<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2461450919879731356</id><updated>2012-01-24T12:19:34.514-08:00</updated><category term='SQL INJECTION'/><category term='Não Importante'/><title type='text'>JM4N</title><subtitle type='html'>- C8H10N4O2</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://chaossecurity.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2461450919879731356/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://chaossecurity.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Redator Admin</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/-6pDBr88egdY/TrGrx1KS6QI/AAAAAAAAAcE/ye9gDaJiic4/s220/twitter.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2461450919879731356.post-6574462004165829299</id><published>2012-01-23T07:47:00.000-08:00</published><updated>2012-01-23T08:03:14.863-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SQL INJECTION'/><title type='text'>Achando vulnerabilidade a SQL Injection sem Havij</title><content type='html'>&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;SQL Injection só é possível quando o site te informa qual o erro que o banco de dados caso não seja possível fazer a consulta no banco de dados.&lt;/span&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;Por exemplo:&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;b style="color: red; font-family: 'Courier New', Courier, monospace;"&gt;&amp;lt;?php&lt;/b&gt;&lt;br /&gt;&lt;span style="color: red; font-family: 'Courier New', Courier, monospace;"&gt;&lt;b&gt;$id = $_GET['id'];&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red; font-family: 'Courier New', Courier, monospace;"&gt;&lt;b&gt;$q = "SELECT * FROM noticias WHERE id = '$id'";&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red; font-family: 'Courier New', Courier, monospace;"&gt;&lt;b&gt;$r = mysql_query($q) or die(mysql_error());&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red; font-family: 'Courier New', Courier, monospace;"&gt;&lt;b&gt;?&amp;gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;Como vimos ali, caso não seja possível enviar a consulta ao MySQL, o script é interrompido exibindo a mensagem de erro da operação enviada ao MySQL.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;Se eu entrar em &lt;b&gt;&lt;span style="color: red;"&gt;http://www.fvox.com/noticias.php?id=10%27&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;(lembrando que&lt;b&gt; %27&lt;/b&gt; equivale a uma aspa simples ').&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;A query a ser enviada seria a seguinte:&lt;/span&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="color: red; font-family: 'Courier New', Courier, monospace;"&gt;SELECT * FROM noticias WHERE id = '10''&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;A aspa inserida na URL iria modificar a sintaxe da consulta, então a função &lt;b&gt;mysql_error()&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;retornaria algo parecido com:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red; font-family: 'Courier New', Courier, monospace;"&gt;&lt;b&gt;Warning: mysql_fetch_array(): supplied argument is not a valid MySQL result resource in (LOCAL DA VULNERABILIDADE) on line 4&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;É claro que o servidor pode emitir outros erros, mas desde que exiba um erro, já é&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;alguma coisa para que você possa realizar seus &lt;b&gt;PENTESTS&lt;/b&gt; com grande esperança, o que te motiva bastante.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2461450919879731356-6574462004165829299?l=chaossecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chaossecurity.blogspot.com/feeds/6574462004165829299/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2461450919879731356&amp;postID=6574462004165829299&amp;isPopup=true' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2461450919879731356/posts/default/6574462004165829299'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2461450919879731356/posts/default/6574462004165829299'/><link rel='alternate' type='text/html' href='http://chaossecurity.blogspot.com/2012/01/achando-vulnerabilidade-sql-injection.html' title='Achando vulnerabilidade a SQL Injection sem Havij'/><author><name>Redator Admin</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/-6pDBr88egdY/TrGrx1KS6QI/AAAAAAAAAcE/ye9gDaJiic4/s220/twitter.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2461450919879731356.post-7204273123318650581</id><published>2012-01-21T10:13:00.000-08:00</published><updated>2012-01-23T08:08:30.023-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Não Importante'/><title type='text'>Apresentação</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;Sou Jm4n e resolvi cria um blog pra posta, algo sobre sql injection attacks, sites vulneráveis, e coisas do tipo&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;div class="separator" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em; text-align: center;"&gt;&lt;img border="0" src="https://si0.twimg.com/profile_images/1720839588/jman.jpg" /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;&lt;b&gt;Aguardem&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;Sigam:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;a href="https://twitter.com/jm4n_" target="_blank"&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;@JM4N_&lt;/span&gt;&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;a href="https://twitter.com/ls098ms_" target="_blank"&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;@LS098MS_&lt;/span&gt;&lt;/a&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;Parceiros:&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;a href="https://twitter.com/the_fernandinho" target="_blank"&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;@The_Fernandinho&lt;/span&gt;&lt;/a&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;a href="https://twitter.com/lucas_walter" target="_blank"&gt;&lt;span style="font-family: 'Courier New', Courier, monospace;"&gt;@Lucas_Walter&lt;/span&gt;&lt;/a&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2461450919879731356-7204273123318650581?l=chaossecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://chaossecurity.blogspot.com/feeds/7204273123318650581/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2461450919879731356&amp;postID=7204273123318650581&amp;isPopup=true' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2461450919879731356/posts/default/7204273123318650581'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2461450919879731356/posts/default/7204273123318650581'/><link rel='alternate' type='text/html' href='http://chaossecurity.blogspot.com/2012/01/primeiro-post.html' title='Apresentação'/><author><name>Redator Admin</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/-6pDBr88egdY/TrGrx1KS6QI/AAAAAAAAAcE/ye9gDaJiic4/s220/twitter.jpg'/></author><thr:total>0</thr:total></entry></feed>
