About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Technology
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it
Go Back   Community > Technology > Network (in)Security
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net.

Reply
 
Thread Tools Display Modes
  #1   Add warweed12 to your ignore list  
Old 2008-12-09, 01:31
warweed12 warweed12 is offline
Moderator
 
directly over the center of the earth Send a message via MSN to warweed12
Default SQL Injection Pt. 2

Since i got so much popularity in the first thread i think i may start creating a few more mods please lock the first thread

im looking for a good candidate site for SQL injection pt2. with a difficultiy level of easy hopefully a simple forum injection anyone have anything the wish to share ?

for those of you who are into advance challanges here is one for you

http://store.easypointatm.com i think those who get it will be in for a great surprise
__________________
For a great source of ebooks (on all illegal subjects :P ) and educated disscussion check warweed.com
Reply With Quote
  #2   Add wargsm to your ignore list  
Old 2008-12-09, 02:11
wargsm wargsm is offline
Regular
 
Unspecifiedistan.
Default Re: SQL Injection Pt. 2

http://www.scdl.net/studentcentre.asp
http://www.psychiatrist.com/
Reply With Quote
  #3   Add Shoplifter to your ignore list  
Old 2008-12-09, 02:17
Shoplifter Shoplifter is offline
Regular
 
Administrator
Default Re: SQL Injection Pt. 2

I got this for the warweed's:

http://upload-fast.com/files/f22e2de9849bd2eb6d875436be501b82.jpg

For wargasm's first:
http://upload-fast.com/files/db22d5524b261bd2aebc775ca1e34d12.jpg

Last edited by Shoplifter; 2008-12-09 at 02:25.
Reply With Quote
  #4   Add trippson to your ignore list  
Old 2008-12-09, 02:19
trippson trippson is offline
New Arrival
 
Dallas Send a message via AIM to trippson
Default Re: SQL Injection Pt. 2

same here
http://i157.photobucket.com/albums/t45/t1337/Screenshot-1.png
Reply With Quote
  #5   Add Shoplifter to your ignore list  
Old 2008-12-09, 02:31
Shoplifter Shoplifter is offline
Regular
 
Administrator
Default Re: SQL Injection Pt. 2

Super easy one:
http://www.udesa.co.za/admin/login.asp
Reply With Quote
  #6   Add trippson to your ignore list  
Old 2008-12-09, 02:41
trippson trippson is offline
New Arrival
 
Dallas Send a message via AIM to trippson
Default Re: SQL Injection Pt. 2

Quote:
Originally Posted by Shoplifter View Post
Super easy one:
http://www.udesa.co.za/admin/login.asp
http://i157.photobucket.com/albums/t45/t1337/Screenshot-2.png

lol

http://i157.photobucket.com/albums/t45/t1337/Screenshot-3.png

Last edited by trippson; 2008-12-09 at 02:54.
Reply With Quote
  #7   Add Shoplifter to your ignore list  
Old 2008-12-09, 02:47
Shoplifter Shoplifter is offline
Regular
 
Administrator
Default Re: SQL Injection Pt. 2

Quote:
Originally Posted by trippson View Post
Nice, I'll be looking for more.
Reply With Quote
  #8   Add warweed12 to your ignore list  
Old 2008-12-09, 03:42
warweed12 warweed12 is offline
Moderator
 
directly over the center of the earth Send a message via MSN to warweed12
Default Re: SQL Injection Pt. 2

Quote:
Originally Posted by trippson View Post

strange thats not what i have can i ask what string you used
__________________
For a great source of ebooks (on all illegal subjects :P ) and educated disscussion check warweed.com
Reply With Quote
  #9   Add wargsm to your ignore list  
Old 2008-12-09, 15:10
wargsm wargsm is offline
Regular
 
Unspecifiedistan.
Default Re: SQL Injection Pt. 2

Quote:
Originally Posted by Shoplifter View Post

Have a look in the source, I think the passwords are stored in plaintext Thats not the password for his hotmail though, so try changing users. I bet some of them are the same.

