  | 
	 | 
	  | 
 
 
    
        
          
              
                
                    
                      
                          
                            
                            
	
	
		  | 
		 | 
	 
	
		  | 
		IT Security and Insecurity Portal | 
	 
	 
	 | 
 
 
 
	 | 
 
	
	
		
		
			
			
				
				| Oilik |  
				 |  
				| Replies: 0 |  
				| Views: 5294 |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			Hello, I really need a brute forcer that supports SHA-1, and salts that are sha1(username.password) for SMF 1.1.4. I need this ASAP because I think he's on to me.
 Thanks,
 Ryan
 
 
 Edit: Nevermind,  ... | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
		
			
			
				
				| Oilik |  
				 |  
				| Replies: 3 |  
				| Views: 8625 |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			sry for the double post, but I tried
 
 0'+(SELECT COUNT(*) FROM mysql.user));--
 
 
 and got
 
 An Error Was Encountered
 Error Number: 
 
 ERROR: schema "mysql" ... | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
		
			
			
				
				| Oilik |  
				 |  
				| Replies: 3 |  
				| Views: 8625 |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			edit:  still exists,
 but when I try that, I get
 
 ERROR: unterminated /* comment at or near "/* ') " LINE 2: ...ES ('48767', '1','0'+(SELECT COUNT(*) FROM mysql.user)/* ') ^
 thanks! | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
		
			
			
				
				| Oilik |  
				 |  
				| Replies: 3 |  
				| Views: 8625 |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			Hello,
 I found a potential SQL injection in an extremely popular large site. When I inject code in it, I get:
 
 
 result = 20276
 An Error Was Encountered
 
 Error Number:
 
 ERROR: syntax error at  ... | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
		
			
			
				
				| Oilik |  
				 |  
				| Replies: 3 |  
				| Views: 10504 |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			| 6b7b655dd22faa3f10677c512493a8a0 = eclipse | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
		
			
			
				
				| Oilik |  
				 |  
				| Replies: 5 |  
				| Views: 9933 |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			mr Oilik thank you full for help    
 
 but how can get another methode for hack this site 
 
 and I cannot get name and  version this script
 
 I'm looking on view source nothing name script 
 
  ... | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
		
			
			
				
				| Oilik |  
				 |  
				| Replies: 5 |  
				| Views: 9933 |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			I want ask any body here if this MySQL error can hack or no
 
 I'm test this code 
 resource.php?id=1-
 
 and I have get error
      Resource
     Warning: MySQL Connection Failed: Access denied for u ... | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
		
			
			
				
				| Oilik |  
				 |  
				| Replies: 2 |  
				| Views: 11717 |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			Try use the admins account for ftp. Otherwise look into editing styles or allowing .php files as uploads.
 Tried them.  
 Even tried editing the handlers and adding an extension to be ran as php. Sti ... | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
		
			
			
				
				| Oilik |  
				 |  
				| Replies: 2 |  
				| Views: 11717 |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			Hello,
 Does anyone know how to upload a shell in MyBB 1.2.12? I've got the head administrator's account, and nothing is working. | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
		
			
			
				
				| Oilik |  
				 |  
				| Replies: 2 |  
				| Views: 6812 |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			Hi all.
 
 I was wondering how to use a where id=1 in sql injection? The "LIKE" is working for me for approximative data, but i dont know how to get only one row with a precise condition with the wher ... | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
		
			
			
				
				| Oilik |  
				 |  
				| Replies: 2 |  
				| Views: 7282 |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			Good idea, this has potential
 Thanks. It sure saves me a lot of time. xD | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
		
			
			
				
				| Oilik |  
				 |  
				| Replies: 2 |  
				| Views: 7282 |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			Hello,
 I was playing around in PHP and messing with AJAX, and I thought, I sure get tired of going to a form, putting the hash in, submitting it, waiting for it to load, then clicking back to do it a ... | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
		
			
			
				
				| Oilik |  
				 |  
				| Replies: 11 |  
				| Views: 16146 |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			i followed everything from that video 
 
 i did
 
 null;exec master..xp_cmdshell 'net user guest 123456 /add';--
 
 and i got a valid page !
 
 then
 
 null;exec master..xp_cmdshell 'net localgroup ad ... | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
		
			
			
				
				| Oilik |  
				 |  
				| Replies: 4 |  
				| Views: 8717 |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			Plaintext of acc045b02d3db9eed24b38f58e55f3b6 is cvfgtz67
 
 I submit this hash to Plaintext, why i cann't search it?
 Are you submitting the hash, or the cracked string? | 
		 
		  | 
	 
	  | 
 
 
	 | 
 
	
	
		
		
			
			
				
				| Oilik |  
				 |  
				| Replies: 11 |  
				| Views: 16146 |  
				  | 
			 
			 
 
  | 
			  | 
		 
		
			  | 
			  | 
		 
		 
 
  | 
		
		
			bump !
 It's using DBO?
 http://milw0rm.com/video/watch.php?id=70 | 
		 
		  | 
	 
	  | 
 
 
  
	| Page 1 of 3 | 
	Goto page 1, 2, 3Next All times are GMT | 
   
 
  
Powered by phpBB © 2001-2008 phpBB Group
 
  
 
 
 | 
                           
                         
                         | 
                     
                    | 
               
              | 
         
       
       |