2009-10-12

WINDOWS VISTA / 2008 SERVER SMB2 PORT 445 REMOTE COMMAND EXECUTION EXPLOIT

 
 

Sent to you by l5g via Google Reader:

 
 

via hacking expose! : extreme disclosure by noreply@blogger.com (d3ck4) on 10/1/09



picture shows an ethical test drive (with *permission* of cos ;-) of the latest smb2 remote command execution exploit (metasploit version) against windows vista home premium service pack 1

Microsoft SRV2.SYS SMB Negotiate ProcessID Function Table Dereference

This module exploits an out of bounds function table dereference in the SMB request validation code of the SRV2.SYS driver included with Windows Vista, Windows 7 release candidates (not RTM), and Windows 2008 Server prior to R2. Windows Vista without SP1 does not seem affected by this flaw.

this issue has been notified here before. details about the vulnerability advisory and workaround is here or read more here. the exploit is now public, a new worm is set to launch for sure while the patch is soon to be available..

..and all the kids goes to heaven ;-)

knock! knock! wake up!

 
 

Things you can do from here:

 
 

Parsing PE (EXE, DLL) Files in Python

 
 

Sent to you by l5g via Google Reader:

 
 

via From a malicious attacker by Jason on 1/11/07

pefile is a Python module to read and work with PE files. Most of the information in the PE Header is accessible, as well as all the sections, section's information and data.

 
 

Things you can do from here:

 
 

Setting Up Pydbg

 
 

Sent to you by l5g via Google Reader:

 
 

via From a malicious attacker by Jason on 1/27/07

This post should provide guidance to the individual looking to setup pydbg with the least amount of headache. When last I tried, PaiMei didn't play nice running under cygwin Python. Things worked much better under Python for Windows. I recommend creating a VMware image and then setting up shop in the image. Once you have a suitable image setup, install Python 2.4 for Windows. Next, download and run the ctypes installer for windows.

Now you're ready to install PaiMei. Download it from OpenRCE. Extract the zip file and execute the installer found in the installers directory. If you chose to install under VMware, there is a small hack you may need to implement before pydbg will work correctly inside VMware. To verify that you have a working installation, download my test script, fire up notepad.exe and execute the script. If the script barfs with an error, something is wrong. Otherwise, you are now ready to begin debugging applications from Python.

 
 

Things you can do from here:

 
 

2009-10-11

from email

from email

生活帮——中国移动的指令大全!(不再需要人工台)

 
 

Sent to you by l5g via Google Reader:

 
 

via 玩聚SR|最佳 by 左岸读书 on 10/9/09

玩聚SR还知道:
湖北移动是个渣,什么都不行!!!
左岸读书发表于2009-10-10 09:53:50

1.发送CXBX到10086,查询当月套餐剩余短信条数。

2.发送CXGFX到10086,查询当月飞信GPRS套餐剩余流量。

3.发送CXGTC到10086,查询当月GPRS套餐剩余流量。

4.发送CXCCT到10086,查询当月超级畅听套餐剩余流量。

5.发送CXGLL到10086,查询当月已使用的GPRS流量总和。

6.发送CXDX120,查询当月可选计划"短信120"剩余短信条数。

7.发送CXDX500,查询当月可选计划"短信500"剩余短信条数。

8.发送CXCXB,查询当月可选计划"彩信包"剩余彩信条数。

9.发送CXIP1000,查询当月可选计划"IP1000"剩余通话时长。

10.发送CXMDX,查询M计划兑换的"短信包(50条/月)"当月剩余短信条数。

11.发送CXMCX,查询M计划兑换的"彩信包(10条/月)"当月剩余彩信条数。

12.发送CXMG,查询M计划兑换的"10M/月的GPRS流量"剩余流量。

信指令                短信发送端口        办理业务

YE/CXYE   10086      余额查询

KTFX     10086      开通飞信

QXFX     10086      取消飞信

BLHZ     10086      开通短信回执

QXHZ     10086      取消短信回执

BLYY19    10086      办理19元音乐卡套餐

BLYY29    10086    ....办理29元音乐卡套餐

BLYY39    10086      办理39元音乐卡套餐

BLYY59    10086      办理59元音乐卡套餐

GPRS5   . 10086      办理GPRS5元套餐

GPRS20    10086      办理GPRS20元套餐

GPRS50    10086      办理GPRS50元套餐

GPRS100   .10086      办理GPRS100元套餐

GPRS200   .10086      办理GPRS200元套餐

 

