<?xml version='1.0' encoding='UTF-8'?>
<rss version='2.0' xmlns:dc='http://purl.org/dc/elements/1.1/'>
<channel>
<title>CSDN技术网摘 -- wz.csdn.net(Security)</title>
<description>CSDN技术网摘 -- wz.csdn.net(Security)</description>
<link>http://wz.csdn.net/tag-rss/Security/</link>
<generator>CSDN网摘 (http://wz.csdn.net)</generator>
<language>zh-cn</language>
<docs>CSDN网摘 包罗技术精华</docs>
<item>
<title>Acegi Security -- Spring下最优秀的安全系统 - 孤独是因为思念谁 - CSDNBlog</title>
<link>http://blog.csdn.net/daoquan/archive/2007/04/18/1568670.aspx</link>
<guid isPermaLink="true">http://blog.csdn.net/daoquan/archive/2007/04/18/1568670.aspx</guid>
<category>Acegi,Security,--,Spring下最优秀的安全系统</category>
<pubDate>Mon, 21 Jul 2008 06:04:47 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>zhaozhikunkunkun</dc:creator>
</item>
<item>
<title>实现在线时间统计</title>
<link>http://topic.csdn.net/u/20080713/14/35c4e65a-44dc-4a2b-8250-e7e31475fefb.html?seed=340821663</link>
<guid isPermaLink="true">http://topic.csdn.net/u/20080713/14/35c4e65a-44dc-4a2b-8250-e7e31475fefb.html?seed=340821663</guid>
<category>CSDN,Security,SignOn</category>
<pubDate>Mon, 14 Jul 2008 16:15:16 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>Jinglecat</dc:creator>
</item>
<item>
<title>在Spring Security 2中使用本地化资源文件 - 蓝剑专栏 - CSDNBlog</title>
<link>http://blog.csdn.net/bukebushuo/archive/2008/05/22/2468560.aspx</link>
<guid isPermaLink="true">http://blog.csdn.net/bukebushuo/archive/2008/05/22/2468560.aspx</guid>
<category>Spring,Security,2</category>
<pubDate>Wed, 09 Jul 2008 17:24:59 GMT</pubDate>
<description><blockquote>在Spring Security 2中使用本地化资源文件</blockquote></description>
<dc:creator>raofei</dc:creator>
</item>
<item>
<title>Symantec Endpoint Protection v11.0.2010 MR2 MP1 简体中文版</title>
<link>http://www.cnbeta.com/articles/58600.htm</link>
<guid isPermaLink="true">http://www.cnbeta.com/articles/58600.htm</guid>
<category>Security</category>
<pubDate>Sun, 22 Jun 2008 00:05:01 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>scz123</dc:creator>
</item>
<item>
<title>远离威胁 端口扫描器为爱机安全体检 - 第2页 | IT168</title>
<link>http://safe.it168.com/p/2008-02-26/200802262300968_1.shtml</link>
<guid isPermaLink="true">http://safe.it168.com/p/2008-02-26/200802262300968_1.shtml</guid>
<category>security</category>
<pubDate>Fri, 20 Jun 2008 07:11:04 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>WTubo</dc:creator>
</item>
<item>
<title>NetGong 6.5 - 简易的网络监视器</title>
<link>http://www.cnbeta.com/articles/56501.htm</link>
<guid isPermaLink="true">http://www.cnbeta.com/articles/56501.htm</guid>
<category>Security</category>
<pubDate>Tue, 27 May 2008 00:27:24 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>scz123</dc:creator>
</item>
<item>
<title>网站被连续注入，疯了，求两个正则一个50分！</title>
<link>http://topic.csdn.net/u/20080508/18/18b7fca7-b08d-4aa8-8637-6e62fd748f48.html</link>
<guid isPermaLink="true">http://topic.csdn.net/u/20080508/18/18b7fca7-b08d-4aa8-8637-6e62fd748f48.html</guid>
<category>website,security</category>
<pubDate>Fri, 09 May 2008 08:14:08 GMT</pubDate>
<description><blockquote>replace</blockquote></description>
<dc:creator>Jacran</dc:creator>
</item>
<item>
<title>Some Blog Posts on Silverlight Security</title>
<link>http://weblogs.asp.net/joestagner/archive/2008/03/13/some-blog-posts-on-silverlight-security.aspx</link>
<guid isPermaLink="true">http://weblogs.asp.net/joestagner/archive/2008/03/13/some-blog-posts-on-silverlight-security.aspx</guid>
