µù¥U | µn¤J | RSS Feeds
ZDNet | Taiwan.CNET.com |

¼s§i¡G
¤j³W¼Ò§ðÀ»¨Æ¥ó¥D¦]¡GÀb«È¤u¨ãµ²¦XGoogle Hacking
¤Íµ½¦C¦L | Âà±HªB¤Í | ¥[¤JHEMiDEMiºô¸ô®ÑÅÒ | ¥[¤JfunP | ¥[¤JGoogle®ÑÅÒ | ¥[¤JYahoo!©_¼¯¤À¨É®ÑÅÒ | 8«h¦^À³
    
ZDNet°OªÌ°¨°öªv¡þ¥x¥_³ø¾É 2008/05/23 20:13:02 ¥»¶g¥H¨Óµo¥Í¦b¨È¬w¦a°Ï¡B¥H¤¤¤åºô­¶¬°¥D­n¥Ø¼Ðªº¤j«¬¸ê®ÆÁô½X(SQL Injection)§ðÀ»¨Æ¥ó¡AºÃ¬°Àb«È³z¹L±M·~¤u¨ãµ²¦XGoogle·j´M¤ÞÀº§Ö³t´M§äºô­¶®zÂI©Ò­P¡C

¤W¶g°_°w¹ï¥xÆW¤Î¤¤°ê¤j³°¦a°Ï¤¤¤åºô­¶ªº¤j³W¼Ò§ðÀ»¦æ¬°¦³¤Fªì¨B¤ÀªRµ²ªG¡Aªü½X¬ì§Þ¦b¤ÀªR§ðÀ»¦æ¬°«áªí¥Ü¡AÀb«ÈºÃ¦üµ²¦X¤F·í«e¬y¦æªºÀb«È¦Û°Ê§ðÀ»¤u¨ã»PGoogleªº·j´M¯à¤O¡A³z¹LGoogle·j´M¥Xºô­¶¤¤¥i¥Î¨Óª`¤Jµ{¦¡½Xªº¡uª`¤JÂI¡v¡A¦A§Q¥Î¼¶¼g¦nªºÀb«È¤u¨ã¦b³o¨Ç¡uª`¤JÂI¡v¤¤¶ñ¤Jµ{¦¡»yªk¡A¥H¦Û°Ê¤Æ¤âªk¡A§Ö³t§ð¤U¤j¶qºô­¶¡C

¡u³oÀ³¬O¥xÆW¦a°Ï¦³¥v¥H¨Ó³W¼Ò³Ì¤j¡B¶i¦æ³Ì§Ö³tªºSQL Injection§ðÀ»¡A¡vªü½X¬ì§Þ°õ¦æªø¶ÀÄ£¤åªí¥Ü¡C

®Ú¾ÚÁͶլì§Þ¦­«e¤½§Gªº²Î­p¡A¦Ü¤Ö¦³¤Q¸U­Ó¤¤¤åºô­¶¦b¤@¤Ñ¤§¤º²_³´¡A¨ä¤¤¤£¥Fª¾¦W·Oµ½¹ÎÅéºô­¶¡A¦b¥|¤t¾_¨a­««Ø¶Ò´Ú¤§»Ú¡A¥i¯àÅý¦n¤ß·Q®½´Úªº¥Á²³¤Ï¾D´Ó¤J´c·Nµ{¦¡¡C

©Ò¿×SQL Injection¡A¬O¤@ºØºô­¶µ{¦¡½Xªº¼g§@º|¬}¡A¦¹º|¬}¥i¤¹³\¤@¯ë¨Ï¥ÎªÌ¦bºô­¶¤W¥i¨Ñ¨Ï¥ÎªÌ¿é¤J¤º®eªºÄæ¦ì¡A¦p°Q½×°Ï¡B·j´M®Øµ¥·í¤¤¿é¤JSQL«ü¥O½X¡A¨Ã¤¹³\¨ä°õ¦æ¡A¾É­P¤@¯ë¨Ï¥ÎªÌ§Y¥i«§ï¸ê®Æ®w¤¤ªº¸ê®Æ¡CÁͶլì§Þ¸ê²`§Þ³NÅU°Ý²³Ó°]«K´¿ªí¥Ü¡A¥¼¨ü¹L¨}¦n¦w¥þ°V½mªººô­¶À³¥Îµ{¦¡¶}µo¤H­û¡A§Y¥i¯à¯d¤U¸Óº|¬}¡C¨Æ¹ê¤W¡ASQL Injectionº|¬}¤§ÄY­«¡A¬Æ¦Ü¦b¥h¦~³Q¶}©ñWeb³nÅé¦w¥þ­pµe(Open Web Application Security Project, OWASP)¿ï©w¬°2007¤Q¤jWeb¦w¥þº|¬}ªº²Ä¤G¦ì¡C

