¤W¶g°_°w¹ï¥xÆW¤Î¤¤°ê¤j³°¦a°Ï¤¤¤åºô¶ªº¤j³W¼Ò§ðÀ»¦æ¬°¦³¤Fªì¨B¤ÀªRµ²ªG¡Aªü½X¬ì§Þ¦b¤ÀªR§ðÀ»¦æ¬°«áªí¥Ü¡AÀb«ÈºÃ¦üµ²¦X¤F·í«e¬y¦æªºÀb«È¦Û°Ê§ðÀ»¤u¨ã»PGoogleªº·j´M¯à¤O¡A³z¹LGoogle·j´M¥Xºô¶¤¤¥i¥Î¨Óª`¤Jµ{¦¡½Xªº¡uª`¤JÂI¡v¡A¦A§Q¥Î¼¶¼g¦nªºÀb«È¤u¨ã¦b³o¨Ç¡uª`¤JÂI¡v¤¤¶ñ¤Jµ{¦¡»yªk¡A¥H¦Û°Ê¤Æ¤âªk¡A§Ö³t§ð¤U¤j¶qºô¶¡C
¡u³oÀ³¬O¥xÆW¦a°Ï¦³¥v¥H¨Ó³W¼Ò³Ì¤j¡B¶i¦æ³Ì§Ö³tªºSQL Injection§ðÀ»¡A¡vªü½X¬ì§Þ°õ¦æªø¶ÀÄ£¤åªí¥Ü¡C
®Ú¾ÚÁͶլì§Þ¦«e¤½§Gªº²Îp¡A¦Ü¤Ö¦³¤Q¸UÓ¤¤¤åºô¶¦b¤@¤Ñ¤§¤º²_³´¡A¨ä¤¤¤£¥Fª¾¦W·Oµ½¹ÎÅéºô¶¡A¦b¥|¤t¾_¨a««Ø¶Ò´Ú¤§»Ú¡A¥i¯àÅý¦n¤ß·Q®½´Úªº¥Á²³¤Ï¾D´Ó¤J´c·Nµ{¦¡¡C
©Ò¿×SQL Injection¡A¬O¤@ºØºô¶µ{¦¡½Xªº¼g§@º|¬}¡A¦¹º|¬}¥i¤¹³\¤@¯ë¨Ï¥ÎªÌ¦bºô¶¤W¥i¨Ñ¨Ï¥ÎªÌ¿é¤J¤º®eªºÄæ¦ì¡A¦p°Q½×°Ï¡B·j´M®Øµ¥·í¤¤¿é¤JSQL«ü¥O½X¡A¨Ã¤¹³\¨ä°õ¦æ¡A¾ÉP¤@¯ë¨Ï¥ÎªÌ§Y¥i«§ï¸ê®Æ®w¤¤ªº¸ê®Æ¡CÁͶլì§Þ¸ê²`§Þ³NÅU°Ý²³Ó°]«K´¿ªí¥Ü¡A¥¼¨ü¹L¨}¦n¦w¥þ°V½mªººô¶À³¥Îµ{¦¡¶}µo¤Hû¡A§Y¥i¯à¯d¤U¸Óº|¬}¡C¨Æ¹ê¤W¡ASQL Injectionº|¬}¤§ÄY«¡A¬Æ¦Ü¦b¥h¦~³Q¶}©ñWeb³nÅé¦w¥þpµe(Open Web Application Security Project, OWASP)¿ï©w¬°2007¤Q¤jWeb¦w¥þº|¬}ªº²Ä¤G¦ì¡C
ȱoª`·Nªº¬O¡A¦¹ªi§ðÀ»¤¤±Ä¥Îªº¦h¥b¬O¤w¦s¦bªºÂ¤âªk¡A¦ý±M®aªí¥Ü¡A¥æ¬Û¾ã¦Xªº¹B¥Î«oÄݤ֨£¡C
¶ÀÄ£¤åªí¥Ü¡A³z¹LGoogle¨Ó·j´Mºô¯¸®zÂIªºGoogle Hacking¥H¤Î±M·~Àb«È¤u¨ãµ¥³£¤w¦s¦b¦h®É¡A¤]¬OÀb«È¸g±`§Q¥Îªº¤âªk¡A¦ý¥Ñ©ó¹L©¹¦h¥b¬O³z¹LÀb«È¤â°Ê·j´M«á¤~µo°Ê§ðÀ»¡AÁöµM¦³®Ä¡A¡u¦ý³W¼Ò»PÂX´²³t«×¤£¦Ü©ó³o»ò§Ö¡A¡v¥L»¡¡C
¥Lªí¥Ü¡A¸g¹L»PÀb«È¡u°«ªk¡v»P¤Ï¦V°lÂÜ´ú¸Õ¡Aµo²{Àb«È§Q¥Î¦ì¦b»´äªº¤¤±±¥D¾÷¡A¾Þ±±20¦h¥x¦ì©ó¤¤°ê¤j³°ªº¹q¸£¥D¾÷¡A¥H´²¼u¦¡§ðÀ»ªk¹ï«D¯S©wºô¶µo°Ê§ðÀ»¡AÁöµM¨Ã«D©Ò¦³³Q´Ó¤J»yªkªººô¶³£·|°õ¦æ´c·N¦æ¬°¡A¦ý¦³¤j¶qºô¶«o³QÃÒ¹ê¾D´Ó¤J´c·N³sµ²¡C
¥H¸Ó¤½¥qµo²{¡B¦b¦¹ªi§ðÀ»¤¤³Q¤j¶q´Ó¤Jªº¨ä¤¤¤@Ó´c·Nºô§}¬°¨Ò¡A´N¥i³z¹LGoogle¦b¥]¬A°¨°ºÂå°|¡B¥x¥_¥«¬F©²µ¥ºô¯¸¤¤³Q§ä¨ì¡A¤£¹L¶ÀÄ£¤åªí¥Ü¡A¤w¦³³¡¤À´c·N³sµ²¥¢®Ä¡A©Î¬O³Qºô¯¸ºÞ²zû²¾°£¡A¦ý¤´¦³¤j¶qºô¶¤´±a¦³´c·N³sµ²¡C