<category>Silverlight,Security</category>
<pubDate>Thu, 13 Mar 2008 20:06:00 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>saucer</dc:creator>
</item>
<item>
<title>Detecting permission issues using auditing and process monitor</title>
<link>http://weblogs.asp.net/steveschofield/archive/2008/03/07/detecting-permission-issues-using-auditing-and-process-monitor.aspx</link>
<guid isPermaLink="true">http://weblogs.asp.net/steveschofield/archive/2008/03/07/detecting-permission-issues-using-auditing-and-process-monitor.aspx</guid>
<category>Security</category>
<pubDate>Fri, 07 Mar 2008 14:28:37 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>saucer</dc:creator>
</item>
<item>
<title>Can Architects Stop Financial Ruin and Market Meltdowns?</title>
<link>http://www.infoq.com/news/2008/02/architects-stop-market-meltdowns</link>
<guid isPermaLink="true">http://www.infoq.com/news/2008/02/architects-stop-market-meltdowns</guid>
<category>Security,Architecture</category>
<pubDate>Tue, 19 Feb 2008 14:07:50 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>saucer</dc:creator>
</item>
<item>
<title>九大措施安全配置SQLServer2000数据库 , 数据库,端口,帐号,安全,存储过程,密码,操作系统,管理员,使用,探测,SQLServer, , - CSDN 新闻</title>
<link>http://news.csdn.net/n/20061124/98147.html</link>
<guid isPermaLink="true">http://news.csdn.net/n/20061124/98147.html</guid>
<category>Security</category>
<pubDate>Sun, 20 Jan 2008 08:45:22 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>nudter401</dc:creator>
</item>
<item>
<title>Hologram Sticker | Shanghai Henglei Hologram CO.,LTD</title>
<link>http://www.hologram.name</link>
<guid isPermaLink="true">http://www.hologram.name</guid>
<category>hologram,technology,holograms,holography,hologram,sticker,hologram,label,holography,holographic,holographer,holographic,sticker,holographic,label,security,hologram</category>
<pubDate>Thu, 29 Nov 2007 05:45:27 GMT</pubDate>
<description><blockquote>hologram company | We supply hologram Sticker, holography Sticker, holographic sticker, Holography Machinery, Hologram sticker</blockquote></description>
<dc:creator>liajer</dc:creator>
</item>
<item>
<title>安全专家支招防范黑客攻击九大方法 , 帐户,黑客,注册表,键值,服务器,入侵,权限,账号,用户,密码, , - CSDN 新闻</title>
<link>http://news.csdn.net/n/20071111/110530.html</link>
<guid isPermaLink="true">http://news.csdn.net/n/20071111/110530.html</guid>
<category>web,security</category>
<pubDate>Tue, 27 Nov 2007 03:18:29 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>Yaaaaaa</dc:creator>
</item>
<item>
<title>nmap</title>
<link>http://blog.csdn.net/ruibird/archive/2006/09/26/1288103.aspx</link>
<guid isPermaLink="true">http://blog.csdn.net/ruibird/archive/2006/09/26/1288103.aspx</guid>
<category>Security</category>
<pubDate>Sun, 18 Nov 2007 08:26:01 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>perfectspr</dc:creator>
</item>
<item>
<title>First Line of Defense for Web Applications – Part 4</title>
<link>http://blogs.msdn.com/hackers/archive/2007/11/12/first-line-of-defense-for-web-applications-part-4.aspx</link>
<guid isPermaLink="true">http://blogs.msdn.com/hackers/archive/2007/11/12/first-line-of-defense-for-web-applications-part-4.aspx</guid>
<category>Security,Web</category>
<pubDate>Mon, 12 Nov 2007 16:27:51 GMT</pubDate>
<description><blockquote>The top most common mistakes developers make today when they implement input validation routines for web application attack</blockquote></description>
<dc:creator>saucer</dc:creator>