­È±oª`·Nªº¬O¡A¦¹ªi§ðÀ»¤¤±Ä¥Îªº¦h¥b¬O¤w¦s¦bªºÂ¤âªk¡A¦ý±M®aªí¥Ü¡A¥æ¬Û¾ã¦Xªº¹B¥Î«oÄݤ֨£¡C

¶ÀÄ£¤åªí¥Ü¡A³z¹LGoogle¨Ó·j´Mºô¯¸®zÂIªºGoogle Hacking¥H¤Î±M·~Àb«È¤u¨ãµ¥³£¤w¦s¦b¦h®É¡A¤]¬OÀb«È¸g±`§Q¥Îªº¤âªk¡A¦ý¥Ñ©ó¹L©¹¦h¥b¬O³z¹LÀb«È¤â°Ê·j´M«á¤~µo°Ê§ðÀ»¡AÁöµM¦³®Ä¡A¡u¦ý³W¼Ò»PÂX´²³t«×¤£¦Ü©ó³o»ò§Ö¡A¡v¥L»¡¡C

¥Lªí¥Ü¡A¸g¹L»PÀb«È¡u°«ªk¡v»P¤Ï¦V°lÂÜ´ú¸Õ¡Aµo²{Àb«È§Q¥Î¦ì¦b­»´äªº¤¤±±¥D¾÷¡A¾Þ±±20¦h¥x¦ì©ó¤¤°ê¤j³°ªº¹q¸£¥D¾÷¡A¥H´²¼u¦¡§ðÀ»ªk¹ï«D¯S©wºô­¶µo°Ê§ðÀ»¡AÁöµM¨Ã«D©Ò¦³³Q´Ó¤J»yªkªººô­¶³£·|°õ¦æ´c·N¦æ¬°¡A¦ý¦³¤j¶qºô­¶«o³QÃÒ¹ê¾D´Ó¤J´c·N³sµ²¡C

¥H¸Ó¤½¥qµo²{¡B¦b¦¹ªi§ðÀ»¤¤³Q¤j¶q´Ó¤Jªº¨ä¤¤¤@­Ó´c·Nºô§}¬°¨Ò¡A´N¥i³z¹LGoogle¦b¥]¬A°¨°ºÂå°|¡B¥x¥_¥«¬F©²µ¥ºô¯¸¤¤³Q§ä¨ì¡A¤£¹L¶ÀÄ£¤åªí¥Ü¡A¤w¦³³¡¤À´c·N³sµ²¥¢®Ä¡A©Î¬O³Qºô¯¸ºÞ²z­û²¾°£¡A¦ý¤´¦³¤j¶qºô­¶¤´±a¦³´c·N³sµ²¡C

¦b³Qµo²{ªº¤@¤d¦h­Ó´c·N³sµ²¤¤¡A¦³¶W¹L¤@¥b¨ÃµL¹ê½è´c·N¦æ¬°¡A¤]¦]¦¹¤@¯ë¥Î¤á¦bÂsÄý³o¨Ç¾DÀbºô­¶®É¡A¨¾¬r³nÅé®Ú¥»¤£·|µo¥Xĵ°T¡C

¦ý¶ÀÄ£¤åĵ§i¡A¦¹¬°Àb«È¥h°£¨Ï¥ÎªÌ»Pºô¯¸¸gÀçªÌ§Ù¤ßªº¤âªk¡A¡uÀb«È«Ü¥i¯à¬O¦b¶i¦æ¤j³W¼Òºô¯¸§G§½¡Aµ¥«Ý¤U¤@­ÓÂsÄý¾¹¹s®É®t§ðÀ»(Zero Day Attack) ¥X²{«á¡A§Y¥i¤j¶q¦¬³Î¡A¥´³y³W¼Ò§ó¤jªºíL«Íºô¸ô(botnet)¡A¡v¥L»¡¡C

¨¾½d¤§¹D«h¬O¦Ñ¥Í±`½Í¡C²³Ó°]´£¿ô¤@¯ë¨Ï¥ÎªÌ¡A³Ì¦n±Ä¥Î¦³¦w¥þ³sµ²¹LÂoªA°Èªº¸ê¦w³nÅé¡AÁ×±¼¦MÀIªººô­¶³sµ²¡A¶ÀÄ£¤å«h«ØÄ³¦³¸gÀçºô¯¸ªº²Õ´¡A¥²¶·©w´Á¹ïºô¯¸¦w¥þ©Ê¶i¦æÀË´ú¡A¥H§K¦¨¬°Àb«È´²§G´c·Nµ{¦¡ªº¸õªO¡C

