RDG Tejon Crypter 2013

By hack520 on

一款老外的加密殼,可以bypass 大部份殺軟。

+Very Stable

+Very Powerful

+Obfuscator PE
+Bypass Kaspersky Internet Security 
2013 (Included) (Proactive Defense)
+Bypass OutPost Firewall
+Bypass Zemana Keylogger (HIPS)
+Bypass Comodo Internet Security (HIPS)
+Bypass AntiHook (HIPS)
+Bypass SpyShelter (HIPS)
+Bypass Avast Antivirus (Proactive)
+Bypass Norton Internet Security (Proactive)
+Bypass Avast Antivirus
 (Sandbox)
+Bypass Eset Nod32
+Bypass GData Internet Security
+Bypass TrustPort Antivirus
+Bypass Panda Internet Security
+Bypass Dr Web Antivirus
+Bypass Avira Internet Security
+Bypass Avg Internet Security
  (Identity Proactive Defense)
+Bypass AV360
+Bypass BitDefender 
& 2013
+Anti AV Database Update
+Remove AV From Disk

[转]Mysql身份认证漏洞及利用(CVE-2012-2122)

By hack520 on

当连接MariaDB/MySQL时,输入的密码会与期望的正确密码比较,由于不正确的处理,会导致即便是memcmp()返回一个非零值,也会使MySQL认为两个密码是相同的。

也就是说只要知道用户名,不断尝试就能够直接登入SQL数据库。按照公告说法大约256次就能够蒙对一次。而且漏洞利用工具已经出现。



受影响的产品:

All MariaDB and MySQL versions up to 5.1.61, 5.2.11, 5.3.5, 5.5.22 are

vulnerable.

MariaDB versions from 5.1.62, 5.2.12, 5.3.6, 5.5.23 are not.

MySQL versions from 5.1.63, 5.5.24, 5.6.6 are not.



网上已经出了metasploit版本的相应利用工具,下载地址