This one looks fun:
http://upload-fast.com/files/f87eccd537faa6a94aee6d06c5796d51.JPG

Last edited by wargsm; 2008-12-09 at 15:15.
Reply With Quote
  #10   Add trippson to your ignore list  
Old 2008-12-09, 16:55
trippson trippson is offline
New Arrival
 
Dallas Send a message via AIM to trippson
Default Re: SQL Injection Pt. 2

Quote:
Originally Posted by wargsm View Post
Have a look in the source, I think the passwords are stored in plaintext Thats not the password for his hotmail though, so try changing users. I bet some of them are the same.

This one looks fun:
http://upload-fast.com/files/f87eccd537faa6a94aee6d06c5796d51.JPG
Yeah, it is stored in plain text and i tried to logon to his hotmail too and it said something about an invalid email... but anyways in the first thread the site downeast.ca thier password is stored in cleartext if you look in the source of the page.
Reply With Quote
 #11 
Old 2008-12-09, 18:20
wargsm wargsm is offline
Regular
 
Default Re: SQL Injection Pt. 2

Yeah, it is stored in plain text and i tried to logon to his hotmail too and it said something about an invalid email... but anyways in the first thread the site downeast.ca thier password is stored in cleartext if you look in the source of the page.

Yeah, I managed to get it to recognize the address, password didn't work though. Just need to find out how to change users. I know the command required, but I can't seem to find any other usernames on the site, so will need to DROP the relevant table me thinks. From there change to a different user, and try out their credentials. I imagine psychiatrists would receive some interesting emails :)
 #12 
Old 2008-12-10, 02:53
Regular
 
Chicago
Default Re: SQL Injection Pt. 2

Super easy one:
http://www.udesa.co.za/admin/login.asp

lol did u do the "fuck you" write ins? or was it someone else?
 #13 
Old 2008-12-10, 07:08
Moderator
 
directly over the center of th
Default Re: SQL Injection Pt. 2

ok so most of us who have been following the swl injection forums have gotten all the links anyone else got somthing ?


also i would be intrested in taking this off totse and perhaps moving it to my site so we can play with a few more "controversial" sites ....


would any of you be intrested ? this way we can talk a bit more freely with less traffic ... and i can limit who sees the conversation ....

not so much as a team or army but a group of people who have basic skill who are looking to improve on them selves
 #14 
Old 2008-12-10, 07:14
Moderator
 
The fiber optic lines
Default Re: SQL Injection Pt. 2

Quote:
Originally Posted by warweed12
ok so most of us who have been following the swl injection forums have gotten all the links anyone else got somthing ?


also i would be intrested in taking this off totse and perhaps moving it to my site so we can play with a few more "controversial" sites ....


would any of you be intrested ? this way we can talk a bit more freely with less traffic ... and i can limit who sees the conversation ....

not so much as a team or army but a group of people who have basic skill who are looking to improve on them selves


Tis a good idea. Let's keep conversation about THIS SQL injections stuff here, and we can move the more 'controversial' stuff to your site.
 #15 
Old 2008-12-10, 07:20
Moderator
 
directly over the center of th
Default Re: SQL Injection Pt. 2

sounds like a plan so we shall post easy non harmful crap here and more controversial theoretical and such on my site

you may register on my site at

http://warweed.com/signup.php
and the restricted forum is
http://warweed.com/plugins/forum/forum_viewforum.php?27

please post your warweed.com user name here .... and i shall set your user class within 24 hours so you can veiw the forum of the link i posted above
 #16 
Old 2008-12-10, 08:12
Moderator
 
The fiber optic lines
Default Re: SQL Injection Pt. 2

Mine is the same as it is here.
 #17 
Old 2008-12-10, 10:04
ParkedCar ParkedCar is offline
Regular
 
Default Re: SQL Injection Pt. 2

Ok, I registered at your website. My username at warweed.com is ParkedCar.
 #18 
Old 2008-12-10, 11:14
Regular
 
Default Re: SQL Injection Pt. 2

I think that we should collectivley put information into a large artical, so that poeple can get started, or get help from it. Then can be uploaded to your site.

