以下来自xnu 10.6.7,我受不了了。动不动又PRIVATE,让不让人活了。
#if defined(XNU_KERNEL_PRIVATE) || !defined(KERNEL)
/*
* KERN_PROC subtype ops return arrays of augmented proc structures:
*/
struct _pcred {
char pc_lock[72]; /* opaque content */
struct ucred *pc_ucred; /* Current credentials. */
uid_t p_ruid; /* Real user id. */
uid_t p_svuid; /* Saved effective user id. */
gid_t p_rgid; /* Real group id. */
gid_t p_svgid; /* Saved effective group id. */
int p_refcnt; /* Number of references. */
};
struct _ucred {
int32_t cr_ref; /* reference count */
uid_t cr_uid; /* effective user id */
short cr_ngroups; /* number of groups */
gid_t cr_groups[NGROUPS]; /* groups */
};
struct kinfo_proc {
struct extern_proc kp_proc; /* proc structure */
struct eproc {
省略。。。
阅读全文
搜索此博客
2011年4月21日星期四
kinfo_proc 不见了
2009年8月30日星期日
Music Online Lite
投入了很多精力去做这个事情,我知道这在中国还需要一个过程,但是我还是比较愿意押宝Google的,希望不会令我太失望。
有兴趣的朋友可以访问http://yyqidian.com
阅读全文
2008年3月9日星期日
2008年3月7日星期五
ms08-010记录
CVE-2008-0077
From idefense:
When certain properties are assigned malformed values, memory can be corrupted in a way that leads to Internet Explorer making a call to a member function of an already released property object. If the memory location of the released property object happens to be filled by attacker controlled content, the attacker can execute arbitrary code.
From ZDI:
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page.
The specific flaw exists in the handling of the "by" property of an animateMotion SVG element. By assigning other DOM elements to this property, a memory corruption occurs during the destruction of a Variant data type. The corruption causes an overwrite of a virtual function address allowing for the execution of arbitrary code.
阅读全文
2008年1月9日星期三
2007年12月13日星期四
MS07-064 和MS07-069
http://seclists.org/fulldisclosure/2007/Dec/0347.html
关键:
This vulnerability exists in the DirextShow SAMI parser, which is
implemented in quartz.dll. When the SAMI parser copies parameters into
a stack buffer, it does not properly check the length of the parameter.
As such, parsing a specially crafted SAMI file can cause a stack-based
buffer overflow. This allows an attacker to execute arbitrary code.
不归我管,没空分析。
http://seclists.org/fulldisclosure/2007/Dec/0345.html
关键:
The vulnerability lies in the JavaScript setExpression method, which is
implemented in mshtml.dll. When malformed parameters are supplied,
memory can be corrupted in a way that results in Internet Explorer
accessing a previously deleted object. By creating a specially crafted
web page, it is possible for an attacker to control the contents of the
memory pointed to by the released object. This allows an attacker to
execute arbitrary code.
怎么现在MS都喜欢一下子更新十几个DLL,有毛病啊。
mshtml.dll大概有十几个函数变动,眼花缭乱。不是为了漏洞本身,要快速解决这个可以考虑直接从setExpression的参数入手,猜猜就应该猜到的。纯粹是为了分析着玩。
阅读全文
2007年7月2日星期一
Mysql sniff <1>
最近的一些记录。
首先是第一部分,MYSQL 认证过程分析,直接引用牛人文章了。
http://www.redferni.uklinux.net/mysql/MySQL-Protocol.html
这里的环境是基于4.1以上版本的。
阅读全文
2007年6月29日星期五
2007年5月29日星期二
About Phrack 64
介绍里面这段话
No, nothing is or was ever lost. Things change, security becomes a business, some hackers sell exploits, others post for fame, but Phrack is here, totally free, for the community. No business, no industry, no honey, baby. Only FREEDOM and KNOWLEDGE.