信指令                短信发送端口                办理业务

CXGPRS5   .10086      查询GPRS5元套餐

CXGPRS20   10086      查询GPRS20元套餐

CXGPRS50   10086      查询GPRS50元套餐

CXGPRS100  10086    ....查询GPRS100元套餐

CXGPRS200  10086    ....查询GPRS200元套餐

QXGPRS        10086      取消GPRS套餐

KTGPRS        10086      恢复GPRS功能

XGMM         10086     .修改密码

KTHK     10086      开通香港漫游

QXHK     10086      取消香港漫游

KTMC     10086      开通澳门漫游

QXMC     10086      取消澳门漫游

KTTW     10086      开通台湾漫游

QXTW     10086      取消台湾漫游

BLLDXS    10086      开通来电显示

QXLDXS    10086     .取消来电显示

CXLDXS    10086     .查询来电显示

BLHJZY   .10086     .开通呼叫转移

QXHJZY   .10086     .取消呼叫转移

CXHJZY   .10086     .查询呼叫转移

BLHJDD   .10086     .开通呼叫等待

QXHJDD   .10086     .取消呼叫等待

CXHJDD   .10086     .查询呼叫等待

BLZWMS   .10086     .开通中文秘书

QXZWMS   .10086     .取消中文秘书

CXZWMS   .10086     .查询中文秘书

BLLYXX         10086        开通留言信箱

QXLYXX        10086        取消留言信箱

CXLYXX        10086        查询留言信箱

GS+11位号码        10086        查询号码归属地

0000/00000        10086        梦网业务查询与退订

TC加想要包月的短信钱数(例如TC30)发到10086,就可以改短信包月

评论《生活帮——中国移动的指令大全!(不再需要人工台)》的内容...

左岸读书投稿信箱:zaolee(at)foxmail.com

两性学堂——男人二十怕,女人要注意!  (2009-10-10 10:50:34)

学习帮——待人接物的基本礼仪,保你学会不少东西!  (2009-10-10 10:40:48)

每日语录——2009/10/08网络经典语录(娱乐/生活/猎奇/两性/思想)  (2009-10-9 8:38:17)

每日心理学——为什么女人(妻子)都爱管钱?  (2009-10-8 11:52:25)

学习帮——180妙招!全方位教你管教出好孩子!  (2009-10-8 11:23:16)

更多订阅方式新段子/笑话心理学经典/语录书/电影/音乐两性哲学工作学习生活


玩聚SR 是一个追踪各种社会化媒体,实时发现IT人都在分享和推荐什么的工具。点击阅读科技频道热文。
手机请登录移动版

 
 

Things you can do from here:

 
 

Stephen Ferg: Debugging in Python

 
 

Sent to you by l5g via Google Reader:

 
 

via Planet Python on 10/3/09


As a programmer, one of the first things that you need for serious program development is a debugger.

Python has a debugger, which is available as a module called pdb (for "Python DeBugger", naturally!). Unfortunately, most discussions of pdb are not very useful to a Python newbie — most are very terse and simply rehash the description of pdb in the Python library reference manual. The discussion that I have found most accessible is in the first four pages of Chapter 27 of the Python 2.1 Bible.

So here is my own personal gentle introduction to using pdb. It assumes that you are not using any IDE — that you're coding Python with a text editor and running your Python programs from the command line.

Some Other Debugger Resources

Getting started — pdb.set_trace()

To start, I'll show you the very simplest way to use the Python debugger.

1. Let's start with a simple program, epdb1.py.

# epdb1.py -- experiment with the Python debugger, pdb a = "aaa" b = "bbb" c = "ccc" final = a + b + c print final

2. Insert the following statement at the beginning of your Python program. This statement imports the Python debugger module, pdb.

import pdb

3. Now find a spot where you would like tracing to begin, and insert the following code:

pdb.set_trace()

So now your program looks like this.

# epdb1.py -- experiment with the Python debugger, pdb import pdb a = "aaa" pdb.set_trace() b = "bbb" c = "ccc" final = a + b + c print final

4. Now run your program from the command line as you usually do, which will probably look something like this:

PROMPT> python epdb1.py

When your program encounters the line with pdb.set_trace() it will start tracing. That is, it will (1) stop, (2) display the "current statement" (that is, the line that will execute next) and (3) wait for your input. You will see the pdb prompt, which looks like this:

(Pdb)

Execute the next statement… with "n" (next)

At the (Pdb) prompt, press the lower-case letter "n" (for "next") on your keyboard, and then press the ENTER key. This will tell pdb to execute the current statement. Keep doing this — pressing "n", then ENTER.

