ค้นหาบทความ

โพสต์แนะนำ

ย้าย Blog ไปที่ TechDiary

วันศุกร์ที่ 10 สิงหาคม พ.ศ. 2555

Hacker อิหร่าน ถล่มเว็บอิสราเอล



แฮ็กเกอร์รายหนึ่งที่ใช้ชื่อแทนตัวเองว่า You-r!-k@n  อ้างว่าได้ทำการแฮ็ก และเปลี่ยนแปลงหน้าเว็บไซต์ต่างๆ จำนวน 91 เว็บ ซึ่งเป็นเว็บของหน่วยงานรัฐ หน่วยงานการศึกษา และบริษัทเอกชนของอิหร่าน โดยทำไปเพื่อประท้วงรัฐบาลอิหร่านในข้อหา สนับสนุนผู้ก่อการร้าย และสร้างอาวุธนิวเคลียร์เพื่อทำลายอิสราเอล
You-r!-k@n  กล่าวว่า เขาเริ่มด้วยการแทนที่หน้าเว็บไซต์เหล่านั้นด้วยรูปธงชาติอิสราเอล พร้อมกับข้อความ This site is hacked by You-r!-k@n. Say no to terror. Say no to nuclear Iran.แปลว่า อิหร่านจงอย่ายุงกับผู้ก่อการร้าย อย่ายุ่งกับนิวเคลียร์ จากนั้นก็ทำการลบเว็บทั้งหมดทิ้ง จากข้อมูลจากอีเมล์ที่เขาได้ส่งให้ InfoWorld และ InfoSec Island กล่าวว่า เว็บไซต์ทั้งหมดได้ถูกลบไปแล้ววันนี้ (del *.*:-) ฉันมี console backdoor ติดตั้งไว้บน server ด้วย DNS และ web server ไม่มีอีกต่อไปแล้ว แต่ทว่า เขาก็ไม่ได้ให้รายชื่อเว็บทั้งหมดที่เขาแฮ็ก แต่ชื่อเว็บทั้งหมดที่เข้าเอ่ยถึง ไม่สามารเข้าไปดูได้ในขณะเขียนเรื่องนี้

นอกจากนี้ยังมีข้อความโต้ตอบทางอีเมล์กับ InfoWorld ดังนี้
InforWorld: คุณใช้เวลานานเท่าไหร่ในการจัดการกับเว็บทั้ง 91 แห่ง ตั้งแต่เริ่มวางแผน จนสำเร็จทั้งหมด
You-r!-k@n: ประมาณ 3 วัน

InfoWorld: คิดว่าง่าย หรือยากกว่าที่คิดในการแฮ็กเว็บทั้งหมดนั้น?
You-r!-k@n: ไม่ได้ยากที่สุดตั้งแต่ที่เคยทำมา อันที่ยากที่สุดสำหรับผมคือที่ irimo.ir (หน่วยงานอุตุนิยมของอิหร่านที่เจาะในเดือน พ.ค.) ซึ่งใช้เวลาถึง 2 เดือน ผมวางแผนที่จะยกระดับสิทธิ์จากผู้เข้าชมเว็บทั่วไป ให้กลายเป็นผู้จัดการระบบโดเมนทั้งโดเมน มันเป็นโดเมนใหญ่ ครอบคลุมเว็บสัก 2-3 เว็บได้ จากนั้นก็ลบ AD ทั้งหมดทิ้ง ทำให้พวกเขาใช้เวลาเป็นอาทิตย์ กว่าจะกู้กลับมาได้ แต่รับรองว่ากู้ได้ไม่หมดหรอก

