (or filter 

      themselves! I'll explain later).</FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>And multiple inputted variables forgotten in the 

      filters.</FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>--</FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>The What and Why of Perl Filters:</FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>Lets get into what perl filters are and why they 

      are so important in terms of security.</FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>Filters are ways perl programers stop bad things 

      from happening. It's my way of saying things that change something.. most 

      of the time it is just reg ex.</FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>For example, if you do: </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>$blah = `cat $ENV{'QUERY_STRING'}`; </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>Then attackers can easily input something like: 

      </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>script.cgi?/etc/password </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>Which would read your password file, or they could 

      be even more tricky and do something to this effect: </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>script.cgi?file.txt;rm -rf anything/ </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>(need to url encode some characters) </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>So perl programmers filter out characters which 

      can do bad things. </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>This is a pretty good idea, and almost every 

      script should have some kind of filtering system set up. Although even one 

      flaw in a filtering system can lead to alot of security headaches. 

    </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>-- </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>Types Of Filtering: </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>There are two main types of filtering, they are: 

      </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>input </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>output </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>The input filtering is the most used, and is 

      usually the most serious for security. </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>It comes before any action is taken on the user 

      input. This will stop any bad characters from effecting the actions of the 

      script. </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>Many people make the mistake to only filter input. 

      Although not always nessasary, output filtering is very useful in stopping 

      file reading vulnerabilities, cross site scriptting, and other attacks. 

      </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>Output filtering is filtering things right before 

      they are outputted to the client, database, file, or other outputs. 

    </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>Some times the output filtering may look to be 

      pointless, but data may have been changed throughout the script's 

      execution, so checking to make sure nothing bad is outputted can be a good 

      idea even when you are fairly sure nothing bad can be. </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>-- </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>Ways of Filtering: </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>There is also two main ways of filtering: 

    </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>Filtering bad input </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>Allowing good input </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>There are also other possible ways to filter, such 

      as length checking, pattern checking, and other odd ones. </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>Filtering bad input is the most used, and the one 

      with the most mistakes by the programmers. </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>When filtering bad input it is extremely easy to 

      forget something or not know of a feature in perl or a feature in an 

      external program which your script uses. </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>These forgotten filters can lead to 

      vulnerabilities very easily. It just takes the attacker awhile to think up 

      of creative ways to evade the filters or to do something a different way - 

      if one way is filtered do it a different way which isn't filtered. 

    </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>Allowing good input is the preferred way of 

      stopping bad input from becoming a security problem. </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>This is because you are only allowing the good 

      character to get by, and stopping all possible bad combinations which 

      would have been hard to filter out with filtering bad input. </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>Sometimes allowing input is almost impossible if 

      you want to give users any flexability. You cannot always hold them to a 

      set of characters, but you need to make a desision on how much importance 

      should go into security and how much into useability. </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>Here is an example of filtering bad input: 

    </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>$blah = $ENV{'QUERY_STRING'}; </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>$blah =~ s/\;//; </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>print `cat $blah`; </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>This will stop people from doing `cat 

      file.txt;touch file2.txt` (using the ; to issue another command). 

    </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>But if you read my "Hacking CGI - Security and 

      Exploitation" tutorial ( 

      http://b0iler.eyeonsecurity.net/tutorials/hackingcgi.htm ) then you will 

      read about the number of ways to use different methods to do things in 

      system commands. </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>It is extremely hard to stop all the possible 

      combinations of bad input individually. So instead lets take a look at 

      only allowing good input: </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>$blah = $ENV{'QUERY_STRING'}; </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>$blah =~ s/[^a-zA-Z0-9\.\-_]//g; </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>print `cat $blah`; </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>print `cat $blah`; #* </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>This will stop anything that might not be good in 

