try this 100% working
just locate these registry entries and change it to the given values
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Tcpip\Parameters]
"GlobalMaxTcpWindowSize"=dword:0000ffff
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Tcpip\Parameters]
"GlobalMaxTcpWindowSize"=dword:00007fff
Thursday, November 1, 2007
top 20 blogs other than mine u should visit
1) Lifehacker
www.lifehacker.com
Lifehackers' motto says it all: "Don't live to geek, geek to live." This blog offers timesavers of just about every stripe, from Firefox shortcuts to tips from the "Getting things done" faithful.
2) IT Toolbox Blogs
http://blogs.ittoolbox.com
IT Toolbox has a number of "in the trenches" IT pros who talk about technology and management issues. There are specialist blogs dealing with security, databases and project management, among other subjects. It's a versatile site.
3) Valleywag
http://valleywag.com
Bring in the noise, bring in the snark. Valleywag is for those who believe that the tech industry lives or dies by the scuttlebutt pinging around Silicon Valley. And it's amusing for those of us who prefer that the lotus-eaters of Northern California stick with the dishing and tongue-wagging, leaving the rest of us to get the real work done.
4) Kotaku
http://kotaku.com
Kotaku is the snarky, gamer uber-blog. It has everything from reviews and gossip to cheat tips. Just about anything you'll ever need, including which game to buy and how to play it.
5) Danger Room
http://blog.wired.com/defense
Wired's military and defense blog writes about some of the coolest and scariest military technologies -- not to mention scandals, debates and other military news. Lots of video and imagery are included.
6) Gizmodo
http://gizmodo.com
Gizmodo's got the scoop on all the latest toys and cool and wacky inventions -- from high-def TVs and coffee makers to booze belts and USB drives. You've got to love a site that publishes photos of a solar-powered bathing suit. Yeah, they also blog about serious technology news too.
7) O'Reilly Radar
http://radar.oreilly.com
This is where you can read Tim O'Reilly (founder of O'Reilly publishing) and others discuss networking, programming, open source, intellectual property, politics and Web 2.0, emerging technology.
8) Techdirt
http://www.techdirt.com
Techdirt is a newsy, "tell it like it is" blog that frequently features debates on the hot issues in the Internet and computer fields. Scandals are a specialty. Simplicity is its hallmark.
9) Groklaw
http://www.groklaw.net
Groklaw's raison d'etre is needling SCO in its long-running patent fights against IBM and Novell, but the discussion sometimes veers toward other issues that involve technology, intellectual property, and government regulations.
10) Hack a Day
http://www.hackaday.com
Want to learn how to add USB to a cheap Linux router? Create a snake robot? How about an XBox 360 laptop? Hack a Day has these basement projects and many more. This site is for the serious techie. At the same time, it's good for a laugh or a new hobby.
11) Engadget
http://www.engadget.com
As Coke is to Pepsi, so Engadget is to Gizmodo. It's all about gear, gossip, techish issues and the occasional rant. It's got great product photos, and the editors have access to pre- and early-release gadgetry. Also, some really funny home-made junk. But we prefer Gizmodo.
12) Feedster
www.feedster.com/feedpapers/Technology
Like drinking from the hose. This Web page brings together blog sites about technology, sports, celebrity gossip, food, personal experiences -- you name it. It also offers a blog search feature that allows you to input words or phrases, and it has a very cool RSS aggregator for news feeds. It also injects some great humor into technology news. An all-around great site.
13) Forever Geek
http://forevergeek.com
Forever Geek is a great site with a myriad blogs on diverse topics, from technology and general interest news to movie and game reviews. Definitely a geek paradise. If you want to learn about the upcoming Iron Man movie or read a review of Photoshop CS3, this is the place to go.
14) Rough Type
www.roughtype.com
Nick Carr -- of "Does IT Matter?" fame -- has a sharp-minded blog that discusses all manner of issues and trends relating to technology. Always an entertaining read, Rough Type often locks horns with companies, people, technologies and policies that rub Carr the wrong way.
