hello everyone i want to have a firewall anyone well help me

Status
Not open for further replies.
Fav. Antivirus
bitdefender

Cowpipe

Level 16
Verified
Well-known
Jun 16, 2014
781
Well I'm a hacker too but not too advance I'm just a girl who love's hiding stuff and actually I use two Os Windows and Linux thank you I well Pm you If I have questions. I speak English not fluently because I'm a Russian half Asian

As a hacker, I'd like to see you have a go at breaking into this site (a site designed to test and refine your hacking skills), and let us know how you did it :) :p

http://jmchilton.net/sqlinject/create.php

@Arakasi @NullPointerException ~ Have a go at this too if you haven't already, it's quite fun.
 
  • Like
Reactions: jen900

Arakasi

Level 4
Verified
Jul 12, 2014
195
@Cowpipe
Just now getting a tiny bit of free time.

What no dork for jmchilton.net ?
Of course not that would make it easy, why do that on a test your intrusion experience website.
 
  • Like
Reactions: Cowpipe

Arakasi

Level 4
Verified
Jul 12, 2014
195
Oh wait . . .
<li><a href="index.php?user_id=4">agentgill</a></li>
<li><a href="index.php?user_id=7">ak</a></li>
<li><a href="index.php?user_id=9">javaug</a></li>
<li><a href="index.php?user_id=10">jody</a></li>
<li><a href="index.php?user_id=2">john</a></li>
<li><a href="index.php?user_id=8">leah</a></li>
<li><a href="index.php?user_id=6">lexi</a></li>
<li><a href="index.php?user_id=3">msi</a></li>
<li><a href="index.php?user_id=5">peter</a></li>
<li><a href="index.php?user_id=1">phil</a></li>
<li><a href="index.php?user_id=11">scott</a></li>
<li><a href="index.php?user_id=12">tim</a></li>
 
  • Like
Reactions: Cowpipe

Arakasi

Level 4
Verified
Jul 12, 2014
195
Whoops, we has possible db variables :oops:
$('#post_username').val();
$('#post_password').val();

Fun is over :(
Will come back to this interesting tweeter site .....:rolleyes:
 
  • Like
Reactions: Cowpipe

Cowpipe

Level 16
Verified
Well-known
Jun 16, 2014
781
Whoops, we has possible db variables :oops:
$('#post_username').val();
$('#post_password').val();

Fun is over :(
Will come back to this interesting tweeter site .....:rolleyes:

It's trickier than it appears from the outside right ;)

Let me know how you get on when you come back to it, it's great to read your updates (my very own twitter feed about hacking, well.. twitter? o_O)
 
  • Like
Reactions: Arakasi

Arakasi

Level 4
Verified
Jul 12, 2014
195
On mobile-

Yes the server has been giving errors, if this is by design, regarding database.

Stay tuned ha!
 
  • Like
Reactions: Cowpipe

Arakasi

Level 4
Verified
Jul 12, 2014
195
Error: Failed to exeucte query [SELECT username FROM users where username='' and password='';]. PDO Error Info: array ( 0 => 'HY000', 1 => 1, 2 => 'unrecognized token: "\'\'\' and password=\'\';"', )

:rolleyes: LOL whoever built it misspelled execute in the error messages returned.
 
  • Like
Reactions: Cowpipe

Cowpipe

Level 16
Verified
Well-known
Jun 16, 2014
781
:rolleyes: LOL whoever built it misspelled execute in the error messages returned.

Hahaha. Looks like it's manually evaluating the queries then.. Would be a little dangerous to run live sql queries, even on a virtual database :) Maybe they can't spill properly, but they seem to have a grasp of security :p
 

Arakasi

Level 4
Verified
Jul 12, 2014
195
Apache on ubuntu
php of course
An MsAccess db

Almost done, can't believe im doing this at work today, instead of well.... working. o_O
 
  • Like
Reactions: Cowpipe

Arakasi

Level 4
Verified
Jul 12, 2014
195
Done

Are we sure this is a test db, specifically for this ROFL?
There is a lot of data/tables here.

What are we doing now, adding a login ? User Cowpipe maybe ? Ha
@Cowpipe
 
  • Like
Reactions: Cowpipe

Cowpipe

Level 16
Verified
Well-known
Jun 16, 2014
781
Done

Are we sure this is a test db, specifically for this ROFL?
There is a lot of data/tables here.

What are we doing now, adding a login ? User Cowpipe maybe ? Ha
@Cowpipe

Haha, yes it's definitely a test db. I think the large data set is specifically to simulate real life servers. The idea being to obtain the list of usernames and passwords :D Feel free to add me to their database if you like, I'll tweet a thank you for you! :p haha
 
  • Like
Reactions: Arakasi
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top