</item>
<item>
<title>How to pass credentials to web service in ATLAS?</title>
<link>http://community.csdn.net/Expert/TopicView3.asp?id=5285109</link>
<guid isPermaLink="true">http://community.csdn.net/Expert/TopicView3.asp?id=5285109</guid>
<category>ScriptManager,security,AJAX,NetworkCredential,membership</category>
<pubDate>Tue, 04 Sep 2007 04:43:47 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>jiangsheng</dc:creator>
</item>
<item>
<title>VC  中利�?GS开关防止缓冲区溢出 - 农民的萝卜地 - CSDNBlog</title>
<link>http://blog.csdn.net/jiaohe2000/archive/2007/08/17/1747797.aspx</link>
<guid isPermaLink="true">http://blog.csdn.net/jiaohe2000/archive/2007/08/17/1747797.aspx</guid>
<category>VC,security,buffer,overflow</category>
<pubDate>Sat, 18 Aug 2007 02:05:11 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>IDisposable</dc:creator>
</item>
<item>
<title>常见端口详解及攻击策略</title>
<link>http://dev.csdn.net/author/jitom515/690c2623b44f42beaf68aa7edc292790.html</link>
<guid isPermaLink="true">http://dev.csdn.net/author/jitom515/690c2623b44f42beaf68aa7edc292790.html</guid>
<category>Security</category>
<pubDate>Thu, 16 Aug 2007 00:18:07 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>perfectspr</dc:creator>
</item>
<item>
<title>认识黑客入侵的利器　嗅探软件逐个了解 </title>
<link>http://security.ccidnet.com/art/1101/20070813/1175381_1.html</link>
<guid isPermaLink="true">http://security.ccidnet.com/art/1101/20070813/1175381_1.html</guid>
<category>Security</category>
<pubDate>Wed, 15 Aug 2007 09:00:23 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>scz123</dc:creator>
</item>
<item>
<title>最佳的75个网络安全工具</title>
<link>http://blog.csdn.net/fengxinz/archive/2007/08/11/1738362.aspx</link>
<guid isPermaLink="true">http://blog.csdn.net/fengxinz/archive/2007/08/11/1738362.aspx</guid>
<category>Security</category>
<pubDate>Mon, 13 Aug 2007 00:00:54 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>perfectspr</dc:creator>
</item>
<item>
<title>用ntfs流隐藏文件</title>
<link>http://www.hacker.com.cn/article/list.asp?id=7504</link>
<guid isPermaLink="true">http://www.hacker.com.cn/article/list.asp?id=7504</guid>
<category>Security</category>
<pubDate>Sat, 11 Aug 2007 06:39:14 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>scz123</dc:creator>
</item>
<item>
<title>(ZT)rootkit入门(翻译)</title>
<link>https://www.xfocus.net/bbs/index.php?act=SE&amp;f=3&amp;t=58260&amp;p=270455</link>
<guid isPermaLink="true">https://www.xfocus.net/bbs/index.php?act=SE&amp;f=3&amp;t=58260&amp;p=270455</guid>
<category>Security</category>
<pubDate>Tue, 10 Jul 2007 04:45:49 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>scz123</dc:creator>
</item>
<item>
<title>城里城外看SSDT</title>
<link>http://www.titilima.cn/readarticle.php?id=78</link>
<guid isPermaLink="true">http://www.titilima.cn/readarticle.php?id=78</guid>
<category>Security</category>
<pubDate>Fri, 06 Jul 2007 00:34:46 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>scz123</dc:creator>
</item>
<item>
<title>Cracking Cached Domain/Active Directory Passwords on Windows XP/2000/2003 - Welcome to my blog -- ZwelL - DonewsBlog</title>
<link>http://blog.donews.com/zwell/archive/2005/03/29/316373.aspx</link>
<guid isPermaLink="true">http://blog.donews.com/zwell/archive/2005/03/29/316373.aspx</guid>
<category>Security</category>
<pubDate>Wed, 13 Jun 2007 11:57:52 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>scz123</dc:creator>
</item>
<item>
<title>McAfee - AudioParasitics</title>
