Paid Advertising

SLA.CKERS.ORG
HA.CKERS SLACKING
sla.ckers.org web application security lab forums
How do you completely compromise a machine given a text box or badly validated input box? This is a place to talk about code issues (PHP includes, null byte injection, backticks, pipe, etc...) as well as how to properly construct an SQL injection attack. 
Subject Views Posts  Started By  Last Post 
MSSQL Need Help and Ideas 90  rickm  09/05/2010 11:50PM 
Last Post by rickm
php filter not working 23  flics  09/05/2010 10:49PM 
Last Post by rickm
whether this vuln to sqli 43  al3x_0wn5  09/05/2010 03:58PM 
Last Post by PaPPy
Help me about this injection 224  xndd  09/05/2010 02:32PM 
Last Post by .mario
Help me , please on this sqli 44  _antivirus_  09/05/2010 02:32PM 
Last Post by lightos
select command is denied 65  the_storm  09/03/2010 09:20AM 
Last Post by the_storm
What can I do with these SQL Injections? 83  eyenit0  09/02/2010 11:29PM 
Last Post by eyenit0
can't open a php file 81  the_storm  09/01/2010 03:09PM 
Last Post by PaPPy
SQLi without quotes 137  PaPPy  08/30/2010 06:49PM 
Last Post by alexfoo
nothing from information_schema.tables 320  jogidoggie  08/30/2010 03:36AM 
Last Post by Jelmer
Need ideas for escalating MySQL injection on Windows Server 138  wish  08/28/2010 12:05PM 
Last Post by wish
SQL Injection - Getting around addslashes() 178  shadowplayer  08/28/2010 11:20AM 
Last Post by Skyphire
West Palm Beach Police Department sqli 160  VMw4r3  08/28/2010 09:18AM 
Last Post by hyrax
INTO OUTFILE always show "File already exists"? 240  18  hyrax  08/23/2010 12:32PM 
Last Post by thrill
Different type of hash in sqli. 171  m1cr0n  08/20/2010 12:21PM 
Last Post by Skyphire
Access denied for user X when using OUTFILE? 151  hyrax  08/15/2010 06:37PM 
Last Post by hyrax
Selective queries (depending on @@version) ? 120  Perow  08/14/2010 05:58PM 
Last Post by Perow
mssql injection finding table names 153  xndd  08/14/2010 11:11AM 
Last Post by xndd
no accpetable in SQL injection 244  10  the_storm  08/13/2010 08:09PM 
Last Post by TopSaT13
How to get table names in mysql < 5 336  14  hyrax  08/13/2010 01:07PM 
Last Post by VMw4r3
File already exists in outfile SQL injection 185  the_storm  08/11/2010 09:07PM 
Last Post by hyrax
2 questions about MSSQL 119  hyrax  08/11/2010 12:16PM 
Last Post by lightos
problem with SQL injection 168  the_storm  08/11/2010 11:37AM 
Last Post by lightos
Whats wrong with this query? 194  hyrax  08/10/2010 05:37PM 
Last Post by hyrax
Why "information_schema not available, back-end DBMS is MySQL < 5.0"? 130  hyrax  08/08/2010 07:04PM 
Last Post by Reiners
How to use xp_cmdshell in queries? 408  hyrax  08/08/2010 11:22AM 
Last Post by hyrax
What does CAST(table_name AS CHAR(10000)), CHAR(32) do? 111  hyrax  08/08/2010 01:25AM 
Last Post by hyrax
Another help with sqlinjection 469  m1cr0n  08/06/2010 02:13PM 
Last Post by m1cr0n
column mismatch in union 137  jogidoggie  08/06/2010 11:52AM 
Last Post by hyrax
Mongo DB injection 127  doodlefish  08/06/2010 06:25AM 
Last Post by doodlefish