Security and Cryptography
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationSecurity and Cryptography

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old January 22nd, 2008, 12:57 PM
jojoba's Avatar
jojoba jojoba is offline
I love your chinese eyes :*
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Jan 2006
Location: Her heart... she claims!
Posts: 1,625 jojoba User rank is Brigadier General (60000 - 70000 Reputation Level)jojoba User rank is Brigadier General (60000 - 70000 Reputation Level)jojoba User rank is Brigadier General (60000 - 70000 Reputation Level)jojoba User rank is Brigadier General (60000 - 70000 Reputation Level)jojoba User rank is Brigadier General (60000 - 70000 Reputation Level)jojoba User rank is Brigadier General (60000 - 70000 Reputation Level)jojoba User rank is Brigadier General (60000 - 70000 Reputation Level)jojoba User rank is Brigadier General (60000 - 70000 Reputation Level)jojoba User rank is Brigadier General (60000 - 70000 Reputation Level)jojoba User rank is Brigadier General (60000 - 70000 Reputation Level)jojoba User rank is Brigadier General (60000 - 70000 Reputation Level)jojoba User rank is Brigadier General (60000 - 70000 Reputation Level)jojoba User rank is Brigadier General (60000 - 70000 Reputation Level) 
Time spent in forums: 2 Weeks 5 Days 17 h 54 m 57 sec
Reputation Power: 648
MySQL based Hacking Attempt Prevention

Hi guys,

I have an exploit issue to discuss to take the wise words of all seniors here.

One of my friends website was hacked recently. On investigating we found that someone executed a special URL / LINK on the website which echoed / displayed the admin's username and password for the admin panel on the page.

the hacker knew the table name that stored the admin data.

here is a rough sketch what he did (i am not gonna give the exact to save many others )

Code:
domain.com/phpPage.php?id=-1/**/union/**/all/**/select/**/concat(une,char(58),pwd)/**/from/**/tablename/*


I can see that he used -1 as id, which cannot be-1 then he used this MySQL command in the URL...

I wanted to ask that how can I take lesson from this and take care of my projects to avoid such exploits?

thank you

Reply With Quote
  #2  
Old January 22nd, 2008, 09:48 PM
B-Con's Avatar
B-Con B-Con is offline
Crypto-Con
Dev Shed God 4th Plane (6500 - 6999 posts)
 
Join Date: Apr 2004
Location: UC Davis
Posts: 6,668 B-Con User rank is General 1st Grade (Above 100000 Reputation Level)B-Con User rank is General 1st Grade (Above 100000 Reputation Level)B-Con User rank is General 1st Grade (Above 100000 Reputation Level)B-Con User rank is General 1st Grade (Above 100000 Reputation Level)B-Con User rank is General 1st Grade (Above 100000 Reputation Level)B-Con User rank is General 1st Grade (Above 100000 Reputation Level)B-Con User rank is General 1st Grade (Above 100000 Reputation Level)B-Con User rank is General 1st Grade (Above 100000 Reputation Level)B-Con User rank is General 1st Grade (Above 100000 Reputation Level)B-Con User rank is General 1st Grade (Above 100000 Reputation Level)B-Con User rank is General 1st Grade (Above 100000 Reputation Level)B-Con User rank is General 1st Grade (Above 100000 Reputation Level)B-Con User rank is General 1st Grade (Above 100000 Reputation Level)B-Con User rank is General 1st Grade (Above 100000 Reputation Level)B-Con User rank is General 1st Grade (Above 100000 Reputation Level)B-Con User rank is General 1st Grade (Above 100000 Reputation Level) 
Time spent in forums: 1 Month 5 Days 22 h 49 m 36 sec
Reputation Power: 1015
Such an exploit is called an SQL-injection. Namely, the user finds a way to execute his own query in the database by inputing manipulative data into one of the user-inputs that he has access to. You'll need to prevent all user-defined variables from being directly executed as, or included in, database queries. Always cleanse your input first.
Comments on this post
jojoba agrees: thank you
__________________
- "Cryptographically secure linear feedback shift register based stream ciphers" -- a phrase that'll get any party started.
- Why know the ordinary when you can understand the extraordinary?
- Sponsor my caffeine addiction! (36.70 USD received so far -- Latest donor: Mark Foxvog.
)

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationSecurity and Cryptography > MySQL based Hacking Attempt Prevention


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump



 Free IT White Papers!
 
How to Present Effectively Online
This white paper offers practical and actionable advice on the key steps that any presenter should consider as they plan and execute a Webinar or online meeting.

 
Open Source Security Myths
Open Source Software (OSS) is computer software whose source code is available to the general public with relaxed or non-existent intellectual property restrictions (or arrangement such as the public domain), and is usually developed with the input of many contributors.

 
Power and Cooling Capacity Management for Data Centers
This paper describes the principles for achieving power and cooling capacity management.

 
Scalable, Fault-Tolerant NAS for Oracle - The Next Generation
For several years NAS has been evolving as a storage alternative for Oracle databases, and for good reason: NAS is quite often the simplest, most cost-effective storage approach for Oracle. Learn about the benefits that HP's approach to scalable NAS brings to Oracle environments in this comprehensive white paper.

 
Understanding Web Application Security Challenges
This white paper discusses many common threats and preventive measures for Web application security, and explains what you can do to help protect your organization.

 

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2009 by Developer Shed. All rights reserved. DS Cluster 6 hosted by Hostway
Stay green...Green IT