InfoWorld: เว็บเหล่านี้มีจุดอ่อนเรื่องความปลอดภัยใช่มั้ย? คุณแปลกใจกับจุดอ่อนต่างๆ ที่คุณเจอหรือเปล่า?
You-r!-k@n: อืมคือผมก็ไม่ใช่มือใหม่ ผมเลยไม่แปลกใจเท่าไหร่ มันเป็นการโจมตีแบบเป็นขั้นเป็นตอน เริ่มจาก SQL Injection เข้าไปในหน้าของผู้ดูแลเว็บ เพื่อหาจุดอ่อน เพื่อให้ผมอัพโหลดไฟล์ ASP เข้าไปได้ จากนั้นก็เข้า command promt และยกระดับสิทธิ์ของตัวเอง จากนั้นก็ port fun J และแล้วก็ได้เป็น Admin

InfoWorld: คุณยกตัวอย่างสักเรื่องสองเรื่องให้ฟังได้มั้ยว่าคุณได้ใช้ social engineering ยังไงบ้าง?
You-r!-k@n: อืม.. มีบริษัทของอิหร่านแห่งหนึ่ง ที่ผมได้แฮ็กอีเมล์อันนึง จากนั้น ส่งอีเมล์หาเพื่อนร่วมงานของคนๆ นั้น โดยใช้ข้อความว่า เจ๋ง ลองดูนี่สิ http://xxx.xxx.xxx.xx” มันเป็น URL หลอก เพื่อจะทำการติดตั้ง malware บน mail server แค่คลิกลิงค์ พวกเขาก็เสร็จ

InfoWorld: เห็นคุณบอกในข้อความแรกของคุณว่า เจ้าของเว็บไซต์จะต้องสร้างเว็บขึ้นมาใหม่หมดตั้งแต่ต้น คุณแน่ใจเหรอว่าพวกเข้าจะไม่มีไฟล์สำรอง?
You-r!-k@n: ผมไม่แน่ใจหรอกว่าพวกเขามีไฟล์สำรองหรือเปล่า แต่ถึงจะมี ก็ไม่รู้ว่าจะอัพเดทล่าสุดหรือเปล่า ปัญหาใหญ่ที่สุดของพวกเขาคือหาจุดอ่อนให้เจอ เพาระถ้าไม่ปิดจุดอ่อนนั้น ถึงจะเอาไฟล์สำรองมาแทน ผมก็เข้าไปอีกได้อยู่ดี

InfoWorld: ถ้าคุณทำความเสียหายให้เว็บตั้ง 91 เว็บได้ คุณคิดว่าจะมีคนที่มีฝีมือพอกันมาทำแบบนี้กับอิสราเอล สหรัฐฯ หรือว่าประเทศอื่นมั้ย?
You-r!-k@n: สิ่งที่ผมมั่นใจคือ ในอิสราเอลเอง และทุกๆ ประเทศทั่วโลก ก็มี server ที่มีจุดอ่อนอยู่ทั้งนั้นแหละ


แปลจาก InfoWorld.com

วันศุกร์ที่ 13 กรกฎาคม พ.ศ. 2555

.NET WinForm แก้ฟอร์ม กระพริบ ถ้ามี control เยอะๆ

ในกรณีที่ form มี control เยอะๆ (หรือ form ทีรูปเป็น background หรือมี TabControl ใน form) การเปิด form หรือ สลับ form ไปมา อาจจะทำให้เกิดการกระพริบของ control ต่างๆ ได้ ถึงแม้จะให้ Double Buffer เป็น true แล้วก็ตาม นี่คือโค้ด การ override property ของ form ที่ชื่อว่า CreateParams


ปกติแล้วเวลา form (หรือ control อื่นๆ) ทำการ update ตัวเอง (Paint) มันจะวาดทับพื้นที่ทั้งหมดของตัวเอง แล้ว วาด control ที่อยู่ในตัวมันใหม่อีกที ทำให้หากมี control เยอะๆ จะเกิดการกระพริบในการวาด
ตัวเลข style ที่เป็นเลข &H2000000 ก็คือ style ที่ชื่อว่า WS_CLIPCONTROLS เป็นการบอกว่า ให้วาดเฉพาะส่วนที่ไม่มี control อื่นๆ อยู่เท่านั้น จึงทำให้การวาด (paint) เร็วขึ้น