Eventually you will come to the end of your program, and it will terminate and return you to the normal command prompt.

Congratulations! You've just done your first debugging run!

Repeating the last debugging command… with ENTER

This time, do the same thing as you did before. Start your program running. At the (Pdb) prompt, press the lower-case letter "n" (for "next") on your keyboard, and then press the ENTER key.

But this time, after the first time that you press "n" and then ENTER, don't do it any more. Instead, when you see the (Pdb) prompt, just press ENTER. You will notice that pdb continues, just as if you had pressed "n". So this is Handy Tip #1:

If you press ENTER without entering anything, pdb will re-execute the last command that you gave it.

In this case, the command was "n", so you could just keep stepping through the program by pressing ENTER.

Notice that as you passed the last line (the line with the "print" statement), it was executed and you saw the output of the print statement ("aaabbbccc") displayed on your screen.

Quitting it all… with "q" (quit)

The debugger can do all sorts of things, some of which you may find totally mystifying. So the most important thing to learn now — before you learn anything else — is how to quit debugging!

It is easy. When you see the (Pdb) prompt, just press "q" (for "quit") and the ENTER key. Pdb will quit and you will be back at your command prompt. Try it, and see how it works.

Printing the value of variables… with "p" (print)

The most useful thing you can do at the (Pdb) prompt is to print the value of a variable. Here's how to do it.

When you see the (Pdb) prompt, enter "p" (for "print") followed by the name of the variable you want to print. And of course, you end by pressing the ENTER key.

Note that you can print multiple variables, by separating their names with commas (just as in a regular Python "print" statement). For example, you can print the value of the variables a, b, and c this way:

p a, b, c

When does pdb display a line?

Suppose you have progressed through the program until you see the line

final = a + b + c

and you give pdb the command

p final

You will get a NameError exception. This is because, although you are seeing the line, it has not yet executed. So the final variable has not yet been created.

Now press "n" and ENTER to continue and execute the line. Then try the "p final" command again. This time, when you give the command "p final", pdb will print the value of final, which is "aaabbbccc".

Turning off the (Pdb) prompt… with "c" (continue)

You probably noticed that the "q" command got you out of pdb in a very crude way — basically, by crashing the program.

If you wish simply to stop debugging, but to let the program continue running, then you want to use the "c" (for "continue") command at the (Pdb) prompt. This will cause your program to continue running normally, without pausing for debugging. It may run to completion. Or, if the pdb.set_trace() statement was inside a loop, you may encounter it again, and the (Pdb) debugging prompt will appear once more.

Seeing where you are… with "l" (list)

As you are debugging, there is a lot of stuff being written to the screen, and it gets really hard to get a feeling for where you are in your program. That's where the "l" (for "list") command comes in. (Note that it is a lower-case "L", not the numeral "one" or the capital letter "I".)

"l" shows you, on the screen, the general area of your program's souce code that you are executing. By default, it lists 11 (eleven) lines of code. The line of code that you are about to execute (the "current line") is right in the middle, and there is a little arrow "–>" that points to it.

So a typical interaction with pdb might go like this

  • The pdb.set_trace() statement is encountered, and you start tracing with the (Pdb) prompt
  • You press "n" and then ENTER, to start stepping through your code.
  • You just press ENTER to step again.
  • You just press ENTER to step again.
  • You just press ENTER to step again. etc. etc. etc.
  • Eventually, you realize that you are a bit lost. You're not exactly sure where you are in your program any more. So…
  • You press "l" and then ENTER. This lists the area of your program that is currently being executed.
  • You inspect the display, get your bearings, and are ready to start again. So….
  • You press "n" and then ENTER, to start stepping through your code.
  • You just press ENTER to step again.
  • You just press ENTER to step again. etc. etc. etc.

Stepping into subroutines… with "s" (step into)

Eventually, you will need to debug larger programs — programs that use subroutines. And sometimes, the problem that you're trying to find will lie buried in a subroutine. Consider the following program.

# epdb2.py -- experiment with the Python debugger, pdb import pdb  def combine(s1,s2):      # define subroutine combine, which... s3 = s1 + s2 + s1    # sandwiches s2 between copies of s1, ... s3 = '"' + s3 +'"'   # encloses it in double quotes,... return s3            # and returns it.  a = "aaa" pdb.set_trace() b = "bbb" c = "ccc" final = combine(a,b) print final

As you move through your programs by using the "n" command at the (Pdb) prompt, you will find that when you encounter a statement that invokes a subroutine — the final = combine(a,b) statement, for example — pdb treats it no differently than any other statement. That is, the statement is executed and you move on to the next statement — in this case, to print final.

