Monday, January 31, 2005

Hacker Tip 20 :: Advancd Guestbook 2.2

Ok, Listen up my Hacker Biatches. Today i will be showing you the SQL Injection to be doing the hacking.
Here is some further reading.
http://www.securiteam.com/securityreviews/5DP0N1P76E.html
http://www.governmentsecurity.org/articles...sicTutorial.php
http://www.sqlcourse.com
http://www.drakesland.com/articles.php?id=6
http://www.nextgenss.com/papers/advanced_sql_injection.pdf
http://www.spidynamics.com/whitepapers/Whi...QLInjection.pdf

It is very easy too do. Extremely Easy

Let us start. First off the warning

By showing this, none of the people that are running with site are responsible for what you may do and will not take responsibility for any action you take!

Now by using the AllTheWeb, Alltheweb is a being a good search engine, basically Google's equivalent except not as widely known. In the search bar, type Advanced Guestbook 2.2.

Most of them are being the defaced by the Asshole Hackers. Like the Kuwaiti Hacker Groopz that are being bitching about the US or those unleet biatches that are be liking the Nazis. Dont do that! Ill fuck you up then.

But when you are at the guest book, the url is most likely to be.
/guestbook/index.html.
Change that to
/guestbook/admin.php

Or something like that, (normally they have the login to the admin Panel)

This is the maker first mistake.

His other mistake was not to fully check it for MySQL vulnerabilities. If you havent tried any already, type (in the password form) EXACTLY:

') OR ('a' = 'a

Leave the UserName Blank and be pressing the ENTER.
Now you can be changing the post ;) But no Nazi bull shit! Ok! That is back!
If you are having the Advancd Guestbook 2.2, I suggest that you be updating and not be defaced by the Gay Nazi Hacker.
That was hacking with Ramzi
--Ramzi--

4 Comments:

XeroCool said...

Thanks dude. Going to jack some shit up.

1:11 AM  
Anonymous said...

^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
xerocool
how the hell does he think he is LAMER

1:25 AM  
Anonymous said...

So wheres this SQL injection your meant to be showing us? You just gave some links to other sites and gave us a VERY old PHP exploit that basically everyone knows! You call yourself a hacker..i already know all this stuff and im only 15.

4:58 PM  
linuxinit said...

its a fucking joke you moron!

7:09 AM  

Post a Comment

<< Home