¦b³Qµo²{ªº¤@¤d¦hÓ´c·N³sµ²¤¤¡A¦³¶W¹L¤@¥b¨ÃµL¹ê½è´c·N¦æ¬°¡A¤]¦]¦¹¤@¯ë¥Î¤á¦bÂsÄý³o¨Ç¾DÀbºô¶®É¡A¨¾¬r³nÅé®Ú¥»¤£·|µo¥Xĵ°T¡C
¦ý¶ÀÄ£¤åĵ§i¡A¦¹¬°Àb«È¥h°£¨Ï¥ÎªÌ»Pºô¯¸¸gÀçªÌ§Ù¤ßªº¤âªk¡A¡uÀb«È«Ü¥i¯à¬O¦b¶i¦æ¤j³W¼Òºô¯¸§G§½¡Aµ¥«Ý¤U¤@ÓÂsÄý¾¹¹s®É®t§ðÀ»(Zero Day Attack) ¥X²{«á¡A§Y¥i¤j¶q¦¬³Î¡A¥´³y³W¼Ò§ó¤jªºíL«Íºô¸ô(botnet)¡A¡v¥L»¡¡C
¨¾½d¤§¹D«h¬O¦Ñ¥Í±`½Í¡C²³Ó°]´£¿ô¤@¯ë¨Ï¥ÎªÌ¡A³Ì¦n±Ä¥Î¦³¦w¥þ³sµ²¹LÂoªA°Èªº¸ê¦w³nÅé¡AÁ×±¼¦MÀIªººô¶³sµ²¡A¶ÀÄ£¤å«h«ØÄ³¦³¸gÀçºô¯¸ªº²Õ´¡A¥²¶·©w´Á¹ïºô¯¸¦w¥þ©Ê¶i¦æÀË´ú¡A¥H§K¦¨¬°Àb«È´²§G´c·Nµ{¦¡ªº¸õªO¡C

8.vocalhigh ©ó 2008/06/13 13:24 ¦^À³
實用好文7.vocalhigh ©ó 2008/06/13 13:24 ¦^À³
實用好文6.asd7777 ©ó 2008/05/30 09:30 ¦^À³
´X¦~«e¦³Ó°ª¤¤¥Í³Q§ì¡AÁÙ¦bĵ§½¬£¥X©Òªíºt¤F1¤ÀÄÁ¤º¯}¸Ñ¤j¾Ç¾Ç´úªº¬d¸ß¡C¨ä¹ê¥u¬O¥ÎSQL Injection(±b¸¹±K½X³£¿é¤J'01' or '1'='1)¡A¸Ñ¨M¿ìªk¬O«eºÝ¼gµ{¦¡Àˬdor¸ê®Æ®w¼g¹w¦sµ{§ÇÀˬd¡C5.°Î¦W ©ó 2008/05/28 05:04 ¦^À³
¯dµ¹¦M³n?¨º±N¤S¬O§ó«¤jºw.......¯E§T!
4.Jamesz ©ó 2008/05/26 07:42 ¦^À³
¤¤±±¥D¾÷¤]³\«üªº¬O³Q«I¤Jªº server¡C¥H³o¨Ç server ¹ï¨ä¤U´x´¤ªº zombie¡]»ø«Í¹q¸£¡A³q±`³£¬O¤¤¤F¤ì°¨ªº Windows client¡^¤U©R¥O¥h¶i¦æ DDos ©Î¨ä¥LºØÃþ§ðÀ»¡C«e¤@°}¤l¥xÆWª¾¦W¹CÀ¸ªÀ¸sºô¯¸´N³Q¤¤°ê¤j³°ªº cracker ¶°¹Î³o¼Ë¾ã¹L¡C³oÃþªº§ðÀ»¥Ø«e¤]¨S¦³§¹¬üªº¸Ñ¨M¤è®×¡A°£«D¯à¦³®Ä´î¤Ö Windows client ¤¤¤ì°¨ªº¾÷²v¡K¯dµ¹·L³n¸Ñ¨M§a¡C3.°Î¦W ©ó 2008/05/24 08:59 ¦^À³
¡u¤¤±±¥D¾÷¡v§¹¥þ¬Ý¤£©ú, controller?
2.ooXx ©ó 2008/05/24 06:31 ¦^À³
¥unºô¯¸³]pªÌª`·N SQL Injection °ÝÃD´N¥i¥H®Ú¥»ªº¸Ñ¨M¤F(²{¦b¨Ó»¡¡A³oÀ³¸Óºâ¬O³]p¤£¨}§a)
¤@¯ë¨Ï¥ÎªÌÀ³¸ÓµL±q¥h¸Ñ¨M³o°ÝÃD§a............
1.°Î¦W ©ó 2008/05/24 01:02 ¦^À³
¨S»¡©ú¸Ó¦p¦ó¸Ñ¨M¼Ú~>"