<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>葡萄树 On The Road --- 我只是一个会操作计算机的民工 &#187; 工具</title>
	<atom:link href="http://www.am82.com/houzan/archives/tag/%e5%b7%a5%e5%85%b7/feed" rel="self" type="application/rss+xml" />
	<link>http://www.am82.com/houzan</link>
	<description>我的时光，停在了你的角落...~</description>
	<lastBuildDate>Sun, 01 Aug 2010 05:52:52 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>linux查找后门程序</title>
		<link>http://www.am82.com/houzan/archives/4472</link>
		<comments>http://www.am82.com/houzan/archives/4472#comments</comments>
		<pubDate>Thu, 22 Jul 2010 14:45:32 +0000</pubDate>
		<dc:creator>假装纯情</dc:creator>
				<category><![CDATA[技术专题]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[后门]]></category>
		<category><![CDATA[工具]]></category>

		<guid isPermaLink="false">http://www.am82.com/houzan/?p=4472</guid>
		<description><![CDATA[每个进程都会有一个PID，而每一个PID都会在/proc目录下有一个相应的目录，这是Linux（当前内核2.6）系统的实现。

一般后门程序，在ps等进程查看工具里找不到，因为这些常用工具甚至系统库在系统被入侵之后基本上已经被动过手脚（网上流传着大量的rootkit。假如是内核级的木马，那么该方法就无效了）。

因为修改系统内核相对复杂（假如内核被修改过，或者是内核级的木马，就更难发现了），所以在/proc下，基本上还都可以找到木马的痕迹。

思路：
在/proc中存在的进程ID，在.......]]></description>
		<wfw:commentRss>http://www.am82.com/houzan/archives/4472/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nginx服务器下阻止SSH暴力破解，DenyHosts安装及配置说明</title>
		<link>http://www.am82.com/houzan/archives/4426</link>
		<comments>http://www.am82.com/houzan/archives/4426#comments</comments>
		<pubDate>Sun, 18 Jul 2010 04:19:02 +0000</pubDate>
		<dc:creator>假装纯情</dc:creator>
				<category><![CDATA[技术专题]]></category>
		<category><![CDATA[DenyHosts]]></category>
		<category><![CDATA[ssh]]></category>
		<category><![CDATA[工具]]></category>

		<guid isPermaLink="false">http://www.am82.com/houzan/?p=4426</guid>
		<description><![CDATA[DenyHosts是Python语言写的一个程序，它会分析sshd的日志文件，当发现重复的攻击时就会记录IP到/etc/hosts.deny文件，从而达到自动屏IP的功能。

如果你在SSH下看到好多SSH进程，说明有人破解SSH，那么可以用这个阻止
1、下载和安装.......]]></description>
		<wfw:commentRss>http://www.am82.com/houzan/archives/4426/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Unix/Linux 下的小工具：lsof</title>
		<link>http://www.am82.com/houzan/archives/4423</link>
		<comments>http://www.am82.com/houzan/archives/4423#comments</comments>
		<pubDate>Sat, 17 Jul 2010 06:09:53 +0000</pubDate>
		<dc:creator>假装纯情</dc:creator>
				<category><![CDATA[技术专题]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[lsof]]></category>
		<category><![CDATA[Unix]]></category>
		<category><![CDATA[工具]]></category>

		<guid isPermaLink="false">http://www.am82.com/houzan/?p=4423</guid>
		<description><![CDATA[lsof 本来是一个很普通的小工具，用来显示被进程打开的文件信息，因为在 Unix/Linux 下任何东西都是文件，所以 lsof 这个 “小” 工具就显得非常强大，常被称作 “Unix debugging 的瑞士军刀”。lsof 很好的遵循了 Unix 的哲学 “只做一件事，并把事情做好”。来看看 Unix/Linux 下被看作文件的有哪些：普通文件，目录，NFS 文件，特殊块文件，字符文件，管道，连接，各种 socket，共享文件库等，所有都是文件，所以 lsof 用途非常广泛。

列出所有......]]></description>
		<wfw:commentRss>http://www.am82.com/houzan/archives/4423/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Synshell &#8211; 同步CMDSHELL</title>
		<link>http://www.am82.com/houzan/archives/3957</link>
		<comments>http://www.am82.com/houzan/archives/3957#comments</comments>
		<pubDate>Fri, 26 Mar 2010 13:18:13 +0000</pubDate>
		<dc:creator>假装纯情</dc:creator>
				<category><![CDATA[技术专题]]></category>
		<category><![CDATA[CMDSHELL]]></category>
		<category><![CDATA[Synshell]]></category>
		<category><![CDATA[工具]]></category>

		<guid isPermaLink="false">http://www.am82.com/houzan/?p=3957</guid>
		<description><![CDATA[信息来源：邪恶八进制

