January
13th
2007

Apache2,SSL,Mysql,PHP and OpenLDAP Installation

Technology 1 Comment

评分: 很差劲不怎样还可以还不错太棒了
Loading ... Loading ...

1. Install Mysql

  1. #groupadd mysql
  2. #adduser mysql -g mysql -s /nologin
  3. #cd mysql-VERSION/
  4. #./configure --prefix=/usr/local/mysql
  5. #make && make install
  6. #scripts/mysql_install_db
  7. #chown -R root:mysql /usr/local/mysql
  8. #chown -R mysql /usr/local/mysql/var
  9. #/usr/local/mysql/bin/mysqld_safe --user=mysql
  10. #mysql -uroot
  11. >use mysql;
  12. >update user set password=password('XXX') where user='root';
  13. >flush priviledges;


December
26th
2006

Apache最新安全漏洞与利用!

Technology No Comments

评分: 很差劲不怎样还可以还不错太棒了
Loading ... Loading ...

描述: 任意以.php开头的文件名,Apache都当做php文件解析, 如”.php.comment”将被当做php文件解析,由此引发一系列漏洞.

MG2是在国外非常流行的一个PHP+HTML的图片管理程序,由于商业版被破解,程序流传甚广,在google搜索关键字为”Powered by MG2 v0.5.1″ 最新版本存在着文件写入漏洞,可配和Apache漏洞直接得shell