¥[¤J§Úªº¹Ï®ÑÀ] ­q¾\ÃöÁä¦r
¥[¤Jºô¸ô®ÑÅÒ> ¥[¤JHEMiDEMiºô¸ô®ÑÅÒ | ¥[¤JfunP | ¥[¤JGoogle®ÑÅÒ | ¥[¤JYahoo!©_¼¯¤À¨É®ÑÅÒ |
¤Íµ½¦C¦L | Âà±HªB¤Í



  • 8.vocalhigh ©ó 2008/06/13 13:24 ¦^À³
    實用好文
  • 7.vocalhigh ©ó 2008/06/13 13:24 ¦^À³
    實用好文
  • 6.asd7777 ©ó 2008/05/30 09:30 ¦^À³
    ´X¦~«e¦³­Ó°ª¤¤¥Í³Q§ì¡AÁÙ¦bĵ§½¬£¥X©Òªíºt¤F1¤ÀÄÁ¤º¯}¸Ñ¤j¾Ç¾Ç´úªº¬d¸ß¡C¨ä¹ê¥u¬O¥ÎSQL Injection(±b¸¹±K½X³£¿é¤J'01' or '1'='1)¡A¸Ñ¨M¿ìªk¬O«eºÝ¼gµ{¦¡Àˬdor¸ê®Æ®w¼g¹w¦sµ{§ÇÀˬd¡C
  • 5.°Î¦W ©ó 2008/05/28 05:04 ¦^À³
    ¯dµ¹¦M³n?
    ¨º±N¤S¬O§ó­«¤jºw.......¯E§T!
  • 4.Jamesz ©ó 2008/05/26 07:42 ¦^À³
    ¤¤±±¥D¾÷¤]³\«üªº¬O³Q«I¤Jªº server¡C¥H³o¨Ç server ¹ï¨ä¤U´x´¤ªº zombie¡]»ø«Í¹q¸£¡A³q±`³£¬O¤¤¤F¤ì°¨ªº Windows client¡^¤U©R¥O¥h¶i¦æ DDos ©Î¨ä¥LºØÃþ§ðÀ»¡C«e¤@°}¤l¥xÆWª¾¦W¹CÀ¸ªÀ¸sºô¯¸´N³Q¤¤°ê¤j³°ªº cracker ¶°¹Î³o¼Ë¾ã¹L¡C³oÃþªº§ðÀ»¥Ø«e¤]¨S¦³§¹¬üªº¸Ñ¨M¤è®×¡A°£«D¯à¦³®Ä´î¤Ö Windows client ¤¤¤ì°¨ªº¾÷²v¡K¯dµ¹·L³n¸Ñ¨M§a¡C
  • 3.°Î¦W ©ó 2008/05/24 08:59 ¦^À³
    ¡u¤¤±±¥D¾÷¡v
    §¹¥þ¬Ý¤£©ú, controller?
  • 2.ooXx ©ó 2008/05/24 06:31 ¦^À³
    ¥u­nºô¯¸³]­pªÌª`·N SQL Injection °ÝÃD´N¥i¥H®Ú¥»ªº¸Ñ¨M¤F
    (²{¦b¨Ó»¡¡A³oÀ³¸Óºâ¬O³]­p¤£¨}§a)

    ¤@¯ë¨Ï¥ÎªÌÀ³¸ÓµL±q¥h¸Ñ¨M³o°ÝÃD§a............
  • 1.°Î¦W ©ó 2008/05/24 01:02 ¦^À³
    ¨S»¡©ú¸Ó¦p¦ó¸Ñ¨M¼Ú~>"


¯d¤U§Aªº·N¨£
·|­û * ±b¸¹¡G
* ±K½X¡G
  1. Äæ¦ì¥i¿ï¶ñ¡A­Y¥þ¤£¶ñ¡A«hÅã¥Ü¬°¡u°Î¦W¡v¡C
  2. ¤£¤ä´©html»yªk
«D·|­û ©m¦W¡G
E-Mail¡G
Blog¡G
  ­«·s¸ü¤JÅçÃÒ½X
* ÅçÃÒ½X¡G °O¦í§Ú




HP©MIntel»â¾É·~¬É¡A´£¨Ñ¨ôµÛªº®Ä¯à¤Î¥i¥Î«×
  + ®Ä¯à¨ô¶Vªº¤M¾W 
  + «ö¨Æ·~ªºÀu¥ý¥Ø¼Ð¡A§Ö³t´£¨Ñ¾A¤Áªº¸ê·½ 
  + ­°§C¯à·½©M§N«o¦¨¥» 
Sponsored

ZD©ñ¤jÃè

¼s§i
¼s§i