<link>http://podcasts.mcafee.com/audioparasitics/archives.html</link>
<guid isPermaLink="true">http://podcasts.mcafee.com/audioparasitics/archives.html</guid>
<category>Security</category>
<pubDate>Wed, 16 May 2007 00:32:15 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>scz123</dc:creator>
</item>
<item>
<title>有关文档保护似是而非的观点及我的看法_EVA的回收站</title>
<link>http://hi.baidu.com/zzzevazzz/blog/item/368459f462fd12d8f2d385de.html</link>
<guid isPermaLink="true">http://hi.baidu.com/zzzevazzz/blog/item/368459f462fd12d8f2d385de.html</guid>
<category>Security</category>
<pubDate>Fri, 27 Apr 2007 03:06:37 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>scz123</dc:creator>
</item>
<item>
<title>允许权限、拒绝权限、传播权限、阻止权限 </title>
<link>http://blog.csdn.net/eye_of_back/archive/2006/03/24/636810.aspx</link>
<guid isPermaLink="true">http://blog.csdn.net/eye_of_back/archive/2006/03/24/636810.aspx</guid>
<category>权限,允许权限,拒绝权限,传播权限,阻止权限,继承,security,permission,authorize,allow,reject</category>
<pubDate>Mon, 23 Apr 2007 10:54:40 GMT</pubDate>
<description><blockquote>允许权限、拒绝权限、传播权限、阻止权限是权限控制体系中非常重要的概念，作者在文中做了一定程度的描述。</blockquote></description>
<dc:creator>eye_of_back</dc:creator>
</item>
<item>
<title>servlet的线程安全表</title>
<link>http://blog.csdn.net/eye_of_back/archive/2006/03/24/636829.aspx</link>
<guid isPermaLink="true">http://blog.csdn.net/eye_of_back/archive/2006/03/24/636829.aspx</guid>
<category>servlet,thread,security,线程,安全</category>
<pubDate>Sun, 22 Apr 2007 10:30:52 GMT</pubDate>
<description><blockquote>servlet的线程安全问题，在一般情况下是不会出现的，但是如果对此理解不够，很容易造成编程上的逻辑混乱。</blockquote></description>
<dc:creator>eye_of_back</dc:creator>
</item>
<item>
<title>破解所谓的“网页源代码加密”_EVA的回收站</title>
<link>http://hi.baidu.com/zzzevazzz/blog/item/94602afacd866f9658ee902d.html</link>
<guid isPermaLink="true">http://hi.baidu.com/zzzevazzz/blog/item/94602afacd866f9658ee902d.html</guid>
<category>Security</category>
<pubDate>Fri, 20 Apr 2007 01:46:12 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>scz123</dc:creator>
</item>
<item>
<title>Acegi Security -- Spring下最优秀的安全系统 - 孤独是因为思念谁 - CSDNBlog</title>
<link>http://blog.csdn.net/daoquan/archive/2007/04/18/1568670.aspx</link>
<guid isPermaLink="true">http://blog.csdn.net/daoquan/archive/2007/04/18/1568670.aspx</guid>
<category>Acegi,Security,安全系统</category>
<pubDate>Wed, 18 Apr 2007 03:30:07 GMT</pubDate>
<description><blockquote>Acegi Security 安全系统</blockquote></description>
<dc:creator>comfort857</dc:creator>
</item>
<item>
<title>Tech Outlook 2007- ZDNet Asia</title>
<link>http://www.zdnetasia.com/specialreport/tech_outlook2007/0,39065225,61985384,00.htm</link>
<guid isPermaLink="true">http://www.zdnetasia.com/specialreport/tech_outlook2007/0,39065225,61985384,00.htm</guid>
<category>spam,security,enterprise</category>
<pubDate>Fri, 02 Mar 2007 10:08:34 GMT</pubDate>
<description><blockquote>Security, say analysts and vendors, will continue to dominate the agenda of enterprises in 2007.</blockquote></description>
<dc:creator>longrujun</dc:creator>
</item>
<item>
<title>Windows Vista Security : An Introduction to Kernel Patch Protection</title>
<link>http://blogs.msdn.com/windowsvistasecurity/archive/2006/08/11/695993.aspx</link>
<guid isPermaLink="true">http://blogs.msdn.com/windowsvistasecurity/archive/2006/08/11/695993.aspx</guid>
<category>Vista,Security</category>
<pubDate>Wed, 17 Jan 2007 01:34:47 GMT</pubDate>