But suppose you suspect that there is a problem in a subroutine. In our case, suppose you suspect that there is a problem in the combine subroutine. What you want — when you encounter the final = combine(a,b) statement — is some way to step into the combine subroutine, and to continue your debugging inside it.

Well, you can do that too. Do it with the "s" (for "step into") command.

When you execute statements that do not involve function calls, "n" and "s" do the same thing — move on to the next statement. But when you execute statements that invoke functions, "s", unlike "n", will step into the subroutine. In our case, if you executed the final = combine(a,b) statement using "s", then next statement that pdb would show you would be the first statement in the combine subroutine:

def combine(s1,s2):

and you will continue debugging from there.

Continuing… but just to the end of the current subroutine… with "r" (return)

When you use "s" to step into subroutines, you will often find yourself trapped in a subroutine. You have examined the code that you're interested in, but now you have to step through a lot of uninteresting code in the subroutine.

In this situation, what you'd like to be able to do is just to skip ahead to the end of the subroutine. That is, you want to do something like the "c" ("continue") command does, but you want just to continue to the end of the subroutine, and then resume your stepping through the code.

You can do it. The command to do it is "r" (for "return" or, better, "continue until return"). If you are in a subroutine and you enter the "r" command at the (Pdb) prompt, pdb will continue executing until the end of the subroutine. At that point — the point when it is ready to return to the calling routine — it will stop and show the (Pdb) prompt again, and you can resume stepping through your code.

You can do anything at all at the (Pdb) prompt …

Sometimes you will be in the following situation — You think you've discovered the problem. The statement that was assigning a value of, say, "aaa" to variable var1 was wrong, and was causing your program to blow up. It should have been assigning the value "bbb" to var1.

… at least, you're pretty sure that was the problem…

What you'd really like to be able to do, now that you've located the problem, is to assign "bbb" to var1, and see if your program now runs to completion without bombing.

It can be done!

One of the nice things about the (Pdb) prompt is that you can do anything at it — you can enter any command that you like at the (Pdb) prompt. So you can, for instance, enter this command at the (Pdb) prompt.

(Pdb) var1 = "bbb"

You can then continue to step through the program. Or you could be adventurous — use "c" to turn off debugging, and see if your program will end without bombing!

… but be a little careful!

[Thanks to Dick Morris for the information in this section.]

Since you can do anything at all at the (Pdb) prompt, you might decide to try setting the variable b to a new value, say "BBB", this way:

(Pdb) b = "BBB"

If you do, pdb produces a strange error message about being unable to find an object named '= "BBB" '. Why???

What happens is that pdb attempts to execute the pdb b command for setting and listing breakpoints (a command that we haven't discussed). It interprets the rest of the line as an argument to the b command, and can't find the object that (it thinks) is being referred to. So it produces an error message.

So how can we assign a new value to b? The trick is to start the command with an exclamation point (!).

(Pdb)!b = "BBB"

An exclamation point tells pdb that what follows is a Python statement, not a pdb command.

The End

Well, that's all for now. There are a number of topics that I haven't mentioned, such as help, aliases, and breakpoints. For information about them, try the online reference for pdb commands on the Python documentation web site. In addition, I recommend Jeremy Jones' article Interactive Debugging in Python in O'Reilly's Python DevCenter.

I hope that this introduction to pdb has been enough to get you up and running fairly quickly and painlessly. Good luck!

—Steve Ferg


 
 

Things you can do from here:

 
 

Ned Batchelder's blog: Today's KenKen

 
 

Sent to you by l5g via Google Reader:

 
 

via Planet Python on 10/11/09

The raging success of Sudoku has created demand for more abstract analytical puzzles, and KenKen seems to fit the bill nicely. Like Sudoku, completing the puzzle requires satisfying a number of overlapping constraints. For KenKen, the rows and columns must have each number only once, and the outlined areas (called cages) must total to the correct number using the specified operator. So a cage marked "10+" must sum to 10, while in one marked "2÷", the numbers must be a pair that divides to 2.

