Vcoderz Community
We create websites that have it all, beauty & brains
Lebanon Web Design & Development - Coddict
 

Go Back   Vcoderz Community > Computer Zone > Computers & Information Technologies

Notices

Computers & Information Technologies « Everything related to computers and internet. »

Reply
 
Share Thread Tools Search this Thread
Old 02-02-2010   #1
jak
Registered Member
 
jak's Avatar
 
Last Online: 12-11-2011
Join Date: Dec 2006
Posts: 946
Thanks: 388
Thanked 601 Times in 294 Posts
Groans: 4
Groaned at 3 Times in 3 Posts
Default SQL injections

i was doin a small research over the internet about SQL injections since im building a website and i want it to be safe against any kind of hacks. Actually some of u know already about this subject so im here just for some extra info and for the ones that have no idea about it well its kinda interesting!!
As u know behind most of the websites there is a database. This database can be accessed through SQL injections sometimes if the site is vulnerable. Simple injections are done through text inputs, mainly when it comes to login to an account:
The thing is to put ’ OR 1=1-- as a username. the SQL statement will be as followed: SELECT * FROM customers WHERE name = ‘’ OR 1=1--’ AND password = ‘’ we are giving an empty username but we are telling him not to use the username because we have a true statement which is 1=1. so you have to select all rows from the customers table. Well this trick doesn't work on most of the websites so don't bother to try, it was just an info

so any other ways that anyone knows about hacking a website through SQL injections?


jak is offline   Reply With Quote
Old 02-02-2010   #2
RUSSIAN
Registered Member
 
RUSSIAN's Avatar
 
Last Online: 10-08-2023
Join Date: Nov 2009
Posts: 569
Thanks: 838
Thanked 232 Times in 174 Posts
Groans: 24
Groaned at 16 Times in 13 Posts
Default

Quote:
Originally Posted by jak View Post
i was doin a small research over the internet about SQL injections since im building a website and i want it to be safe against any kind of hacks.
Such site can't be built.
__________________
What about a 500+ symbols long, colored signature with URL allowed and size limited to 7?
RUSSIAN is offline   Reply With Quote
Old 02-02-2010   #3
jak
Registered Member
 
jak's Avatar
 
Last Online: 12-11-2011
Join Date: Dec 2006
Posts: 946
Thanks: 388
Thanked 601 Times in 294 Posts
Groans: 4
Groaned at 3 Times in 3 Posts
Default

of course it can't but im doing my best to get all necessary data about the most used techniques and i will try to do my best to make the website as immune as possible
jak is offline   Reply With Quote
Old 02-02-2010   #4
Google

 
Google's Avatar
 
Last Online: 05-30-2013
Join Date: Jan 2008
Posts: 1,788
Thanks: 10,018
Thanked 1,100 Times in 651 Posts
Groans: 1
Groaned at 6 Times in 6 Posts
Default

I can help you with the penetration testing when the website is done.
__________________

Google is offline   Reply With Quote
Old 02-03-2010   #5
jak
Registered Member
 
jak's Avatar
 
Last Online: 12-11-2011
Join Date: Dec 2006
Posts: 946
Thanks: 388
Thanked 601 Times in 294 Posts
Groans: 4
Groaned at 3 Times in 3 Posts
Default

Quote:
Originally Posted by Google View Post
I can help you with the penetration testing when the website is done.
Thanks but first i need the techniques to be able to know how a hacker thinks when hes working on a website so i can be able to build a vulnerable one. so if u know any techniques it would be great to tell us about it.
if u want i can pm you my personal email if u dont want to post it to the public.
jak is offline   Reply With Quote
Old 02-03-2010   #6
Google

 
Google's Avatar
 
Last Online: 05-30-2013
Join Date: Jan 2008
Posts: 1,788
Thanks: 10,018
Thanked 1,100 Times in 651 Posts
Groans: 1
Groaned at 6 Times in 6 Posts
Default

Techniques are many. I won't post here vulnerable websites to show you samples, but if you want, add me. My IM is in my profile.
__________________

Google is offline   Reply With Quote
Reply

  Vcoderz Community > Computer Zone > Computers & Information Technologies

Tags
injections, sql



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 09:16 PM.


Lebanon web design and development
Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Ad Management plugin by RedTyger
Share