<description><blockquote>Hello, I'm Scott Field, an Architect working on Windows Kernel Security. There have been a lot of questions recently about a Windows technology called Kernel Patch Protection (sometimes referred to as PatchGuard) so I wanted to provide some context about the feature to help answer them.  OS kernel design is a very specialized area of computer science that rarely receives a lot of public attention, so it's understandable that there are a lot of questions out there. The purpose of this post is to give a basic primer on Kernel Patch Protection and why it is an important technology to increase the security and reliability of Windows-based PCs.</blockquote></description>
<dc:creator>laiyiling</dc:creator>
</item>
<item>
<title>黑客调试技术揭秘 - 免费试读 - book.csdn.net</title>
<link>http://book.csdn.net/bookfiles/101/</link>
<guid isPermaLink="true">http://book.csdn.net/bookfiles/101/</guid>
<category>book,security</category>
<pubDate>Fri, 05 Jan 2007 16:21:17 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>axiuluo</dc:creator>
</item>
<item>
<title>计算机安全学——安全的艺术与科学 - book.csdn.net</title>
<link>http://club.book.csdn.net/book/29207.html</link>
<guid isPermaLink="true">http://club.book.csdn.net/book/29207.html</guid>
<category>SECURITY</category>
<pubDate>Sun, 24 Dec 2006 13:47:36 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>lxs85</dc:creator>
</item>
<item>
<title>Google代码搜索：漏洞的汇集？</title>
<link>http://news.csdn.net/n/20061214/99388.html</link>
<guid isPermaLink="true">http://news.csdn.net/n/20061214/99388.html</guid>
<category>Search,google,OpenSource,Security</category>
<pubDate>Thu, 14 Dec 2006 15:39:14 GMT</pubDate>
<description><blockquote>“gets()”函数的例子仅仅是使用Google代码搜索能够找到的这类问题的一个例子。著名安全研究人员Dug Song和Aaron Campbell在博客中指出，Google代码搜索能够用来发现十几种不同的安全漏洞，包括某些缓存溢出状况，格式串漏洞、off-by-one错误等等。

在近期，Google代码搜索将帮助开发人员找到和修复能够导致严重安全漏洞的编写不佳的代码。从长远看，Google代码搜索将改善安全状况，因为这项功能提供了一个令人难以置信的查看代码的功能强大的方法。然而，近期的发展是非常不平坦的，因为在其它团体努力修复漏洞的时候，坏蛋们也在挖掘安全漏洞。</blockquote></description>
<dc:creator>zdg</dc:creator>
</item>
<item>
<title>MSN的监听与反监听 - 网络 人生 学习 进步 - CSDNBlog</title>
<link>http://blog.csdn.net/WAST/archive/2006/12/13/1441182.aspx</link>
<guid isPermaLink="true">http://blog.csdn.net/WAST/archive/2006/12/13/1441182.aspx</guid>
<category>security</category>
<pubDate>Thu, 14 Dec 2006 02:32:39 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>scz123</dc:creator>
</item>
<item>
<title>微软推出Anti-Cross Site Scripting Library V1.5</title>
<link>http://blog.joycode.com/saucer/archive/2006/11/21/87365.aspx</link>
<guid isPermaLink="true">http://blog.joycode.com/saucer/archive/2006/11/21/87365.aspx</guid>
<category>Tools,Security,.NET开发</category>
<pubDate>Mon, 27 Nov 2006 09:31:01 GMT</pubDate>
<description><blockquote>根据 ACE Team 博客，你应该升级到这个版本的五大理由是：
1。更多的Encoding方法，除了HtmlEncode和UrlEncode方法外，这个版本还提供了HtmlAttributeEncode，JavaScriptEncode，VisualBasicScriptEncode，XmlEncode，XmlAttributeEncode 5个方法！
2。对Partially Trusted Caller Attribute (PTCA)的支持
3。大为改进的文档，例程和实用教程
4。End User License Agreement (EULA)更为清晰和灵活
5。升级路径极其容易，因为这个版本里仍然支持旧的命名空间</blockquote></description>
<dc:creator>zdg</dc:creator>
</item>
<item>
<title>20 ways to Secure your Apache Configuration</title>
<link>http://www.petefreitag.com/item/505.cfm</link>
<guid isPermaLink="true">http://www.petefreitag.com/item/505.cfm</guid>
<category>Apache,Security</category>
<pubDate>Thu, 09 Nov 2006 15:36:19 GMT</pubDate>
<description><blockquote>20 ways to Secure your Apache Configuration</blockquote></description>