08年初，放出类似这个程序的逆向代码，博客里有原理代码(<a href="http://hi.baidu.com/lovemfc/blog/item/7e9e6b8beb06d7789f2fb41d.html" target="_blank">http://hi.baidu.com/lovemfc/blog/item/7e9e6b8beb06d7789f2fb41d.html</a>)之后一直想做个成品出来，没想到一拖就2年。

真正同步的CMD SHELL，比如ftp , telnet 都可以正常使用.
目前只支持反向连接，只传......]]></description>
		<wfw:commentRss>http://www.am82.com/houzan/archives/3957/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google发布开源Web安全扫描器【下载】</title>
		<link>http://www.am82.com/houzan/archives/3947</link>
		<comments>http://www.am82.com/houzan/archives/3947#comments</comments>
		<pubDate>Wed, 24 Mar 2010 04:01:19 +0000</pubDate>
		<dc:creator>假装纯情</dc:creator>
				<category><![CDATA[技术专题]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[下载]]></category>
		<category><![CDATA[工具]]></category>

		<guid isPermaLink="false">http://www.am82.com/houzan/?p=3947</guid>
		<description><![CDATA[谷歌发布了开源Web安全扫描器，帮助Web开发者测试他们的应用是否安全。这款软件叫做Skipfish，它的功能类似Nmap或Nessus，不过谷歌声称有这些工具有所区别，并且在速度上比他们更快。使用Skipfish，可以帮助开发者快速检查的的跨站攻击，SQL和XML注入攻击，然后会系统会成产报道。

Skipfish是纯C语言开发，可以很容易处理每秒2000个HTTP请求，在跨本地网络测试中，在占有CPU和内存都很少的情况下，每秒能处理超过7000个请求。但........]]></description>
		<wfw:commentRss>http://www.am82.com/houzan/archives/3947/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>关于最近那个网马0day（CVE-2010-0806）用Metasploit生成方法</title>
		<link>http://www.am82.com/houzan/archives/3910</link>
		<comments>http://www.am82.com/houzan/archives/3910#comments</comments>
		<pubDate>Thu, 11 Mar 2010 14:51:52 +0000</pubDate>
		<dc:creator>假装纯情</dc:creator>
				<category><![CDATA[技术专题]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[工具]]></category>
		<category><![CDATA[网马]]></category>

		<guid isPermaLink="false">http://www.am82.com/houzan/?p=3910</guid>
		<description><![CDATA[一、下载http://www.rec-sec.com/exploits/msf/ie_iepeers_pointer.rb

二、放到C:\Metasploit\Framework3\msf3\modules\exploits\test。我改个了名字叫ie.rb

三、启动msfconsole

四、msf >........]]></description>
		<wfw:commentRss>http://www.am82.com/houzan/archives/3910/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Acunetix Web Vulnerability Scanner 6.5 Build 2010_02_10 Enterprise Version</title>
		<link>http://www.am82.com/houzan/archives/3823</link>
		<comments>http://www.am82.com/houzan/archives/3823#comments</comments>
		<pubDate>Sat, 27 Feb 2010 05:03:43 +0000</pubDate>
		<dc:creator>假装纯情</dc:creator>
				<category><![CDATA[挨踢消息]]></category>
		<category><![CDATA[AWVS]]></category>
		<category><![CDATA[SQL注入]]></category>
		<category><![CDATA[工具]]></category>
		<category><![CDATA[注入]]></category>

		<guid isPermaLink="false">http://www.am82.com/houzan/?p=3823</guid>
		<description><![CDATA[Acunetix Web Vulnerability Scanner 6.5 Build 2010_02_10 Enterprise Version:

Download Here

2010_02_10_01_webvulnscan65.exe

size: 15445824 byte

MD5: 4BB84128A895CD5959C1369E1BD8AE55

SHA1: 040AFAC2EE406AB6FBCF8AFBA078C34074EED933


CRC32: 0CAFEA4F

Crack Patch:

Download Here]]></description>
		<wfw:commentRss>http://www.am82.com/houzan/archives/3823/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nmap 5.20发布</title>
		<link>http://www.am82.com/houzan/archives/3672</link>
		<comments>http://www.am82.com/houzan/archives/3672#comments</comments>
		<pubDate>Mon, 25 Jan 2010 12:28:29 +0000</pubDate>
		<dc:creator>假装纯情</dc:creator>
				<category><![CDATA[技术专题]]></category>
		<category><![CDATA[nmap]]></category>
		<category><![CDATA[工具]]></category>

