﻿<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>IT博客-我为谁狂</title><link>http://www.cnitblog.com/glgaolei/</link><description>IT专业人才</description><language>zh-cn</language><lastBuildDate>Wed, 29 Apr 2026 06:01:20 GMT</lastBuildDate><pubDate>Wed, 29 Apr 2026 06:01:20 GMT</pubDate><ttl>60</ttl><item><title>智能ABC的漏洞+FLASH</title><link>http://www.cnitblog.com/glgaolei/archive/2007/05/10/26809.html</link><dc:creator>宇翔</dc:creator><author>宇翔</author><pubDate>Thu, 10 May 2007 00:47:00 GMT</pubDate><guid>http://www.cnitblog.com/glgaolei/archive/2007/05/10/26809.html</guid><wfw:comment>http://www.cnitblog.com/glgaolei/comments/26809.html</wfw:comment><comments>http://www.cnitblog.com/glgaolei/archive/2007/05/10/26809.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/glgaolei/comments/commentRss/26809.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/glgaolei/services/trackbacks/26809.html</trackback:ping><description><![CDATA[只要有任何一个程序在运行的状态下的可输入部分调出智能abc。输入v，再按一下&#8593;（补充，按左方向键也行，主要是为了把光标移动到v前面去，然后通过del删除v，用Backspace删除不行！），再按一下del键，之后按空格或者回车该程序立即被杀死。该漏洞目前可以用来对付一切网吧记费软件，适用于所有能安装智能abc的windows系统。该漏洞新的用法正在研究之中太厉害了!!!!!估计是对v的处理有问题吧，智能ABC输入vS，则将S作为英文字符串输出用箭头调整光标（此时向上和向左是一样的）后DEL掉v，但是在程序的内部状态仍然认为输入串是以v打头的比如输入vabcde，删掉v后，输出的是bcde。如果只输入一个v，然后把 v删掉，则按下空格后，智能ABC会对一个空串进行取substr(1)的操作，然后把这个可能是非常大的串用sendmsg发给了目标程序导致目标程序崩溃。<br>
<object style="WIDTH: 328px; HEIGHT: 228px" height=228 width=328 classid=clsid:D27CDB6E-AE6D-11cf-96B8-444553540000 xcodebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab">
<PARAM name="Movie" value="http://202.102.240.91/~zhangyanjie/Flash/泰坦尼克号主题曲.swf" /> <PARAM name="Quality" value="high"/><param name="wmode" value="transparent"/><param name="bgcolor" value="#000000"/><embed src="http://202.102.240.91/~zhangyanjie/Flash/泰坦尼克号主题曲.swf" width="200" height="200"  quality="high" wmode="transparent"   bgcolor="#000000"  type="application/x-shockwave-flash" pluginspage="http://www.macromedia.com/go/getflashplayer"></embed>
</object>
<img src ="http://www.cnitblog.com/glgaolei/aggbug/26809.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/glgaolei/" target="_blank">宇翔</a> 2007-05-10 08:47 <a href="http://www.cnitblog.com/glgaolei/archive/2007/05/10/26809.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>程序员“八荣八耻” </title><link>http://www.cnitblog.com/glgaolei/archive/2007/05/10/26808.html</link><dc:creator>宇翔</dc:creator><author>宇翔</author><pubDate>Thu, 10 May 2007 00:44:00 GMT</pubDate><guid>http://www.cnitblog.com/glgaolei/archive/2007/05/10/26808.html</guid><wfw:comment>http://www.cnitblog.com/glgaolei/comments/26808.html</wfw:comment><comments>http://www.cnitblog.com/glgaolei/archive/2007/05/10/26808.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/glgaolei/comments/commentRss/26808.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/glgaolei/services/trackbacks/26808.html</trackback:ping><description><![CDATA[<p align=center>以动手实践为荣，以只看不练为耻；<br>以打印日志为荣，以出错不报为耻；<br>以局部变量为荣，以全局变量为耻；<br>以单元测试为荣，以手工测试为耻.<br>以代码重用为荣，以复制粘贴为耻；<br>以多态应用为荣，以分支判断为耻；<br>以定义常量为荣，以魔法数字为耻；<br>以总结思考为荣，以不求甚解为耻；</p>
<img src ="http://www.cnitblog.com/glgaolei/aggbug/26808.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/glgaolei/" target="_blank">宇翔</a> 2007-05-10 08:44 <a href="http://www.cnitblog.com/glgaolei/archive/2007/05/10/26808.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item></channel></rss>