Fourteen Years of Service
Posts: 1,166
Threads: 65
A lil help plzz! 02-26-2012, 10:50 PM
#1
Hey!
I was thinking about something.
Can you make a normally site into a vulnerable site??
Sorry if its a stupid question...
•
Fourteen Years of Service
Posts: 475
Threads: 74
RE: A lil help plzz! 02-26-2012, 11:32 PM
#2
You mean like.. Make Google suddenly have a SQL vulnerability? No.
SQL vulnerabilities are caused when user input is poorly typed or if user input is incorrectly filtered in SQL statements.
![[Image: nNICR.jpg]](http://i.imgur.com/nNICR.jpg)
Creds to bluedog
For a list of my contributions (includes tutorials). Click here.
If you'd like to apply for Heat, please click
here.
•
Fourteen Years of Service
Posts: 3,799
Threads: 957
RE: A lil help plzz! 02-26-2012, 11:33 PM
#3
If you have access to it then yes.
For example, if I add MyCode to HC, I have to run various tests to make sure, that nobody can exploit the MyCode in some way (making HC vuln to XSS or w/e).
Staff will never ever ask you for your personal information.
We know everything about you anyway.
•
Fourteen Years of Service
Posts: 721
Threads: 49
RE: A lil help plzz! 02-27-2012, 10:39 PM
#8
You don't make someone else's site vulnerable. You find an existing vulnerability that is already there, in order to gain access to it. However, once you have access to it, you can of course add more vulnerabilities if you want, by adding some additional code that can be exploited, or more likely, that's even directly made so it will allow for example execution of arbitrary code sent to the server. If you're the author of some website, you can of course make it vulnerable, though people who usually make websites and posses certain level of sanity usually take the exactly opposite approach.
Though... theoretically you might use some social engineering in order to expose some vulnerability that wasn't there, by making administrator/user do some change to it, although I don't know how much would you succeed with that, as users usually have restricted rights and administrator most probably wouldn't do anything that would seem suspicious/vulnerable to him, unless it was a very peculiar case... if he would even be willing to make changes based on someone's request.
I love creativity and creating, I love science and rational thought, I am an open atheist and avid self-learner.
•
Fourteen Years of Service
Posts: 54
Threads: 18
RE: A lil help plzz! 04-04-2012, 02:08 PM
#10
but whats the point of adding more vulnerabilities to the site if you have already hacked into it??
•