这才是真正的phrack。
http://phrack.org/
阅读全文
2007年5月25日星期五
2007年5月24日星期四
Intel PROSet Wireless bug
Intel PROSet Wireless 11.x版本存在一个bug,我本子的3945ABG网卡不定期出错,发现原来是新版本的驱动为了支持49xx无线网卡,用了新的驱动版本,估计有点毛病,换回原来的10.x以及对应的NET3wxxx驱动就没问题了,不排除和其它软件兼容问题的可能,没时间测试了。
阅读全文
2007年2月11日星期日
[ZT]支付宝控件漏洞——到底是谁在撒谎?
文档维护:tombkeeper
[Base64Decode("dG9tYmtlZXBlckB4Zm9jdXMub3Jn")]
文档创建:2007年02月09日
最后更改:2007年02月09日
cocoruder去年底向阿里巴巴报了一个淘宝旺旺ActiveX控件溢出的漏洞:
http://www.xfocus.net/articles/200701/901.html
结果阿里巴巴偷偷把漏洞补了,但是不肯发公告。
有了这个教训,前两天cocoruder发现支付宝登陆控件代码执行漏洞的时候就直接公布了:
http://www.xfocus.net/articles/200702/906.html
阿里巴巴的态度还是一样:偷偷把漏洞补上了。有媒体问阿里巴巴是不是有这回事,阿里巴巴完全否定:
http://tech.sina.com.cn/i/2007-02-08/06481375187.shtml
而且派人时刻盯着支付宝社区,凡出现相关主题的不利帖子立即删除,所以现在我们在支付宝社区能看到的都是“形势一片大好”的帖子:
http://club.alipay.com/show_thread-20-1--5930514-.htm
如果事情到此为止也就算了,安全研究界要的也不过就是对自己工作的认可,你想藏着掖着,我们也可以理解。彼此间也没什么深仇大恨,你不承认也就不承认吧。除了腾讯,国内的公司我还没见到几家愿意诚实地发布自己产品安全公告的,我们早就习惯了。
但是事情没有结束。
昨天wlj在donew上发了一篇关于此事的文章,原来的链接是这个:
http://home.donews.com/donews/article/1/110127.html
但是今天早晨我发现这篇文章已经不见了。
而且还针对这篇文章请“天威诚信数字认证中心”搞了一个“专家检测”:
http://club.alipay.com/show_thread-79---5930928-.htm
最无耻的是,可能因为wlj在文章里引用了我说的“就在2月8号,支付宝控件升级了。如果没问题,升级什么呢。”,阿里巴巴来了这么一句:“为了用户更安 全,我们加固了支付宝控件。如果您看到升级提示,请按要求操作。”这种行为不但是对全体支付宝用户的愚弄,也是对我们这些信息安全研究者的侮辱。
阿里巴巴在这里表现最突出的不是欺骗,也不是邪恶,而是愚蠢。认为死不认账就叫作危机公关了,殊不知裤子是遮不住屎的。下面就让我们看看阿里巴巴屁股帘后面藏的东西。
有问题的文件是pta.dll,这个东西属于“ActiveX控件”,只要装了这个东西,你访问的任何网页都可以通过IE浏览器来调用这个控件。也就是 说,如果这个控件有问题,你在访问任何网站的时候,都可能被该网站上的恶意网页攻击,在机器上安装木马。这种漏洞并不是什么稀罕东西,最近几年从 Flash到微软的Media Player等都出过很多类似的。而这种漏洞也是目前国内木马最为流行的传播方式。
明白了漏洞是怎么回事,再让我们来看看阿里巴巴的登陆控件到底有没有这个漏洞。是不是像“专家检测”的那样:“并未发现上述问题及其它隐患”。
先让我们来访问淘宝的登陆页面:
http://member1.taobao.com/member/login.jhtml
如果你以前没有安装过支付宝的控件,这时候就会看到一个安装的提示。在网页上点击右键,察看源代码,在其中搜索“aliedit”,你会看到类似这样的两行:
https://img.alipay.com/download/1009/aliedit.cab
http://img.alipay.com/download/1009/aliedit.exe
这两个都是支付宝的控件,前者是可以通过IE提示你安装的,后者是你可以手工下载安装的。控件的当前版本是1.0.0.9。
阿里巴巴在技术方面的愚蠢之处就是在事发后,仍然把各个版本的登陆控件保留在服务器上。所以我们可以通过访问下面这些链接取得所有版本的控件:
http://img.alipay.com/download/1006/aliedit.cab
http://img.alipay.com/download/1007/aliedit.cab
http://img.alipay.com/download/1008/aliedit.cab
http://img.alipay.com/download/1009/aliedit.cab
http://img.alipay.com/download/1006/aliedit.exe
http://img.alipay.com/download/1007/aliedit.exe
http://img.alipay.com/download/1008/aliedit.exe
http://img.alipay.com/download/1009/aliedit.exe
当然,本文发布后,阿里巴巴十有八九会把1.0.0.9之前的版本删除。不过我相信,在他们删除之前,已经有足够多的人看到了这篇文章,下载了这些文件。并且我已经把存在漏洞的1.0.0.7版文件传到了这里:
http://tombkeeper.googlepages.com/1.0.0.7_aliedit.cab
http://tombkeeper.googlepages.com/1.0.0.7_aliedit.exe
(相信阿里巴巴的活动能力不至于能从googlepages上删除文件,所以本文涉及的所有文件一律放在googlepages上。)
那么上面这些文件会不会是我伪造的,用来陷害阿里巴巴的呢?ActiveX控件的一大特点是必须有数字签名来保证其身份。请大家在aliedit.cab 或者aliedit.exe上单击右键,察看其属性。在属性窗口里有“数字签名”这一栏。任何人通过察看这里都可以确认该程序是由阿里巴巴发布的。
如果你不太懂为什么数字签名可以证明这个程序的确是由阿里巴巴发布的,请致电专业的数字认证公司“天威诚信数字认证中心”(010-84603568 转 708),问问他们,数字签名是不是能够认定这一点。
没考虑数字签名这个茬,这是阿里巴巴在这件事情上第三个愚蠢之处。
存在漏洞的pta.dll是从1.0.0.7版开始有的。这个1.0.0.7版的数字签名时间是2006年2月 22日 23:00:31,也就是说差不多也就在这个时间之后不久发布。1.0.0.8版控件的签名时间是2007年2月7日 22:30:09,在这个版本中,pta.dll被修复。从2006年2月到2007年2月,这个危险在我们的计算机上差不多存在了一年。
那么这个1.0.0.7版的控件到底有没有安全漏洞呢?现在大家都升级了控件,怎么测试呢?
很简单,从这个地址下载1.0.0.7版控件,然后关闭IE等浏览器安装控件:
http://img.alipay.com/download/1007/aliedit.exe
如果上面这个地址已经下载不到东西,那就是阿里巴巴已经动手删除了,大家可以从我这里下载:
http://tombkeeper.googlepages.com/1.0.0.7_aliedit.exe
下载后请察看一下数字签名,确认是“ZHEJIANG ZHIFUBAO NETWORK TECHNOLOGY CO., LTD.”发布的,而不是我造的假。
安装时会提示“目标文件已存在,而且比源文件要新”,点击“是”确认安装。如果提示要重新启动,就重新启动,否则旧版本控件不会生效。
然后访问下面这个链接,这是cocoruder提供的一个测试代码,如果执行成功,会运行系统的“计算器”;即使不成功,也会让IE出错崩溃:
http://tombkeeper.googlepages.com/alipay_1007_calc_poc.htm
现在任何人都可以确定无疑地知道,在2007年2月8日之前,阿里巴巴的支付宝控件的确是有极其严重的漏洞的。
事情到此结束了么?还没有。
我昨晚抽空看了一下修复了漏洞之后的1.0.0.9版本的pta.dll,发现这个文件仍然有问题,虽不至于导致入侵系统,但还是可以导致IE浏览器崩溃。
无论你的支付宝控件是什么版本,即使是最新的,访问下面这个URL都会导致IE崩溃:
http://tombkeeper.googlepages.com/alipay_1009_crash_poc.htm
根据操作系统和IE版本的不同,你可能会看到类似这些的窗口:
那么作为普通用户,如何保护自己呢?
很简单,运行系统的“命令提示符”,在其中输入:
regsvr32 /u %SystemRoot%\System32\aliedit\pta.dll
这样就解除了pta.dll在系统中的注册,任何网页都无法调用它。大家再访问上面的链接就不会崩溃了。
阅读全文
2007年2月5日星期一
2007年1月23日星期二
RkUnhooker
不是我喜欢半夜发文,是因为白天那网速,实在浏览不了什么网页,也查不了什么资料。
在台湾看到这个东西:http://x-solve.com/blog/?p=92
ADS+Filesystem 的rootkit. 虽然不是什么特别新的技术,但是,嘿嘿,自己看就明白了。
另外提一句:luoluo把JRE那个写成了java class单个文件,发到了bugtraq上,哈。
http://seclists.org/bugtraq/2007/Jan/0470.html
恭喜恭喜阿。
阅读全文
2007年1月16日星期二
2007年1月15日星期一
2007年1月8日星期一
About the atime mtime and ctime
Linux的文件系统通常包括change time,access time和modification time这3个时间标签。
st_atime
Time when file data was last accessed. Changed by the
following functions: creat(), mknod(), pipe(),
utime(2), and read(2).
st_mtime
Time when data was last modified. Changed by the fol-
lowing functions: creat(), mknod(), pipe(), utime(),
and write(2).
st_ctime
Time when file status was last changed. Changed by the
following functions: chmod(), chown(), creat(),
link(2), mknod(), pipe(), unlink(2), utime(), and
write().
在实际shell命令中,
先记录到这,后续会增加部分解释如何控制这三个标签不被变更。
阅读全文
2007年1月1日星期一
2006年12月30日星期六
Crypto Challenge
nequ writes: You have gotten past the outer barriers. You have installed a network sniffer. You were able to get access to some key-files. Full of hope you analyze the traffic of past days. Will you be able to break their code? Will you spot the weaknesses? the files you grabbed are: maybe you will: have the log of a black-hat-session that is denied get logs that leak more information, because of a thoughtless server-update .. in the next days. at the moment there seems to be a TAN-generator. the client sends the init for the generator, the server selects which TAN to see. but what are the *.ref files good for? why are there five TAN-transactions before login suceeds? maybe you have to take a closer look and rethink your presumptions. if you think you can take the risk, than start a session by posting a comment that includes your transmission. please make a new topic per session, i will post the servers answers. one session per NO-member maximum! if you make it to the prompt you win. here are the logs:
central.ref:
02 02 04 04 07 07 10 11 21 24 26 30 31 33 34 35
36 40 43 45 45 45 50 50 51 56 62 63 65 71 72 74
user.smith.ref:
01 01 05 07 12 12 13 13 16 16 23 26 27 35 36 37
40 41 44 45 46 47 50 53 54 60 60 60 61 64 71 77
role.smith.clerk.ref:
01 02 04 13 16 16 16 17 21 24 25 31 33 34 35 36
37 44 47 52 53 56 64 65 67 67 70 70 71 71 72 72