<dc:creator>longrujun</dc:creator>
</item>
<item>
<title>Tools : ReverseDOS.Home</title>
<link>http://www.angrypets.com/tools/rdos/</link>
<guid isPermaLink="true">http://www.angrypets.com/tools/rdos/</guid>
<category>Security,DDOS,HttpModule</category>
<pubDate>Tue, 31 Oct 2006 11:16:47 GMT</pubDate>
<description><blockquote>ReverseDOS is a very simple HttpModule that checks various parts of incoming requests against a list of crap that you don't want pushed on to your site. If ReverseDOS detects a match, it attempts to stall the requesting client for a number of seconds (specified in a .config file). During this loop, which uses virtually no server resources - and only a tiny smidgen of bandwidth, ReverseDOS checks every .3 seconds to see if the client is still connected. If the spammer disconnects, good riddance. If the spammer sticks around, they're finally rewarded with the Response Headers - containing an HTTP 403 - Access Denied Response Code. (Awwwhh tooo bad...)</blockquote></description>
<dc:creator>zdg</dc:creator>
</item>
<item>
<title>如何使用代码设置一个windows帐户“作为服务登录”</title>
<link>http://community.csdn.net/Expert/TopicView3.asp?id=4851451</link>
<guid isPermaLink="true">http://community.csdn.net/Expert/TopicView3.asp?id=4851451</guid>
<category>local,policy,IPSec,RSoP,Group,Policy,DumpSec,ntrights.exe,SeServiceLogonRight,Local,Security,Authority,LsaAddAccountRights,LsaEnumerateAccountsWithUserRight</category>
<pubDate>Wed, 25 Oct 2006 16:21:01 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>jiangsheng</dc:creator>
</item>
<item>
<title>Extending Task Manager with DLL Injection</title>
<link>http://www.codeproject.com/threads/taskex.asp</link>
<guid isPermaLink="true">http://www.codeproject.com/threads/taskex.asp</guid>
<category>UI,security</category>
<pubDate>Mon, 17 Apr 2006 21:07:28 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>jiangsheng</dc:creator>
</item>
<item>
<title>博客园 - 二十四画生的Blog - 详解对密码执行散列和 salt 运算方法</title>
<link>http://www.cnblogs.com/esshs/archive/2005/03/29/127998.html</link>
<guid isPermaLink="true">http://www.cnblogs.com/esshs/archive/2005/03/29/127998.html</guid>
<category>asp.net,security</category>
<pubDate>Mon, 07 Nov 2005 15:59:00 GMT</pubDate>
<description><blockquote>大家对密码执行散列和Salt运算一定不陌生。两个Visual Studio企业版示例都是用的这个方法来加密这个方法的。结合示例代码，我总结了一个包含对密码进行加密，比较等静态方法的类。使用说明：先用HashAndSalt方法对密码进行加密，然后存储到数据库中。在用户登录时用ComparePasswords方法在对用户输入的密码和用户注册时存储在数据库中的密码进行比较，判断用户输入的密码是否正确。</blockquote></description>
<dc:creator>tianhao960</dc:creator>
</item>
<item>
<title>Storing Passwords - done right!</title>
<link>http://www.aspheute.com/english/20040105.asp</link>
<guid isPermaLink="true">http://www.aspheute.com/english/20040105.asp</guid>
<category>asp.net,security</category>
<pubDate>Mon, 07 Nov 2005 14:51:04 GMT</pubDate>
<description><blockquote>Storing Passwords - done right!</blockquote></description>
<dc:creator>tianhao960</dc:creator>
</item>
<item>
<title>Ten hacker tricks to exploit SQL Server systems</title>
<link>http://searchsqlserver.techtarget.com/tip/1,289483,sid87_gci1165052_tax301336,00.html?Offer=SQLwnha217</link>
<guid isPermaLink="true">http://searchsqlserver.techtarget.com/tip/1,289483,sid87_gci1165052_tax301336,00.html?Offer=SQLwnha217</guid>
<category>Security,SQLServer</category>
<pubDate>Tue, 21 Mar 2006 10:47:35 GMT</pubDate>
