
美国著名流行歌星迈克尔·杰克逊25日因心脏病发作在洛杉矶的一家医院去世。
美国《洛杉矶时报》网站援引当地警方的消息称,杰克逊当天下午因心脏病发作深度昏迷被送入洛杉矶加州大学医疗中心,不久该中心的医生正式宣布这位50岁的前流行乐坛巨星不治身亡。
阅读全文

美国著名流行歌星迈克尔·杰克逊25日因心脏病发作在洛杉矶的一家医院去世。
美国《洛杉矶时报》网站援引当地警方的消息称,杰克逊当天下午因心脏病发作深度昏迷被送入洛杉矶加州大学医疗中心,不久该中心的医生正式宣布这位50岁的前流行乐坛巨星不治身亡。
阅读全文
微软公司在中关村一家电脑攒机商购买了12台装有盗版系统的电脑后,将攒机商起诉到法院。昨天,这起“微软起诉攒机商第一案”在一中院宣判,法院判决攒机商北京思创未来科技发展公司赔偿微软公司46万余元。
随着现在大家对电脑行情的了解,中关村海龙鼎好等楼里面的攒机商们利润下降了不少,而且也没法想几年前那样蒙人了。现在这个事情出现了,卖组装机的更不好干了。
这次的胜诉对微软来说,意义绝不是46万的问题。他们要的是尽量的增多购买正版的人数。在暴雪说要将星际争霸二的局域网功能取消的新闻发出时就分析过,对于中国这样的国家,虽然无法阻止人们使用盗版。
阅读全文
据说Charlie Miller发现了一个iPhone的短信漏洞,正在跟Apple合作修复,目前没有更多细节
具体报道见F-secure blog:http://www.f-secure.com/weblog/archives/00001714.html
“This is about as bad as it gets as the vulnerability seems to allow unsigned code to run which circumvents a core part of iPhone’s security model as it’s usually only able to run signed code, i.e. Apps that have been approved by Apple. No user-interaction required which is unlike current mobile malware”
From:zdnet
The sudden death of Michael Jackson quickly opened a window of opportunity for cybercriminals to capitalize on.
With a malicious spam campaign, blackhat SEO search results poisoning which is serving scareware within the first 100 search results for Michael Jackson’s death, and an opportunistic participant in Zango adware’s network using typosquatting, malicious activity is prone to increase during the next couple of days.
Here are more details on the campaigns currently in circulation:
阅读全文
WordPress Plugin Related Sites 2.1 BlindSQLinj Vuln http://wordpress.org/extend/plugins/related-sites/ /wp-content/plugins/related-sites/BTE_RW_webajax.php eLwaux(c) 30.05.2009, uasc.org.ua SQL-Inj 27: $guid = $_POST['guid']; 28: $click = $_POST['click']; 31: $ref = $_SERVER["HTTP_REFERER"];阅读全文
题目:WebLogic简单抓鸡大法
作者:Mickey [I.S.T.O.]&hackest [H.S.T.]
此文章已发表在《黑客X档案》2008年第11期杂志上
后经作者发布在博客上,如转载请务必保留此信息!
Tomcat 估计给很多人带来了N多肉鸡服务器了吧,直接扫描弱口令,进入Tomcat管理后台,上传Webshell就得到一台肉鸡服务器了,操作之简单,效率之 高,实在是抓鸡必备!不过这次要介绍的是一个类似于Tomcat的JSP支持平台WebLogic漏洞的简单利用(其实也是默认口令),相比Tomcat 会稍微复杂一些,不过操作起来也是比较容易的。
阅读全文
Threat models are a very good way to make implicit security threats and mechanisms, into explicit threats and mechanisms, so that you can write requirements, build, and test that they do the job you intend. As a starting point, I like to use a modified version of STRIDE, which among other things cleanly maps threat to mechanism. This way when starting a new project, for example with SOA Web services, you can identify where the standards will help you.
阅读全文