Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


My SQL injection complete tutorial :) filter_list
Author
Message
RE: My SQL injection complete tutorial :) #281
I know quite some amount of database management using mysql but I never came across something like this +/*! or this /./
How does it bypass that 403 error?
[Image: 2YpkRjy.png]
PM me if you need help.
My pastebin HERE. My URL Shortener HERE.


RE: My SQL injection complete tutorial :) #282
Very nice tutorial Viper, tnx for sharing it.


RE: My SQL injection complete tutorial :) #283
(03-04-2013, 04:37 PM)The Alchemist Wrote: I know quite some amount of database management using mysql but I never came across something like this +/*! or this /./
How does it bypass that 403 error?
It's just a matter of bypassing the rules of the WAF that looks for specific patterns in the variable values. There are loads of articles on WAF bypassing, here's a good one:

http://kaoticcreations.blogspot.nl/p/sql...ssing.html


RE: My SQL injection complete tutorial :) #284
(03-09-2013, 01:16 PM)zomgwtfbbq Wrote:
(03-04-2013, 04:37 PM)The Alchemist Wrote: I know quite some amount of database management using mysql but I never came across something like this +/*! or this /./
How does it bypass that 403 error?
It's just a matter of bypassing the rules of the WAF that looks for specific patterns in the variable values. There are loads of articles on WAF bypassing, here's a good one:

http://kaoticcreations.blogspot.nl/p/sql...ssing.html

It still didn't work. But I'll be looking into the link that you provided and also other articles about it(thanks for mentioning the term WAF bypassing, I didn't know it). So, when an 403 error appears, it means that they've blocked a certain pattern of URL type that they suspect to be vulnerable? They do this comparing with the URL right?
[Image: 2YpkRjy.png]
PM me if you need help.
My pastebin HERE. My URL Shortener HERE.


RE: My SQL injection complete tutorial :) #285
(03-10-2013, 07:22 PM)The Alchemist Wrote:
(03-09-2013, 01:16 PM)zomgwtfbbq Wrote:
(03-04-2013, 04:37 PM)The Alchemist Wrote: I know quite some amount of database management using mysql but I never came across something like this +/*! or this /./
How does it bypass that 403 error?
It's just a matter of bypassing the rules of the WAF that looks for specific patterns in the variable values. There are loads of articles on WAF bypassing, here's a good one:

http://kaoticcreations.blogspot.nl/p/sql...ssing.html

It still didn't work. But I'll be looking into the link that you provided and also other articles about it(thanks for mentioning the term WAF bypassing, I didn't know it). So, when an 403 error appears, it means that they've blocked a certain pattern of URL type that they suspect to be vulnerable? They do this comparing with the URL right?
WAFs search for (sql) keywords like 'union', the trick is to add sql comments to bypass them. There are many WAFs around, all searching for different patterns in variables.


RE: My SQL injection complete tutorial :) #286
Man I need the passworld of this link for download: http://www.mediafire.com/?y7v30lcj0kn8836
Please, I will waiting a replay.


RE: My SQL injection complete tutorial :) #287
you can read in the end of the thread how to get the password Smile
valar morghulis


RE: My SQL injection complete tutorial :) #288
Great Tutorial For the One who are stepping in this field and also for the intermediates

Thanks
[Image: htz7sy.jpg]


RE: My SQL injection complete tutorial :) #289
Please help me with the password for Download SQLI dorks list. I liked facebook page and sent you an message but no response. Thank you very much


RE: My SQL injection complete tutorial :) #290
Please help me with the password for Download SQLI dorks list. I liked facebook page and sent you an message but no response. Thank you very much