		<guid isPermaLink="false">http://www.am82.com/houzan/?p=3672</guid>
		<description><![CDATA[Nmap是一个网络连接端扫描软件，用来扫描网上电脑开放的网络连接端，并能推断出对方运行的操作系统。现在Nmap正式发布了5.20版，包含了GUI前端Zenmap的一个更新版。Nmap 5.20现在能识别出Snow Leopard，Android Linux智能手机，以及Chumby、HW group、Icom、Lyngsoe和NEC等生产的打印机、宽带路由器和其它设备，共收集了1349个指纹。Nmap 5.20还新增了31个Nmap Scripting Engine脚本，预写好.......]]></description>
		<wfw:commentRss>http://www.am82.com/houzan/archives/3672/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>安装BT4 FINAL到移动硬盘上</title>
		<link>http://www.am82.com/houzan/archives/3610</link>
		<comments>http://www.am82.com/houzan/archives/3610#comments</comments>
		<pubDate>Thu, 14 Jan 2010 06:20:58 +0000</pubDate>
		<dc:creator>假装纯情</dc:creator>
				<category><![CDATA[技术专题]]></category>
		<category><![CDATA[BT4]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[工具]]></category>

		<guid isPermaLink="false">http://www.am82.com/houzan/archives/3610</guid>
		<description><![CDATA[今天有人发过来BT4网站下载链接，看到出了BT4最终版了，立即下载回来研究下。我按官方说明的用unetbootin安装bt4-final.iso失败了，因为unetbootin没能识别到我的移动硬盘........]]></description>
		<wfw:commentRss>http://www.am82.com/houzan/archives/3610/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>计算机反COFEE取证工具-DECAF</title>
		<link>http://www.am82.com/houzan/archives/3460</link>
		<comments>http://www.am82.com/houzan/archives/3460#comments</comments>
		<pubDate>Sun, 27 Dec 2009 01:40:34 +0000</pubDate>
		<dc:creator>假装纯情</dc:creator>
				<category><![CDATA[技术专题]]></category>
		<category><![CDATA[COFEE]]></category>
		<category><![CDATA[DECAF]]></category>
		<category><![CDATA[工具]]></category>

		<guid isPermaLink="false">http://www.am82.com/houzan/?p=3460</guid>
		<description><![CDATA[From decafme.org ：

DECAF is a counter intelligence tool specifically created around the obstruction of the well known Microsoft product COFEE used by law enforcement around the world.

DECAF provides real-time monitoring for COFEE signatures on USB devices and running applications. Upon finding the presence of COFEE, DECAF performs numerous user-defined processes; including COFEE log clearing, ejecting USB devices, drive-by dropper........]]></description>
		<wfw:commentRss>http://www.am82.com/houzan/archives/3460/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sa-Upfile 1.0(sa权限上传文件)</title>
		<link>http://www.am82.com/houzan/archives/3282</link>
		<comments>http://www.am82.com/houzan/archives/3282#comments</comments>
		<pubDate>Sat, 12 Dec 2009 04:43:40 +0000</pubDate>
		<dc:creator>假装纯情</dc:creator>
				<category><![CDATA[技术专题]]></category>
		<category><![CDATA[Sa-Upfile]]></category>
		<category><![CDATA[工具]]></category>
		<category><![CDATA[提权]]></category>

		<guid isPermaLink="false">http://www.am82.cn/houzan/?p=3282</guid>
		<description><![CDATA[Author:Bin 使用环境:SQL2000，SA权限，常用提权扩展存在。 原理 ：利用textcopy进行二进制导入导出。 文件下载 ：SA-Upfile (Google)]]></description>
		<wfw:commentRss>http://www.am82.com/houzan/archives/3282/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Metasploit Framework 3.3 Release Candidate 1</title>
		<link>http://www.am82.com/houzan/archives/2985</link>
		<comments>http://www.am82.com/houzan/archives/2985#comments</comments>
		<pubDate>Tue, 10 Nov 2009 04:31:14 +0000</pubDate>
		<dc:creator>假装纯情</dc:creator>
				<category><![CDATA[技术专题]]></category>
		<category><![CDATA[Framework]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[MSF]]></category>
		<category><![CDATA[工具]]></category>

		<guid isPermaLink="false">http://www.am82.cn/houzan/?p=2985</guid>
		<description><![CDATA[This 3.3 release candidate is an early snapshot of what Metasploit 3.3 will look like. We are looking for feedback from the community about the new installers, the stability of the framework itself, and the functional changes between 3.3 and earlier releases of the Metasploit Framework. The 3.3 Draft Release Notes go into detail on the new features and behaviors of this version. For a full list of bug fixes, please refer to the Redmine ChangeLog . If you are a software packager and would like to include Metasploit 3.3 in.......]]></description>
		<wfw:commentRss>http://www.am82.com/houzan/archives/2985/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