<description><blockquote>Whether it is through manual poking and prodding or the use of security testing tools, malicious attackers employ a variety of tricks to break into SQL Server systems, both inside and outside your firewall. It stands to reason then, if the hackers are doing it, you need to carry the same attacks to test the security strength of your systems. Here are 10 hacker tricks to gain access and violate systems running SQL Server.</blockquote></description>
<dc:creator>zdg</dc:creator>
</item>
<item>
<title>建立隐藏的超级用户多种方法 华夏黑客同盟 - http://www.77169.org</title>
<link>http://www.77169.org/Article/Class33/Class34/200501/14138.html</link>
<guid isPermaLink="true">http://www.77169.org/Article/Class33/Class34/200501/14138.html</guid>
<category>IT,Security</category>
<pubDate>Wed, 29 Jun 2005 12:37:29 GMT</pubDate>
<description><blockquote></blockquote></description>
<dc:creator>longrujun</dc:creator>
</item>
<item>
<title>超级黑客 Kevin Mitnick 网站被黑</title>
<link>http://www.wangtam.com/50226711/ece_kevin_mitnick_ccee_40675.php</link>
<guid isPermaLink="true">http://www.wangtam.com/50226711/ece_kevin_mitnick_ccee_40675.php</guid>
<category>黑客,Security</category>
<pubDate>Wed, 23 Aug 2006 14:45:33 GMT</pubDate>
<description><blockquote>Kevin Mitnick 的黑客生涯可谓充满传奇，在1995年2月被捕入狱服刑四年半之前，美国国防部、五角大楼、中央情报局、北美防空系统、美国国家税务局、纽约花旗银行、Sun、摩托罗拉等都曾是他闲庭信步的地方，&quot;社会工程学&quot;也成了后来黑客模仿的典范，无数的黑客书籍以敬畏的口吻崇拜着他。</blockquote></description>
<dc:creator>zdg</dc:creator>
</item>
<item>
<title>英《金融时报》：雅虎MySpace轮番遇袭 Web2.0成黑客温床 雅虎 MySpace Web2.0</title>
<link>http://news.csdn.net/n/20060814/93662.html</link>
<guid isPermaLink="true">http://news.csdn.net/n/20060814/93662.html</guid>
<category>web2.0,ajax,javascript,病毒,Security</category>
<pubDate>Mon, 14 Aug 2006 15:40:16 GMT</pubDate>
<description><blockquote>“你必须培训开发人员，”SPI的霍夫曼先生说。“围绕Ajax的炒作正导致一个问题：人们看到了MySpace的成功而纷纷采用Ajax技术。他们24小时内读完一本如何学会Ajax的书，然后创建一个存在安全隐忧的网站。”</blockquote></description>
<dc:creator>zdg</dc:creator>
</item>
<item>
<title>Whitepapers</title>
<link>http://www.xfocus.org/honeynet/papers/</link>
<guid isPermaLink="true">http://www.xfocus.org/honeynet/papers/</guid>
<category>Security</category>
<pubDate>Sat, 24 Jun 2006 17:37:23 GMT</pubDate>
<description><blockquote>这些论文是Honeynet项目的成果。它们讨论了入侵者团体的工具，手段和动机。</blockquote></description>
<dc:creator>zdg</dc:creator>
</item>
<item>
<title>利用 ASP.NET 的内置功能抵御 Web 攻击</title>
<link>http://blog.csdn.net/yjz0065/archive/2006/04/24/674758.aspx</link>
<guid isPermaLink="true">http://blog.csdn.net/yjz0065/archive/2006/04/24/674758.aspx</guid>
<category>.NET开发,Security</category>
<pubDate>Mon, 24 Apr 2006 11:12:56 GMT</pubDate>
<description><blockquote>ASP.NET 应用程序与其他 Web 应用程序相较，既不更易受攻击，也不更安全。安全性和漏洞同样根植于编码实践、实际经验和团队合作。如果网络不安全，那么任何应用程序都不安全；类似地，无论网络如何安全，管理如何精良，如果应用程序存在缺陷，攻击者总是能够得手。ASP.NET 的好处是提供了一些好的工具，只需少量工作，就可以将安全标准提升到可以接受的级别。当然，这并不是 足够高的级别。不应纯粹以来 ASP.NET 的内置解决方案，同样也不应忽视它们。尽可能多地了解常见的攻击。</blockquote></description>
<dc:creator>zdg</dc:creator>
</item>
<item>
<title>十个探测SQL Server 2000漏洞的技巧或工具</title>
<link>http://www.dotnettools.org/Blog/article.asp?id=112</link>
<guid isPermaLink="true">http://www.dotnettools.org/Blog/article.asp?id=112</guid>
<category>SQLServer,Security</category>
<pubDate>Tue, 21 Mar 2006 10:46:14 GMT</pubDate>
<description><blockquote>看到这篇文章之后，感觉到每个SQL Server 2000都有可以&quot;挖掘&quot;和&quot;探索&quot;的漏洞(还好现在用SQL Server 2005居多)，告诫自己以后每次部署SQL Server 2000/2005的时候，都要从这些工具箱中选出几个，试一下。SQL injection 无处不在，要时刻保持安全警惕性。</blockquote></description>
<dc:creator>zdg</dc:creator>
</item>
</channel></rss>