I still need to do a bit of research SQL injections, I kinda understand the concept (at least the SQL part (After doing a year or on SQL at college). But need some source of information of the basic understanding. What I don't understand is HOW 1' or '1'='1 works in the password feild. or how 100' or '2'='1 still works the same?

But ill do my research and come back to here and tell you what i found out. (for others in the same posistion.

Edit: https://www.criticalsecurity.net/index.php?showtopic=10&pid=66&mode=threaded&start=

Heres a good start guide. I also found with the sql injection of 'down east site' injection can be just[ ' or ' ] which i find wierd.
 #19 
Old 2008-12-10, 11:32
wargsm wargsm is offline
Regular
 
Default Re: SQL Injection Pt. 2

Quote:
Originally Posted by warweed12
sounds like a plan so we shall post easy non harmful crap here and more controversial theoretical and such on my site

you may register on my site at

http://warweed.com/signup.php
and the restricted forum is
http://warweed.com/plugins/forum/forum_viewforum.php?27

please post your warweed.com user name here .... and i shall set your user class within 24 hours so you can veiw the forum of the link i posted above


Yeah, I registered the other night. Made a thread as well.
 #20 
Old 2008-12-10, 16:31
trippson trippson is offline
Regular
 
Default Re: SQL Injection Pt. 2

I registered a while back as trippson, so add me:D
 #21 
Old 2008-12-10, 17:03
Regular
 
Default Re: SQL Injection Pt. 2

Me too as Failedartifact.. though i can already see the forum...
 #22 
Old 2008-12-10, 20:02
Regular
 
Administrator
Default Re: SQL Injection Pt. 2

I registered under the same username.
 #23 
Old 2008-12-10, 23:55
Moderator
 
directly over the center of th
Default Re: SQL Injection Pt. 2

lol you guys depress me lol ... after all this sql crap you guys register on my site probally knowing my passwords are MD5 lol and yet you pick passwords retardedly easy ;) especially Expl0itz lol common least pick somthing semi secure

http://i33.tinypic.com/1zlsr4g.jpg i see j00 ALLLL lawlz
 #24 
Old 2008-12-11, 00:05
wargsm wargsm is offline
Regular
 
Default Re: SQL Injection Pt. 2

Quote:
Originally Posted by warweed12
lol you guys depress me lol ... after all this sql crap you guys register on my site probally knowing my passwords are MD5 lol and yet you pick passwords retardedly easy ;) especially Expl0itz lol common least pick somthing semi secure

http://i33.tinypic.com/1zlsr4g.jpg i see j00 ALLLL lawlz


I deliberately made mine insecure. Well, sort of. I didn't want to use any of my usual passwords, seeing as it's your site, so I just used a random pass. Nothing personal :)
 #25 
Old 2008-12-11, 00:09
Regular
 
Scotland
Default Re: SQL Injection Pt. 2

I've got an account there now .. same name :)
 #26 
Old 2008-12-11, 00:11
Regular
 
Default Re: SQL Injection Pt. 2

HAHHA me too, i thought i would create a really easy password not used before.. We are more clever than you think Warweed!
 #27 
Old 2008-12-11, 01:19
Moderator
 
directly over the center of th
Default Re: SQL Injection Pt. 2

hahaha can't blame me for trying :P
 #28 
Old 2008-12-11, 01:40
Moderator
 
The fiber optic lines
Default Re: SQL Injection Pt. 2

Quote:
Originally Posted by warweed12
hahaha can't blame me for trying :P


Yeah dude... cmon. That might work for the people who don't know better. =)

I can feel password harvesting before it happens. Almost like a sixth sense... lol ;)
 #29 
Old 2008-12-11, 01:44
Moderator
 
directly over the center of th
Default Re: SQL Injection Pt. 2

haha you and me both :P
 #30 
Old 2008-12-11, 01:55
Regular
 
a.K.a Dfg (PK)
Default Re: SQL Injection Pt. 2

I am in,
Dfg <-----


Password isn't that secure :(.

Edit: i did a run on 5 different sites and its ahem....... i hope OP doesn't expose the password :(.