I find KenKen more interesting than Sudoku, because of the variety of logic that has to be applied to solve one. As an example, here is today's New York Times KenKen:

KenKen, as presented

I'll show here step-by-step how I solved it. First we fill in the forced numbers:

KenKen, step 1

At cage C4:D4, we need a sum of 5, which is either 1,4 or 2,3. Column 4 already has a 3, so it must be 1,4, though we don't know exactly where. Fill in the possibilities:

KenKen, step 2

Looking at row E, the 5 can't go in either of the 2÷ cages, so it has to go into the 6+, making it 1,5. Column 4 already has a 1, so we know exactly where they go:

KenKen, step 3

G5:G6 is either 1,3 or 2,6, but G4 is already 3, so it must be 2,6:

KenKen, step 4

Now, consider rows F and G together. The sum of all the cells in both rows must be 56 (2×(1+2+3+4+5+6+7)). Other than F4:F5 and G2:G3, we have a sum of 10+7+10+3+8, or 38. So F4:F5 + G2:G3 is 18. If one of them is 1,4, then the other must sum to 18-5 or 13, making it 5,8, which is impossible, so neither is 1,4. If one of them is 3,6, then the other is also 3,6 but G2:G3 can't be 3,6 since G4 is already 3. The last remaining possibility is that one of them is 2,5 and the other is 4,7. F4:F5 can't be 4,7 (since F3 is 7), so it is 2,5, and G2:G3 is 7,4. E4 determines where the 5 will go, and F3 determines where the 7 will go:

KenKen, step 5

In row A, we have a similar arrangement with two 3− cages. Because the entire row sums to 28, and the third cage is a 10+, the two 3− cages together sum to 18, just like we saw in rows F and G. Again 1,4 and 5,8 isn't a possibility, and because they're on the same row, we can't use 3,6 and 3,6. So these cages will also be filled with 2,5 and 4,7, though we don't know which is which.

That leaves 1,3,6 to fill the 10+ on row A. The 1 has to go in column 5 since columns 3 and 4 already have 1's. Column 4 has a 3, so A4 gets the 6, and A3 gets the 3:

KenKen, step 6

The last number in column 4 is the 7 for B4. The 56× cage needs a 7, which can't go in row B or column 5, so it goes in C6:

KenKen, step 7

Now comes some complicated logic. Look at rows B, C, and D. All togther, their cells have to sum to 84. We know the 56× cage has to be 7,2,4, so the only cages we don't know the sums of are 36×, 3−, and 2−. The others sum to 54.

There are three possibilities for the 36× cage: 3,4,3 or 6,2,3 or 6,1,6. Let's consider them in turn:

  • If 36× is 3,4,3, then the 3− and 2− cages have to sum to 20, which isn't possible since the sum of a 3− must be odd and the sum of a 2− must be even, which sum to odd.
  • If 36× is 6,2,3, then the 3− and 2− cages sum to 19. There are three ways to do that, none of which are allowed:
    • 7,4 and 5,3: won't work, because columns 2 and 3 already have 7's.
    • 6,3 and 6,4: that would put two 6's in row D.
    • 5,2 and 7,5: two 5's in row D.
  • So 36× must be 6,1,6. Let's look at the possibilities for the 3− and 2−:
    • 7,4 and 4,2: nope, two 4's in row D.
    • 6,3 and 5,3: nope, two 3's in row D.
    • 5,2 and 6,4: that's valid!
    • 4,1 and 7,5: nope, columns 5 and 6 both have 7's already.

So there's only one way to complete the 3− and 2− in row D, and we know the solution to the 36×. Also, the possibilites for the 2− cage force the positions of the 1 and 4 in column 4:

KenKen, step 8

Column 3 is almost completed. D3 is either 2 or 5, so B3 is either 5 or 2. If it's 2, then B5 must be 6, but column 5 will get a 6 from either D5 or G5, so B3 must be 5, and D2 and D3 are determined also:

KenKen, step 9

The 56× cage has to be 7,2,4 and we now have enough squares filled in to see where they go. These then fix the positions of two cages on rows D and G:

KenKen, step 10

Returning to the two 3− cages in row A: they are 2,5 and 4,7. With column 6 more filled in, we can see that A6:A7 has to be 5,2, and A1:A2 is 7,4:

KenKen, step 11

The two 2÷ cages in row E will be 2,4 and 3,6. Neither 2 or 4 can go in column 6, so those cages can be filled in, along with the last remaining numbers in columns 2 and 6:

KenKen, step 12

Now our rows have only two numbers each remaining. In each row we can consider the two missing numbers, and place them in the column that doesn't already have it:

KenKen, step 13

And the rest is easy:

KenKen, completed


 
 

Things you can do from here: