<?xml version="1.0" encoding="gb2312"?>

<!DOCTYPE rss PUBLIC "-//Netscape Communications//DTD RSS 0.91//EN"
 "http://my.netscape.com/publish/formats/rss-0.91.dtd">

<rss version="0.91">

<channel>
<title>Team 509&amp;#039;s Home</title>
<link>http://--------.---</link>
<description>PHP-Nuke Powered Site</description>
<language>gb2312</language>

<item>
<title>POC of CVE-2010-0049</title>
<link>http://--------.---/modules.php?name=News&amp;file=article&amp;sid=81</link>
<description>POC of a safari vuln&lt;br /&gt;</description>
</item>

<item>
<title>坑灰未冷山东乱,loader原来不读书</title>
<link>http://--------.---/modules.php?name=News&amp;file=article&amp;sid=80</link>
<description>IDA和DumpBin等工具在检测Tls Callback函数时存在的一个问题，及解决方案</description>
</item>

<item>
<title>IDA Pro plugin wizard的一个bug及修正方法</title>
<link>http://--------.---/modules.php?name=News&amp;file=article&amp;sid=79</link>
<description>&lt;div&gt;IDA Pro plugin wizard is great tools for writing IDA's plugin.&lt;br /&gt;By using this tools, I find a little bug in it.&lt;/div&gt;&lt;div&gt;the bug is that when your IDA's install path include a space.&lt;br /&gt;&amp;nbsp;for example:C:\\Program Files\\IDA(IDA's default install path)&lt;br /&gt;IDA Pro plugin wizard will can't copy the .plw file to IDA's plugins folder.&lt;/div&gt;&lt;div&gt;the reason of this bug is the tools use the command:&lt;br /&gt;&amp;nbsp;copy /y XXXXX.plw C:\\Program Files\\IDA\\plugins&lt;br /&gt;to copy the .plw file to IDA's plugins folder,if the IDA path include a space,this command will fail.&lt;/div&gt;&lt;div&gt;I think I can fix this bug by changing a file.&lt;br /&gt;the file is &lt;a&gt;\\IDA_Plugin_Wizard_VS2005\\Put&lt;/a&gt; Contents into AppWiz\\IDA Pro Plugin\\Scripts\\1033\\default.js&lt;br /&gt;No. 246 line is :&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; idaBinDir = wizard.FindSymbol(&amp;quot;BINPATH&amp;quot;) + '\\\\plugins';&lt;br /&gt;I chang it to :&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; idaBinDir = '\\&amp;quot;' \+ wizard.FindSymbol(&amp;quot;BINPATH&amp;quot;) + '\\\\plugins\\&amp;quot;';&lt;br /&gt;then save the file,the bug has be fixed.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;看中文按下面的详细内容...&lt;/div&gt;</description>
</item>

<item>
<title>Reverse Engineering Code with IDA Pro第七章中文译稿</title>
<link>http://--------.---/modules.php?name=News&amp;file=article&amp;sid=78</link>
<description>声明&lt;br /&gt;本文属于看雪学院《Reverse Engineering Code with IDA Pro》图书翻译项目（&lt;a href=&quot;http://bbs.pediy.com/showthread.php?t=66430&quot;&gt;http://bbs.pediy.com/showthread.php?t=66430&lt;/a&gt;），本人负责翻译其中第七、八章。经与组织者商议，决定先行公开第七章译稿，作为本书的免费样章，以飨读者。在译稿中给出原文的原因是：在翻译过程中我们对原文进行了校对，发现了一些有问题的地方，在译稿中已经予以纠正。读者可以自行对照查阅。我们希望我们的中文译稿能比E文原版的质量更好一些&amp;#9786;&lt;br /&gt;版权所有，谢绝转载。&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;内容提要：&lt;br /&gt;从一个read()函数开始对协议进行分析&lt;br /&gt;分析出协议数据包的格式&lt;br /&gt;检查协议中是否隐藏有后门&lt;br /&gt;使用IDA找出用于处理某种类型数据包的所有函数 &lt;br /&gt;&lt;br /&gt;</description>
</item>

<item>
<title>Adobe Flash Player Code Execution Vulnerability(CVE-2007-0071)</title>
<link>http://--------.---/modules.php?name=News&amp;file=article&amp;sid=77</link>
<description>&lt;span class=&quot;content&quot;&gt;&lt;div class=&quot;pBodyCMT&quot;&gt;Adobe
Flash Player is vulnerable to a buffer overflow, caused by an integer
overflow vulnerability in the processing of multimedia files. By
creating a specially crafted multimedia file and persuading the victim
to open the file, a remote attacker could overflow a buffer and execute
arbitrary code on the system.&lt;/div&gt;

 &lt;a name=&quot;wp9000084&quot;&gt;&lt;/a&gt;
&lt;div class=&quot;pBodyCMT&quot;&gt;The integer overflow vulnerability is detailed in CVE-2007-0071&lt;a href=&quot;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5707/ps5057/product_bulletin_c25-484785.html#wp9000077&quot;&gt;&lt;sup&gt;1&lt;/sup&gt;&lt;/a&gt;.
An attacker may be able to trigger this overflow by convincing a user
to open a specially crafted SWF file. The SWF file could be hosted or
imbedded in a webpage.&lt;/div&gt;&lt;/span&gt;</description>
</item>

<item>
<title>Vulnerabilities in Microsoft Word Could Allow Remote Code Execution(MS08-026)</title>
<link>http://--------.---/modules.php?name=News&amp;file=article&amp;sid=76</link>
<description>all content from : http://secunia.com/gfx/pdf/SA30143_BA.pdf ,thanks secunia.&lt;br /&gt;&lt;br /&gt;A vulnerability in Microsoft Word when processing drawing objects in RTF files can be&lt;br /&gt;exploited by malicious people to compromise a user's system.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</description>
</item>

<item>
<title>Mozilla Foundation Security Advisory 2008-55</title>
<link>http://--------.---/modules.php?name=News&amp;file=article&amp;sid=75</link>
<description>&lt;span class=&quot;label&quot;&gt;Title:&lt;/span&gt;      Crash and remote code execution in nsFrameManager&lt;br /&gt;
&lt;span class=&quot;label&quot;&gt;Impact:&lt;/span&gt;     Critical&lt;br /&gt;
&lt;span class=&quot;label&quot;&gt;Announced:&lt;/span&gt;  November 12, 2008&lt;br /&gt;
&lt;span class=&quot;label&quot;&gt;Reporter:&lt;/span&gt;   ling and wushi of team509 (via TippingPoint)&lt;br /&gt;
&lt;span class=&quot;label&quot;&gt;Products:&lt;/span&gt;   Firefox, Thunderbird, SeaMonkey&lt;br /&gt;
&lt;br /&gt;
&lt;span class=&quot;label&quot;&gt;Fixed in:&lt;/span&gt;   Firefox 3.0.4&lt;br /&gt;
&lt;span class=&quot;label&quot;&gt;&amp;nbsp;&lt;/span&gt;      Firefox 2.0.0.18&lt;br /&gt;
&lt;span class=&quot;label&quot;&gt;&amp;nbsp;&lt;/span&gt;      Thunderbird 2.0.0.18&lt;br /&gt;
&lt;span class=&quot;label&quot;&gt;&amp;nbsp;&lt;/span&gt;      SeaMonkey 1.1.13</description>
</item>

<item>
<title>China quake</title>
<link>http://--------.---/modules.php?name=News&amp;file=article&amp;sid=74</link>
<description>&lt;br /&gt;
I think all of you know that a 7.8-magnitude earthquake hit China's
Sichuan province on Monday. Till now, it's already caused over 28,500
death (the final number might reach 50,000). More than 100,000 people
injured and at least 12,000 people still buried under collapsed
buildings, many of them are children. &lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;</description>
</item>

<item>
<title>漫谈TLS_CallBack：原理、编程、手工感染及检测</title>
<link>http://--------.---/modules.php?name=News&amp;file=article&amp;sid=73</link>
<description>利用TLS_CallBack（线程局部存储回调函数）玩弄调试器以及感染PE文件的方法已经不算是什么新技术了。但是出乎我意料的是：前些日子无聊，翻译了IDA作者Guilfanov博客上的《TLS callbacks》一文竟然拿到了6个5分，呵呵。要知道，我自认为比较有质量的《利用Lookaside表实现Exploit的2种方法》也只有拿到5个5分啊！这是怎么了？&lt;br /&gt;那篇《TLS callbacks》讲的不是很细，检测方法也值得商榷（当然这和文章的写作动机有关）。最主要是为了不要辜负这6个5分，另外也由于TLS_CallBack中文资料相对少，我再写篇详细的，很基础，大虾们就不用看了&amp;#9786;</description>
</item>

<item>
<title>名词解释：Front End Allocator</title>
<link>http://--------.---/modules.php?name=News&amp;file=article&amp;sid=72</link>
<description>&amp;quot;Front End Allocator&amp;quot;究竟是什么意思？&lt;br /&gt;以及一些题外话。</description>
</item>

</channel>
</rss>