---8<-----[sniffer started] S: hello, this is broken-tin.neverbank.co.uk S: localtime: 07:51:37 Nov/01/2006 (GMT) C: login user=smith role=clerk C: 03 03 05 05 07 07 10 11 12 14 16 17 20 22 32 35 37 41 45 46 52 54 57 60 60 62 64 70 71 76 76 76 S: 2 C: 73405261 S: OK C: 00 07 10 15 16 20 24 27 27 30 32 33 34 36 37 42 43 45 50 54 56 62 62 62 63 67 71 71 75 75 76 76 S: 1 C: 72045361 S: OK C: 01 05 06 11 14 20 21 25 31 34 34 36 40 40 42 42 45 45 53 53 53 54 57 60 63 67 71 73 74 75 76 77 S: 0 C: 21750463 S: OK C: 00 05 12 15 17 17 17 20 21 22 23 25 27 32 34 37 40 41 43 51 51 54 54 56 56 60 61 64 70 73 75 75 S: 0 C: 14362075 S: OK C: 02 04 07 07 10 10 10 13 17 22 27 30 31 32 33 34 37 40 43 45 51 52 54 61 62 65 71 71 75 75 76 76 S: 2 C: 61435207 S: OK S: welcome Mr Smith! S: /usr/local/clerk/bin/smith>
---8<-----[sniffer started] S: hello, this is broken-tin.neverbank.co.uk S: localtime: 07:52:39 Nov/02/2006 (GMT) C: login user=smith role=clerk C: 02 05 07 10 10 12 12 15 15 21 24 26 26 26 34 35 36 41 42 43 44 46 47 52 53 57 61 61 63 67 71 77 S: 2 C: 07153264 S: OK C: 02 02 03 03 06 06 10 11 20 24 24 24 27 31 32 35 40 40 41 45 53 54 57 61 62 63 70 71 72 74 75 77 S: 0 C: 01425673 S: OK C: 02 02 03 03 04 04 10 11 12 15 16 17 20 21 25 25 25 32 34 36 42 46 47 50 50 56 57 60 66 71 74 75 S: 1 C: 14623075 S: OK C: 00 01 03 04 05 07 10 13 17 17 17 21 24 26 31 31 32 32 36 36 43 44 50 56 57 61 64 65 73 73 74 75 S: 1 C: 46217530 S: OK C: 01 01 02 02 04 04 12 14 17 24 26 27 30 30 36 37 40 43 43 43 45 50 53 54 55 56 57 62 63 65 70 77 S: 2 C: 70261354 S: OK S: welcome Mr Smith! S: /usr/local/clerk/bin/smith>
---8<-----[sniffer started] S: hello, this is broken-tin.neverbank.co.uk S: localtime: 07:59:07 Nov/03/2006 (GMT) C: login user=smith role=clerk C: 04 05 07 10 10 12 12 15 15 20 25 27 31 31 34 37 40 43 46 51 53 53 53 56 61 63 64 65 66 67 71 77 S: 2 C: 27065134 S: OK C: 01 01 02 02 03 03 12 13 15 20 24 24 24 26 32 35 37 40 40 45 47 50 55 60 62 64 65 66 67 73 74 76 S: 2 C: 70126435 S: OK C: 03 04 05 15 15 16 16 17 17 21 22 30 31 31 32 40 41 42 43 44 46 50 52 56 61 63 63 63 64 72 75 76 S: 0 C: 60153247 S: OK C: 03 03 04 04 05 05 12 13 17 20 20 21 26 31 35 36 43 45 46 50 52 52 52 57 60 66 70 71 72 75 76 77 S: 2 C: 75620143 S: OK C: 00 06 10 15 17 20 23 26 26 32 34 35 40 42 43 44 46 47 50 53 57 61 61 65 65 67 67 72 72 72 74 76 S: 0 C: 17563204 S: OK S: welcome Mr Smith! S: /usr/local/clerk/bin/smith>
---8<-----[sniffer started] S: hello, this is broken-tin.neverbank.co.uk S: localtime: 07:54:07 Nov/04/2006 (GMT) C: login user=smith role=clerk C: 02 03 06 10 10 12 12 15 15 21 24 27 27 27 31 33 41 42 43 44 46 47 50 52 53 60 64 67 71 71 73 76 S: 2 C: 27143056 S: OK C: 01 01 04 07 12 12 13 13 16 16 23 24 27 30 30 30 31 35 40 42 45 50 51 53 54 55 57 62 63 67 71 77 S: 1 C: 01365427 S: OK C: 01 01 01 02 