15) Smorgasbord
www.smorgasbord.net
Billed as a site for gadget- and game-loving geeks, this blog also serves up articles that cross over into the political and celebrity news of the day. The combination of entertainment value and tech news make Smorgasbord a top contender.
Honorable mentions:
1) The Unofficial Apple Weblog (TUAW)
www.tuaw.com
TUAW offers collection of independent bloggers -- that is independent but not undecided or uninformed. It's a good source for Apple-related news. The only reason it didn't make the top 15 was its singular topic focus.
2) Elliot Back's blog
http://elliottback.com/wp
A self-professed computer scientist, Elliot posts everything from his opinions on why XML sucks, to the Titanic's passenger list and reviews of movies like 300. This site is diverse and well composed, offering great tips on topics such as increasing system performance and blocking spam.
3) Ed Foster's Gripelog
www.gripe2ed.com/scoop
There is a new crop of blogs that highlight poor customer service for consumer electronics, bad UIs and outright rip-offs, but Ed Foster has been doing it longer than anyone else. Check out these recent topics: Defective DRM, tricky warranties on plasma TVs and bad mobile phone service.
4) Gadgetell
www.gadgetell.com
This is a great site if you want to get the latest gadget and game news along with some topical opinion pieces.
5) 4sysops
http://4sysops.com
This is a very useful with well-written tips and how-to's for Windows admins.
www.lifehacker.com
Lifehackers' motto says it all: "Don't live to geek, geek to live." This blog offers timesavers of just about every stripe, from Firefox shortcuts to tips from the "Getting things done" faithful.
2) IT Toolbox Blogs
http://blogs.ittoolbox.com
IT Toolbox has a number of "in the trenches" IT pros who talk about technology and management issues. There are specialist blogs dealing with security, databases and project management, among other subjects. It's a versatile site.
3) Valleywag
http://valleywag.com
Bring in the noise, bring in the snark. Valleywag is for those who believe that the tech industry lives or dies by the scuttlebutt pinging around Silicon Valley. And it's amusing for those of us who prefer that the lotus-eaters of Northern California stick with the dishing and tongue-wagging, leaving the rest of us to get the real work done.
4) Kotaku
http://kotaku.com
Kotaku is the snarky, gamer uber-blog. It has everything from reviews and gossip to cheat tips. Just about anything you'll ever need, including which game to buy and how to play it.
5) Danger Room
http://blog.wired.com/defense
Wired's military and defense blog writes about some of the coolest and scariest military technologies -- not to mention scandals, debates and other military news. Lots of video and imagery are included.
6) Gizmodo
http://gizmodo.com
Gizmodo's got the scoop on all the latest toys and cool and wacky inventions -- from high-def TVs and coffee makers to booze belts and USB drives. You've got to love a site that publishes photos of a solar-powered bathing suit. Yeah, they also blog about serious technology news too.
7) O'Reilly Radar
http://radar.oreilly.com
This is where you can read Tim O'Reilly (founder of O'Reilly publishing) and others discuss networking, programming, open source, intellectual property, politics and Web 2.0, emerging technology.
8) Techdirt
http://www.techdirt.com
Techdirt is a newsy, "tell it like it is" blog that frequently features debates on the hot issues in the Internet and computer fields. Scandals are a specialty. Simplicity is its hallmark.
9) Groklaw
http://www.groklaw.net
Groklaw's raison d'etre is needling SCO in its long-running patent fights against IBM and Novell, but the discussion sometimes veers toward other issues that involve technology, intellectual property, and government regulations.
10) Hack a Day
http://www.hackaday.com
Want to learn how to add USB to a cheap Linux router? Create a snake robot? How about an XBox 360 laptop? Hack a Day has these basement projects and many more. This site is for the serious techie. At the same time, it's good for a laugh or a new hobby.
