Login Register






The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.
Thread Rating:
  • 0 Vote(s) - 0 Average


SQL injection tutorial filter_list
Author
Message
RE: SQL injection tutorial #11
Thank you for sharing. Nice and simple to comprehend; the best kind of tutorial.

Reply

RE: SQL injection tutorial #12
(04-22-2012, 10:52 AM)grouver08 Wrote: 1:admin:$P$BVn6ffoysMZIZWl..WeFguFFjfG8rX0:loschi@studioaltermedia.it
2:test:$P$B.pgSzrVT7AChwBS.hHc0x9nVSXvBF1:loschi@iuav.it
3:fabriziogalli:$P$BRozKUfxX/YlD5kwg6.soiU.aMTfLr/:fabriziogalli@infinito.it
7:giuseppe_ridolfi:$P$BDfYuVKqZUVDqCP4tcM1d8D5Agc9I3.:giuseppe.ridolfi@taed.unifi.it
6Confusedpartaco paris:$P$BdrzsFGO/Kusq0ZNawghs98fhVggYM1Confusedpartacoparis@hotmail.com
8:isidoro:$P$B0GTmpOKQwahKr8m4zICPg23cBQdFe0:antonio.lauria@taed.unifi.it
10:Walter Angelico:$P$BH2xBV6eY3K02emxhg8BzpzVvEDcbA0:walterangelico1@tin.it
11:Andrianq:$P$B4S.SWhJiD6CxLlV1mRywf7i3y48kn.:pulvillarrac@gmail.com
12:MikeWink:$P$B8dwPQu/ZVV62Xq256jIldy5z1HxrV/:bugbeemershonyhe@gmail.com
13:UlricheDmond:$P$BtQX0X44HnBZuPuzKaJrYdK/vO/Tjv1:ulrichedmondsuses@gmail.com
14:marco:$P$BYLPKdC3Fy8xmpfX2lW0HmlRRr/IGf/:marco@itrsystem.com
16TongueIPERYJ27:$P$Bw8ZjwnIhIcCxh.ZCK5ZSgD1I/OSh4.TongueIPERYJ27@unique-papers.com
17:wpadmina:$P$BL3g7vYq3xxxMx5PAOxeuFlYaqkyvj0:makilovitalcamader@gmail.com
18:jos:$P$B/XfeEk/xuERa7OFYP2O9duY458Ihi1:john@chetkoe.tv
19:finoli 13


Is there a way to decrypt the password?

Yes there is a way to decrypt the hashes. They are Md5 wordpress hashes which tend to be rather tricky to crack. The algorithm is pretty hard to crack and takes a long time, also might want to make sure if they contain salts. Look into using hashcat if you want to crack them.

As for OP nice TUT, but you could have also explained WAF Bypassing. Sometimes Union Select and other commands are blocked by Windows Application Firewall (WAF) so you would have to trick the application into not detecting the union select command by either commenting or white spaces, like so /**UNION**/+/**SELECT**/+1,2,3...
[Image: 8Hd3UZQ.png]

My Private Tools:
[*] Private SQL INJECTION SCANNER! [*]

[*] HQ Tutiorals Too! [*]

Reply







Users browsing this thread: 9 Guest(s)