Friday, February 18, 2011

SQL Injection Tutorial




I.            Introduction:
In the following article I'm not trying to introduce anything new.
As a pentester and a Web Developer I can say that more than 90% of nowadays Web Application seems to be vulnerable to SQLInjection and many other kind of vulnerabilities,

                  II.            What is SQL Injection?
SQL Injection is composed of two words; let's start with the second one:
·       Injection: if we look in the dictionary, we'll find that Injection means the act of putting one thing into another.
·       SQL: Structured Query Language.

According to Wikipedia, SQL Injection is a code injection technique that exploits a security vulnerability occurring in the database layer of an application. The vulnerability is present when user input is either incorrectly filtered for string literal escape characters embedded in SQL statements or user input is not strongly typed and thereby unexpectedly executed. It is an instance of a more general class of vulnerabilities that can occur whenever one programming or scripting language is embedded inside another. SQL Injection attacks are also known as SQL insertion attacks.

              III.            SQL Injection Example:

Tuesday, January 11, 2011

WordList Creator

 


We all know that the brute forcing and the password cracking process relies on the quality of the WordList. 

So, I decided to share a tool I developed on my free time.
I named it WordList Creator.

The WordList Creator enables you to collect words from web pages, the result can be saved in a new WordList or appended to an existing WordList, with no duplicates.

How it works:
The WordList Creator has two methodes for working:
  1. The first one consists of querying Google to collect all links, and then collect all the words found in those links.
  2. The second one is similar to the first, except that the links are gathered from a text file.
The rar file contains the source & the jar file.
Download WordList Creator


** If you encounter a bug please report it 

Wednesday, December 15, 2010

Google Hacking Database


   
    If you do not already know, Google can be used by malicious person to hack websites, servers, credit cards, and ………..

Ohhh yes, Google is the best friend of hackers, using what is called GOOGLE DORKS, a hacker can easily find exploitable vulnerabilities and mount attacks that will allow access to the vulnerable target.

   Google dorks are a combination of words used as search keyword.

   The Google Hacking Database (GHDB) is a project started by Johnny Long, and located at: http://www.hackersforcharity.org/ghdb/
For more information follow the link: http://www.exploit-db.com/google-hacking-database-reborn/ 

   Now time to demonstrate the power of the Google Hacking Database,