About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Technology
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it
Go Back   Community > Technology > Network (in)Security
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net.

Reply
 
Thread Tools Display Modes
 #1 
Old 2006-03-14, 02:18
naturalbornkilla naturalbornkilla is offline
Regular
 
Default SQL Attacks

I made an absent minded post a while back that is still on the NS&H frontpage about password cracking. It was a very dumb thread and I'll try not to repeat that here.

Ok, I find tons of info. about detecting vulnerabilities with SQL but what I'm having trouble finding is actual SQL attacks that you can use on forms.

Can somebody either help me directly or refer me to a site that is easy to understand for beginners? That is if it isn't against forum policy.
 #2 
Old 2006-03-14, 07:37
robyextreme robyextreme is offline
Regular
 
Default Re: SQL Attacks

Search for SQL Injections.

 #3 
Old 2006-03-14, 22:25
VolatileShiftInPersona VolatileShiftInPersona is offline
Regular
 
Default Re: SQL Attacks

Most of the times a simple "='" in the username and password entry box will do.
 #4 
Old 2006-03-15, 08:43
robyextreme robyextreme is offline
Regular
 
Default Re: SQL Attacks

quote:
Originally posted by VolatileShiftInPersona:
Most of the times a simple "='" in the username and password entry box will do.


I use to do that.. but MySQL and MSSQL patched it.
 #5 
Old 2006-03-16, 01:32
naturalbornkilla naturalbornkilla is offline
Regular
 
Default Re: SQL Attacks

quote:
Originally posted by VolatileShiftInPersona:
Most of the times a simple "='" in the username and password entry box will do.


For bypassing the form?
 #6 
Old 2006-03-18, 23:22
VolatileShiftInPersona VolatileShiftInPersona is offline
Regular
 
Default Re: SQL Attacks

quote:
Originally posted by naturalbornkilla:
For bypassing the form?

Yes.
 #7 
Old 2006-03-19, 00:51
naturalbornkilla naturalbornkilla is offline
Regular
 
Default Re: SQL Attacks

So would a return that looks something like this mean there is a vulnerability?
http://img54.imageshack.us/img54/7464/urine4wt.jpg
 #8 
Old 2006-03-19, 14:49
VolatileShiftInPersona VolatileShiftInPersona is offline
Regular
 
Default Re: SQL Attacks

quote:
Originally posted by naturalbornkilla:
So would a return that looks something like this mean there is a vulnerability?
[URL=http: //img54.im ageshack.u s/img54/74 64/urine4w t.jpg]http ://img54.i mageshack. us/img54/7464/urine4wt.jpg[/URL]



Yes.
 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
 

totse.com certificate signatures
 
 
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
Hot Topics