|
|
|||||||
| Computers & Information Technologies « Everything related to computers and internet. » |
![]() |
|
|
Share | Thread Tools | Search this Thread |
|
|
#1 |
|
Registered Member
Last Online: 12-11-2011
Join Date: Dec 2006
Posts: 946
Thanks: 388
Thanked 601 Times in 294 Posts
Groans: 4
Groaned at 3 Times in 3 Posts
|
i was doin a small research over the internet about SQL injections since im building a website and i want it to be safe against any kind of hacks. Actually some of u know already about this subject so im here just for some extra info and for the ones that have no idea about it well its kinda interesting!!
As u know behind most of the websites there is a database. This database can be accessed through SQL injections sometimes if the site is vulnerable. Simple injections are done through text inputs, mainly when it comes to login to an account: The thing is to put ’ OR 1=1-- as a username. the SQL statement will be as followed: SELECT * FROM customers WHERE name = ‘’ OR 1=1--’ AND password = ‘’ we are giving an empty username but we are telling him not to use the username because we have a true statement which is 1=1. so you have to select all rows from the customers table. Well this trick doesn't work on most of the websites so don't bother to try, it was just an info so any other ways that anyone knows about hacking a website through SQL injections? |
|
|
|
|
|
#2 |
|
Registered Member
Last Online: 10-08-2023
Join Date: Nov 2009
Posts: 569
Thanks: 838
Thanked 232 Times in 174 Posts
Groans: 24
Groaned at 16 Times in 13 Posts
|
Such site can't be built.
__________________
What about a 500+ symbols long, colored signature with URL allowed and size limited to 7? |
|
|
|
|
|
#3 |
|
Registered Member
Last Online: 12-11-2011
Join Date: Dec 2006
Posts: 946
Thanks: 388
Thanked 601 Times in 294 Posts
Groans: 4
Groaned at 3 Times in 3 Posts
|
of course it can't but im doing my best to get all necessary data about the most used techniques and i will try to do my best to make the website as immune as possible
|
|
|
|
|
|
#4 |
|
Last Online: 05-30-2013
Join Date: Jan 2008
Posts: 1,788
Thanks: 10,018
Thanked 1,100 Times in 651 Posts
Groans: 1
Groaned at 6 Times in 6 Posts
|
I can help you with the penetration testing when the website is done.
__________________
|
|
|
|
|
|
#5 | |
|
Registered Member
Last Online: 12-11-2011
Join Date: Dec 2006
Posts: 946
Thanks: 388
Thanked 601 Times in 294 Posts
Groans: 4
Groaned at 3 Times in 3 Posts
|
Quote:
if u want i can pm you my personal email if u dont want to post it to the public. |
|
|
|
|
|
|
#6 |
|
Last Online: 05-30-2013
Join Date: Jan 2008
Posts: 1,788
Thanks: 10,018
Thanked 1,100 Times in 651 Posts
Groans: 1
Groaned at 6 Times in 6 Posts
|
Techniques are many. I won't post here vulnerable websites to show you samples, but if you want, add me. My IM is in my profile.
__________________
|
|
|
|
![]() |
|
| Tags |
| injections, sql |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | Search this Thread |
|
|