*changes Totse password.
 #31 
Old 2008-12-11, 03:19
Super Moderator
 
In a nuclear crater
Default Re: SQL Injection Pt. 2

i hope OP doesn't expose the password :(.

Well, I know he won't post the password on THIS site, or he'll get banned or demodded. He knows well enough about that. At the very least, he'd get a rather long, hard talk with Zok or acidmelt.
 #32 
Old 2008-12-11, 05:41
Moderator
 
directly over the center of th
Default Re: SQL Injection Pt. 2

i am very much a white hat "hacker" maybe bordline grey hat one thing you have to know is i would never use your passwords without your expressed consent nor would i steal them or harvest them .... i know better then that...

if only you knew how much sensative stuff i have stumbled into that i could have made LARGE sums of money lol

i have alot of morals when it comes to what i do ... but i still like to know i can do somthing and like to learn
 #33 
Old 2008-12-11, 08:46
MaddMan MaddMan is offline
Regular
 
Default Re: SQL Injection Pt. 2

I registered on your site as RadioFree.
 #34 
Old 2008-12-11, 09:37
Regular
 
a.K.a Dfg (PK)
Default Re: SQL Injection Pt. 2

Well, I know he won't post the password on THIS site, or he'll get banned or demodded. He knows well enough about that. At the very least, he'd get a rather long, hard talk with Zok or acidmelt.

I was just pulling his leg ;), but still thanks for the support.

i am very much a white hat "hacker" maybe bordline grey hat one thing you have to know is i would never use your passwords without your expressed consent nor would i steal them or harvest them .... i know better then that...

if only you knew how much sensative stuff i have stumbled into that i could have made LARGE sums of money lol

i have alot of morals when it comes to what i do ... but i still like to know i can do somthing and like to learn

No, don't worry. I just made up the password just for your site. Btw it is one of the strongest password in use right now (by me). I would love it if you can test it out. I mean it will only help me in the long run ;).
 #35 
Old 2008-12-11, 20:34
Moderator
 
directly over the center of th
Default Re: SQL Injection Pt. 2

I don't have any users by "DFG"
 #36 
Old 2008-12-12, 04:28
Roor Roor is offline
Regular
 
Default Re: SQL Injection Pt. 2

Hey warweed, im interested in this SQL injection and im also looking to join your group on your own website. I was referred by trippson who I do know in RL.

Here are some sites that i got into by injection.
http://i409.photobucket.com/albums/pp174/Roorlux/udesa.jpg

http://i409.photobucket.com/albums/pp174/Roorlux/micmac.jpg

I know that they are probably 2 of the easiest sites to get into using the ' or ' code..
 #37 
Old 2008-12-12, 07:58
Regular
 
a.K.a Dfg (PK)
Default Re: SQL Injection Pt. 2

Quote:
Originally Posted by warweed12
I don't have any users by "DFG"


Done, its activated.
 #38 
Old 2008-12-12, 13:12
Regular
 
Scotland
Default Re: SQL Injection Pt. 2

https://www.downeast.ca/admin/B2B/B2BAccountList.asp


teeheehee
 #39 
Old 2008-12-12, 22:58
Moderator
 
directly over the center of th
Default Re: SQL Injection Pt. 2

Quote:
Originally Posted by Roor
Hey warweed, im interested in this SQL injection and im also looking to join your group on your own website. I was referred by trippson who I do know in RL.

Here are some sites that i got into by injection.
http://i409.photobucket.com/albums/pp174/Roorlux/udesa.jpg

http://i409.photobucket.com/albums/pp174/Roorlux/micmac.jpg

I know that they are probably 2 of the easiest sites to get into using the ' or ' code..




down east was the site a posted in my previous thread and i posted the injection and the second one was easyer then fuck ..

do you have anything new you may be able to offer up by chance ?
Reply

Thread Tools
Show Printable Version Show Printable Version
Email this Page Email this Page
Display Modes
Linear Mode Linear Mode
Hybrid Mode Switch to Hybrid Mode
Threaded Mode Switch to Threaded Mode

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump

 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
 

totse.com certificate signatures
 
 
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
Hot Topics