05 12 12 14 16 20 20 23 23 27 27 30 36 37 41 45 47 50 51 52 54 55 56 62 66 70 74 76 S: 0 C: 45076312 S: OK C: 03 04 04 04 06 10 12 15 22 26 30 32 33 34 35 36 42 45 46 46 51 53 54 60 60 61 61 67 67 70 71 72 S: 0 C: 42135607 S: OK C: 00 05 10 14 15 15 20 21 22 24 25 27 30 34 37 41 42 43 53 53 56 56 57 57 60 63 67 71 71 71 72 75 S: 2 C: 46325701 S: OK S: welcome Mr Smith! S: /usr/local/clerk/bin/smith>
---8<-----[sniffer started] S: hello, this is broken-tin.neverbank.co.uk S: localtime: 07:53:02 Nov/05/2006 (GMT) C: login user=smith role=clerk C: 03 03 06 07 14 16 17 20 22 23 24 26 27 31 31 34 34 35 35 40 40 40 42 43 51 54 57 60 61 62 73 77 S: 1 C: 03416257 S: OK C: 00 02 03 04 06 07 13 16 17 23 24 24 26 33 34 41 41 45 45 47 47 51 53 57 60 61 62 70 72 72 72 74 S: 2 C: 32647051 S: OK C: 01 04 05 10 16 17 21 26 27 31 31 32 32 37 37 40 43 43 46 50 53 54 55 56 57 63 66 73 74 74 74 75 S: 0 C: 62705314 S: OK C: 02 06 07 11 14 20 21 23 34 36 37 37 37 42 42 43 43 45 45 51 52 53 60 61 63 64 66 67 70 71 74 74 S: 0 C: 61240735 S: OK C: 01 02 05 14 14 14 16 17 22 26 30 31 32 42 45 46 46 50 54 57 60 60 61 61 63 63 71 72 74 75 76 77 S: 0 C: 24175603 S: OK S: welcome Mr Smith! S: /usr/local/clerk/bin/smith>
---8<-----[sniffer started] S: hello, this is broken-tin.neverbank.co.uk S: localtime: 07:54:54 Nov/06/2006 (GMT) C: login user=smith role=clerk C: 04 05 06 11 13 14 15 16 17 20 25 26 34 36 37 37 40 41 43 51 53 53 53 57 66 67 70 70 72 72 75 75 S: 0 C: 23756410 S: OK C: 01 01 05 05 06 06 12 14 16 21 23 27 30 32 33 34 36 37 40 44 51 54 56 60 63 67 67 67 70 70 72 74 S: 0 C: 02631745 S: OK C: 00 01 02 04 05 07 12 14 15 15 20 21 26 34 36 37 44 45 53 53 56 56 57 57 62 64 67 70 71 71 71 75 S: 2 C: 36504721 S: OK C: 03 06 06 06 07 12 16 17 20 21 25 30 30 32 32 34 34 40 42 45 53 55 61 63 63 65 70 71 73 75 76 77 S: 1 C: 65312704 S: OK C: 00 01 12 12 14 14 17 17 20 25 27 30 31 33 35 36 37 40 42 47 52 53 56 60 61 61 65 71 73 76 76 76 S: 0 C: 10237654 S: OK S: welcome Mr Smith! S: /usr/local/clerk/bin/smith>
---8<-----[sniffer started] S: hello, this is broken-tin.neverbank.co.uk S: localtime: 07:51:51 Nov/07/2006 (GMT) C: login user=smith role=clerk C: 00 01 02 04 05 07 12 15 15 17 22 25 32 34 36 40 41 41 41 45 53 53 54 54 56 56 62 64 67 70 71 76 S: 1 C: 40726135 S: OK C: 03 03 03 04 07 11 17 20 21 25 31 35 37 37 40 41 43 44 45 47 52 53 54 60 61 62 70 70 72 72 76 76 S: 2 C: 14263507 S: OK C: 03 03 03 04 06 12 13 14 20 21 27 31 36 36 37 40 41 43 44 46 47 50 52 57 60 60 62 62 65 65 76 77 S: 2 C: 15263074 S: OK C: 00 03 04 05 06 07 13 14 16 21 23 24 30 35 37 37 37 44 45 51 51 52 52 53 53 60 61 67 74 75 75 76 S: 1 C: 43267150 S: OK C: 03 03 04 04 05 05 10 11 23 26 27 31 32 35 41 43 45 50 56 56 56 57 60 60 61 62 70 71 72 75 76 77 S: 0 C: 01627453 S: OK S: welcome Mr Smith! S: /usr/local/clerk/bin/smith>