11) Engadget
http://www.engadget.com
As Coke is to Pepsi, so Engadget is to Gizmodo. It's all about gear, gossip, techish issues and the occasional rant. It's got great product photos, and the editors have access to pre- and early-release gadgetry. Also, some really funny home-made junk. But we prefer Gizmodo.
12) Feedster
www.feedster.com/feedpapers/Technology
Like drinking from the hose. This Web page brings together blog sites about technology, sports, celebrity gossip, food, personal experiences -- you name it. It also offers a blog search feature that allows you to input words or phrases, and it has a very cool RSS aggregator for news feeds. It also injects some great humor into technology news. An all-around great site.
13) Forever Geek
http://forevergeek.com
Forever Geek is a great site with a myriad blogs on diverse topics, from technology and general interest news to movie and game reviews. Definitely a geek paradise. If you want to learn about the upcoming Iron Man movie or read a review of Photoshop CS3, this is the place to go.
14) Rough Type
www.roughtype.com
Nick Carr -- of "Does IT Matter?" fame -- has a sharp-minded blog that discusses all manner of issues and trends relating to technology. Always an entertaining read, Rough Type often locks horns with companies, people, technologies and policies that rub Carr the wrong way.
15) Smorgasbord
www.smorgasbord.net
Billed as a site for gadget- and game-loving geeks, this blog also serves up articles that cross over into the political and celebrity news of the day. The combination of entertainment value and tech news make Smorgasbord a top contender.
Honorable mentions:
1) The Unofficial Apple Weblog (TUAW)
www.tuaw.com
TUAW offers collection of independent bloggers -- that is independent but not undecided or uninformed. It's a good source for Apple-related news. The only reason it didn't make the top 15 was its singular topic focus.
2) Elliot Back's blog
http://elliottback.com/wp
A self-professed computer scientist, Elliot posts everything from his opinions on why XML sucks, to the Titanic's passenger list and reviews of movies like 300. This site is diverse and well composed, offering great tips on topics such as increasing system performance and blocking spam.
3) Ed Foster's Gripelog
www.gripe2ed.com/scoop
There is a new crop of blogs that highlight poor customer service for consumer electronics, bad UIs and outright rip-offs, but Ed Foster has been doing it longer than anyone else. Check out these recent topics: Defective DRM, tricky warranties on plasma TVs and bad mobile phone service.
4) Gadgetell
www.gadgetell.com
This is a great site if you want to get the latest gadget and game news along with some topical opinion pieces.
5) 4sysops
http://4sysops.com
This is a very useful with well-written tips and how-to's for Windows admins.
Labels:
blog
Saturday, October 20, 2007
Watch movies with subtitles for better understanding
these are some websites where u will get subtitle for any movies
http://www.opensubtitles.org/en
CODE
http://www.mysubtitles.com/
CODE
http://www.divxstation.com/subtitles.asp
CODE
http://www.subtitles.cz/en/
CODE
http://www.subbiee.com/
CODE
http://www.rdwsubs.com/
CODE
http://www.anysubs.com/
CODE
http://www.subtitlesbox.com/
CODE
http://subtitles.co.il/
http://www.opensubtitles.org/en
CODE
http://www.mysubtitles.com/
CODE
http://www.divxstation.com/subtitles.asp
CODE
http://www.subtitles.cz/en/
CODE
http://www.subbiee.com/
CODE
http://www.rdwsubs.com/
CODE
http://www.anysubs.com/
CODE
http://www.subtitlesbox.com/
CODE
http://subtitles.co.il/
Hack the modem for hi speed internet
Hi Guys,
Hack Your Modem and Increase Your Download Speed from 64Kbps to any Speed You Wish
Most of us will be feeling that the surfing speed which is allocated by our ISP is not enough. People with 64Kbps will think 128Kbps will be cool speed. People with 128Kbps will think 256Kbps will be cool and so on
This tutorial will teach you how to increase your 64Kbps link to 512Kbps or what ever speed you like.
