|
|
 |
 |
 |
 |
register |
bbs |
search |
rss |
faq |
about
|
 |
 |
meet up |
add to del.icio.us |
digg it
|
 |
 |
| Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net. |
 |
|
|
#1
 2006-03-14, 02:18
|
naturalbornkilla 
Regular
|
|
|
|
SQL Attacks
I made an absent minded post a while back that is still on the NS&H frontpage about password cracking. It was a very dumb thread and I'll try not to repeat that here.
Ok, I find tons of info. about detecting vulnerabilities with SQL but what I'm having trouble finding is actual SQL attacks that you can use on forms.
Can somebody either help me directly or refer me to a site that is easy to understand for beginners? That is if it isn't against forum policy.
|
|
#2
 2006-03-14, 07:37
|
robyextreme 
Regular
|
|
|
|
Re: SQL Attacks
Search for SQL Injections.
|
|
#3
 2006-03-14, 22:25
|
VolatileShiftInPersona 
Regular
|
|
|
|
Re: SQL Attacks
Most of the times a simple "='" in the username and password entry box will do.
|
|
#4
 2006-03-15, 08:43
|
robyextreme 
Regular
|
|
|
|
Re: SQL Attacks
quote: Originally posted by VolatileShiftInPersona: Most of the times a simple "='" in the username and password entry box will do.
I use to do that.. but MySQL and MSSQL patched it.
|
|
#5
 2006-03-16, 01:32
|
naturalbornkilla 
Regular
|
|
|
|
Re: SQL Attacks
quote: Originally posted by VolatileShiftInPersona: Most of the times a simple "='" in the username and password entry box will do.
For bypassing the form?
|
|
#6
 2006-03-18, 23:22
|
VolatileShiftInPersona 
Regular
|
|
|
|
Re: SQL Attacks
quote: Originally posted by naturalbornkilla: For bypassing the form?
Yes.
|
|
#7
 2006-03-19, 00:51
|
naturalbornkilla 
Regular
|
|
|
|
Re: SQL Attacks
So would a return that looks something like this mean there is a vulnerability? http://img54.imageshack.us/img54/7464/urine4wt.jpg
|
|
#8
 2006-03-19, 14:49
|
VolatileShiftInPersona 
Regular
|
|
|
|
Re: SQL Attacks
quote: Originally posted by naturalbornkilla: So would a return that looks something like this mean there is a vulnerability? [URL=http: //img54.im ageshack.u s/img54/74 64/urine4w t.jpg]http ://img54.i mageshack. us/img54/7464/urine4wt.jpg[/URL]
Yes.
|
|
 |
 |
To the best of our knowledge, the text on this page may be freely reproduced and distributed.

totse.com certificate signatures
|
 |
 |
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
|
 |
 |
 |
 |
|
|