---8<-----[sniffer started] S: hello, this is broken-tin.neverbank.co.uk S: localtime: 07:55:25 Nov/08/2006 (GMT) C: login user=smith role=clerk C: 01 04 04 05 11 14 21 23 27 31 35 37 42 42 43 43 47 47 50 53 56 60 61 64 65 66 67 70 70 70 74 76 S: 1 C: 07231546 S: OK C: 04 04 04 06 07 10 13 15 20 21 23 33 37 43 45 47 47 51 54 56 60 63 64 65 66 67 70 70 71 71 72 72 S: 0 C: 42715630 S: OK C: 01 03 07 07 07 10 11 12 13 15 17 22 23 30 30 34 34 36 36 40 42 46 51 56 57 60 62 65 72 73 73 75 S: 1 C: 64712530 S: OK C: 01 01 02 02 05 05 10 14 14 14 16 21 23 27 30 33 40 40 43 47 51 52 53 60 61 63 64 66 67 72 74 76 S: 0 C: 04215736 S: OK C: 01 02 03 10 15 17 22 26 35 35 35 36 37 40 42 43 51 52 56 56 60 60 63 63 64 64 71 72 73 75 76 77 S: 0 C: 26147503 S: OK S: welcome Mr Smith! S: /usr/local/clerk/bin/smith>
---8<-----[sniffer started] S: hello, this is broken-tin.neverbank.co.uk S: localtime: 07:53:27 Nov/09/2006 (GMT) C: login user=smith role=clerk C: 01 01 02 02 03 03 13 14 17 21 23 27 30 35 35 35 36 41 45 46 50 50 54 57 60 63 64 65 66 67 70 77 S: 0 C: 02746531 S: OK C: 01 02 07 13 13 13 15 16 21 24 27 34 35 35 37 42 43 46 50 50 51 51 52 52 61 63 64 65 66 67 75 77 S: 2 C: 01265734 S: OK C: 02 04 05 10 10 12 12 14 14 21 23 27 27 27 31 32 33 35 36 37 42 45 46 51 55 63 64 67 71 71 75 76 S: 1 C: 21643750 S: OK C: 03 04 06 12 14 15 21 22 23 25 26 27 33 37 41 43 46 51 53 57 57 62 65 65 65 67 70 70 74 74 76 76 S: 2 C: 05342617 S: OK C: 03 03 05 05 07 07 10 10 12 14 21 25 26 30 31 31 31 36 40 44 52 53 54 60 61 62 63 64 66 73 74 75 S: 0 C: 05641237 S: OK S: welcome Mr Smith! S: /usr/local/clerk/bin/smith>
---8<-----[sniffer started] S: hello, this is broken-tin.neverbank.co.uk S: localtime: 07:54:48 Nov/10/2006 (GMT) C: login user=smith role=clerk C: 03 03 05 05 06 06 10 10 12 17 20 22 30 31 31 31 34 40 41 42 43 44 47 52 53 57 62 63 65 71 74 75 S: 1 C: 10764325 S: OK C: 00 03 10 14 17 20 23 23 26 31 31 34 34 37 37 40 46 47 50 52 53 55 56 57 62 64 65 72 72 72 73 75 S: 2 C: 40672351 S: OK C: 02 06 07 12 14 17 17 17 20 21 22 24 25 27 31 35 36 41 41 43 43 46 46 54 55 60 61 65 70 74 74 75 S: 2 C: 51307426 S: OK C: 00 01 03 05 06 07 13 16 16 17 23 25 27 33 36 42 43 45 50 51 51 51 56 62 62 64 64 65 65 70 71 72 S: 0 C: 35217406 S: OK C: 00 02 10 13 14 21 21 23 23 24 24 30 34 36 42 45 45 45 47 50 52 52 56 63 65 67 70 72 74 75 76 77 S: 1 C: 72136054 S: OK S: welcome Mr Smith! S: /usr/local/clerk/bin/smith>
digg it!
阅读全文