Protected Overrides ReadOnly Property CreateParams() As _
System.Windows.Forms.CreateParams
        Get
            Dim cp As CreateParams = MyBase.CreateParams
            Dim OSVer As Version = _
            System.Environment.OSVersion.Version()


            Select Case OSVer.Major
                Case 5
                    If OSVer.Minor > 0 Then
                        cp.ExStyle = cp.ExStyle Or &H2000000
                    End If
                Case Is > 5
                    cp.ExStyle = cp.ExStyle Or &H2000000
            End Select


            Return cp


        End Get
End Property


สาเหตุที่ต้องตรวจสอบ version ของ windows เนื่องจากใน Windows ที่ต่ำกว่า XP จะทำให้ form แบบ MDI กิน cpu มาก จนทำให้โปรแกรมแฮงก์ได้


Credit: 
Stuart Blackler@http://sblackler.net
Marius Bancila@http://www.codeguru.com



วันอังคารที่ 10 กรกฎาคม พ.ศ. 2555

Bye bye Thunder Bird

Mozilla plans to let go of its open-source e-mail software, with hopes that other people will keep Thunderbird alive, TechCrunch says.

Read more: download.cnet.com

วันศุกร์ที่ 1 มิถุนายน พ.ศ. 2555

ฟังก์ชั่น Excel VBA SaveAs dialog และเขียน TextFile


Sub WriteFile(fname As String, txt As String)     'เขียน Text File
    Dim fso As New FileSystemObject
    Dim stream As TextStream


    Set stream = fso.CreateTextFile(fname, True)
    stream.Write (txt)
    stream.Close
End Sub


Function SaveDialog() As String       'เปิด Dialog ถามชื่อ File
    Dim ret As String


    ret = Application.GetSaveAsFilename("Output.xml", _
          "XML files (*.xml),*.xml", 1, "Save XML Output")


    If ret <> "False" Then
        SaveDialog = ret
    End If
End Function


ถ้าจะใช้ FileSystemObject ต้อง reference Microsoft Scripting Runtime ด้วย โดยในหน้า VB ไปที่ Tool -> References...

MS Excel: Format Function


MS Excel: Format Function with Strings (VBA only)


In Excel, the Format function takes an expression and returns it as a formatted string.
The syntax for the Format function is:
Format ( expression, [ format ] )
expression is the value to format.
format is optional. It is the format to apply to the expression. You can either define your own format or use one of the named formats that Excel has predefined such as:
FormatExplanation
General NumberDisplays a number without thousand separators.
CurrencyDisplays thousand separators as well as two decimal places.
FixedDisplays at least one digit to the left of the decimal place and two digits to the right of the decimal place.
StandardDisplays the thousand separators, at least one digit to the left of the decimal place, and two digits to the right of the decimal place.
PercentDisplays a percent value - that is, a number multiplied by 100 with a percent sign. Displays two digits to the right of the decimal place.
ScientificScientific notation.
Yes/NoDisplays No if the number is 0. Displays Yes if the number is not 0.
True/FalseDisplays True if the number is 0. Displays False if the number is not 0.
On/OffDisplays Off if the number is 0. Displays On is the number is not 0.
General DateDisplays date based on your system settings
Long DateDisplays date based on your system's long date setting
Medium DateDisplays date based on your system's medium date setting
Short DateDisplays date based on your system's short date setting
Long TimeDisplays time based on your system's long time setting
Medium TimeDisplays time based on your system's medium time setting
Short TimeDisplays time based on your system's short time setting

Applies To:

  • Excel 2007, Excel 2003, Excel XP, Excel 2000

For Example:

Format("210.6", "#,##0.00")would return '210.60'
Format("210.6", "Standard")would return '210.60'
Format("0.981", "Percent")would return '98.10%'
Format("1267.5", "Currency")would return '$1,267.50'
Format("Sep 3, 2003", "Short Date")would return '9/3/2003'

VBA Code:

The Format function can only be used in VBA code. For example:
Dim LValue As String
LValue = Format("0.981", "Percent")
In this example, the variable called LValue would now contain the value of '98.10%'.