      a filename from being cat'd. But there is another method of allowing good 

      input that I prefer. </FONT></TD></TR>

  <TR>

    <TD><FONT color=#ffffff>&lt;b0iler&gt;</FONT></TD>

    <TD><FONT color=#ffffff>This method is denying access to anything if the 

      user inputs a character not allowed: </FONT></TD></TR>

  <TR>

?? 快捷鍵說明

復制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號 Ctrl + =
減小字號 Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
国产精品一区二区黑丝| 亚洲色图欧美偷拍| 欧美日韩国产一级片| 成a人片亚洲日本久久| 国产美女在线观看一区| 国内精品伊人久久久久av影院| 图片区小说区区亚洲影院| 日韩精品视频网| 蜜桃91丨九色丨蝌蚪91桃色| 久久精品免费看| 国产成人免费视| 成人app在线观看| 97久久精品人人做人人爽| 日本韩国精品在线| 欧美日韩电影在线播放| 日韩精品一区二区三区三区免费| 欧美mv和日韩mv的网站| 国产女主播视频一区二区| 日本一区二区三区免费乱视频| 亚洲日本护士毛茸茸| 亚洲午夜在线视频| 久久99精品国产91久久来源| 国产精品99久久不卡二区| 91视频一区二区| 91麻豆精品国产自产在线 | 99国产精品久久久久久久久久久 | 欧美三级电影在线观看| 欧美一级爆毛片| 国产日韩欧美精品一区| 亚洲麻豆国产自偷在线| 午夜日韩在线电影| 国产成人在线看| 在线中文字幕一区二区| 亚洲精品在线三区| 樱桃国产成人精品视频| 激情深爱一区二区| 色婷婷亚洲婷婷| 2023国产精品自拍| 一区二区三区在线观看动漫| 国产在线精品免费av| 欧美综合在线视频| 国产欧美一区二区在线观看| 日本不卡123| 91黄色免费观看| 国产日韩高清在线| 久久99日本精品| 欧美中文字幕一二三区视频| 久久久久久麻豆| 日本欧美一区二区在线观看| 91丝袜国产在线播放| 精品久久久久香蕉网| 亚洲一卡二卡三卡四卡| 岛国精品在线播放| 日韩欧美成人午夜| 日韩不卡一区二区| 欧美无砖砖区免费| 最新热久久免费视频| 国产大陆亚洲精品国产| 日韩欧美一区中文| 丝袜美腿亚洲色图| 欧美性生活久久| 日韩美女啊v在线免费观看| 国产精品小仙女| 日韩精品一区二区在线观看| 亚洲妇熟xx妇色黄| 欧美亚洲综合另类| 亚洲乱码中文字幕| 色综合色综合色综合| 国产精品成人免费在线| 国产福利一区在线| 欧美国产激情二区三区| 国产成人精品aa毛片| 日本一区二区三区久久久久久久久不| 国内久久婷婷综合| 亚洲国产精品av| 成人av在线播放网站| 国产精品亲子乱子伦xxxx裸| 国产成人免费高清| 国产精品欧美精品| av在线不卡免费看| 中文字幕人成不卡一区| 色美美综合视频| 午夜精品爽啪视频| 日韩精品一区二区三区蜜臀 | 91精品一区二区三区久久久久久| 日韩综合在线视频| 欧美一区二区黄| 精品一二三四区| 国产日韩欧美a| 91麻豆精东视频| 亚洲香蕉伊在人在线观| 日韩午夜精品视频| 国产一区二区三区不卡在线观看| 国产欧美一区二区精品性| 成人短视频下载| 一区二区三区国产精品| 在线播放国产精品二区一二区四区| 三级欧美韩日大片在线看| 欧美精品一区二区高清在线观看 | 欧美日韩国产电影| 理论电影国产精品| 中文字幕日韩一区| 日韩一区二区视频| 不卡一二三区首页| 日韩电影在线观看电影| 中文字幕精品一区二区三区精品 | 久久av中文字幕片| 综合亚洲深深色噜噜狠狠网站| 欧美视频在线观看一区二区| 国产原创一区二区三区| 亚洲免费在线播放| 日韩女同互慰一区二区| 色婷婷激情综合| 久久99精品久久久久婷婷| 亚洲乱码国产乱码精品精98午夜| 欧美一级二级三级蜜桃| 97久久精品人人做人人爽| 老汉av免费一区二区三区| 亚洲色图欧美偷拍| 久久理论电影网| 欧美酷刑日本凌虐凌虐| 成人综合激情网| 老司机午夜精品99久久| 一区二区三区欧美久久| 久久久精品综合| 91精品国产乱码久久蜜臀| 91免费观看视频| 国产精品1024| 久久国产精品区| 午夜视频在线观看一区二区| 国产精品不卡一区二区三区| 精品噜噜噜噜久久久久久久久试看| 91网站在线播放| 成人国产精品免费观看| 精品亚洲成a人在线观看| 五月天一区二区三区| 亚洲美腿欧美偷拍| 国产精品国产三级国产专播品爱网 | 日本乱人伦aⅴ精品| 国产毛片精品国产一区二区三区| 日韩主播视频在线| 亚洲一区在线观看视频| 亚洲视频图片小说| 国产精品久久99| 成人免费在线播放视频| 国产日产欧美一区二区三区| 精品国产免费人成在线观看| 欧美高清激情brazzers| 欧美日韩亚洲综合| 欧美综合久久久| 欧美日本韩国一区二区三区视频| 欧美亚洲国产一卡| 欧美日韩在线一区二区| 91搞黄在线观看| 欧美日韩1234| 91精品国产综合久久久蜜臀粉嫩| 日韩一二三区视频| 久久夜色精品一区| 久久久精品日韩欧美| 国产欧美在线观看一区| 日韩毛片精品高清免费| 亚洲欧美日韩国产一区二区三区| 一区二区三区美女| 日韩高清欧美激情| 麻豆91精品视频| 福利电影一区二区三区| 99久久久精品| 欧美伊人久久久久久午夜久久久久| 欧美日韩激情在线| 日韩三级高清在线| 国产日韩精品视频一区| 亚洲精品一二三区| 五月综合激情网| 国产原创一区二区| 91丨国产丨九色丨pron| 精品视频一区二区三区免费| 日韩一区和二区| 日本一区二区成人在线| 亚洲免费在线视频| 久久精品国产免费看久久精品| 国产精品一二三四| 97成人超碰视| 日韩欧美一级精品久久| 国产欧美日韩精品a在线观看| 亚洲自拍偷拍综合| 激情久久五月天| 色婷婷久久久久swag精品| 日韩欧美国产一区在线观看| 中文子幕无线码一区tr| 日韩电影在线看| 91在线看国产| 精品成人一区二区三区| 亚洲欧洲国产日本综合| 美女一区二区三区在线观看| 成人成人成人在线视频| 91精品久久久久久蜜臀| 日韩美女精品在线| 国产成人免费视| 日韩欧美美女一区二区三区| 亚洲激情校园春色|