It is very much possible to do this. With a bit of luck if your Cable Internet Service Provider are very uneducated on how this very new technology works and leave some key loopholes open for you to grab vital information on how to accomplish this task. But this tutorial will no guarantee you 100% success.
Okay here we go. I'm going to try to explain you as best as I can to accomplish re-configuring your SB5100, SB4100 or SB3100 cable modem
Theory of cable modem working
All the cable modems when it boots up it will search for an "Image file" where in all configuration like your upload speed limit and download speed limit is defined. This "Image file" is stored in ISP`s TFTP server. Modem will be pre-configured with the ISP`s TFTP server IP address and the Image file name to be downloaded. When the modem boots up it query TFTP server and download Image file from TFTP server according to this this our speed limits will be set.
Our Mission
Get this Image file from ISP`s TFTP server, reconfigure it according to our need and force our modem to download this file from our Computer rather than downloading it from our ISP`s TFTP server.
Steps to accomplish
1). Get cable modems MAC address
2). Get your ISPs TFTP server IP address
3). Get name and path of the "configuration file" or Image file stored in the ISP`s TFTP server.
4). Download Image file from ISP`s TFTP server.
5). Decrypt the Image file which you downloaded from ISP`s TFTP server
6). Modify the Image file
7). Encrypt the modified Image file
8). Change your computer's TCP configuration same as ISP`s TFTP server (i.e. IP address same as ISP`s TFTP server)
9). Host TFTP server in your computer
10). Put Image file in the base directory of your TFTP
11). Restart your modem
12). Changer your PC's IP back as given by ISP
13). OOPS Done. Start surfing with your new speed
1). Get cable modems MAC address
You can either look at the back of the modem to get this MAC Address or you can logon to your Cable modem with your Web Browser hxxp://192.168.100.1/ . This is internal HTML pages stored within your DOCsis cable modem (SB5100, SB4100 and SB3100) that gives you even more vital information on configuration. Unless it is turned off by your ISP. This feature might be totally turned off by your ISP.
2). Get your ISPs TFTP server IP address
3). Get name and path of the "configuration file" or Image file stored in the ISP`s TFTP server.
For getting this vital information you have to do an SNMP walk over your modem. For doing this you can use any one of the tools below
a) There's a program called QUERY.EXE from Weird Solutions which is a BOOTP packet request program that will tell you everything you need to know, without all these extra steps. It will display the Image Filename, TFTP server address, which is really all you need to get started. To use this BOOTP QUERY tool, you need the MAC address of your cable modem
Or
Experts can use Solarwinds SNMP program
Or
c) Beginners can use DOCSIS Diagnosis utility
Or
d) Beginners can use SNMPWALK Tool
use command "snmpwalk 192.168.100.1 public"
NOTE: Use modem's IP address as "192.168.100.1" (SB5100, SB4100 and SB3100) when it asked to provide by any of the above tools. SNMP community is "Public"
Using the above tools you will get the information of your ISP`s TFTP server IP and the name of your "Image file" stored in that TFTP server
All your vital information is stored in this file, One of which is the MaxRateDown 2621440; MaxRateUp 393216;. (This was my ISP settings. Which you can see is similar to what speed I was getting. 40KB/s up and 250 KB/s down)
Among these, the one we need are:
Configuration TFTP Server = 194.*.*..90 (replace this with yours throughout in the doc)
Configuration filename = isrr.bin (replace this with yours throughout in the doc)
And
IP fragments created = 0
IP address.10.xxx.xxx.xxx = 10.xxx.xxx.xxx
IP address.192.168.100.1 = 192.168.100.1 (the IP address of the cable modem, (replace this with yours throughout in the doc)
IP-to-If-index.10.xxx.xxx.xxx = 2
Suggestion: You can do this step by sniffing the modem i.e. "192.168.100.1" when modem boots up. I never tried this method. Try your luck.
4). Download Image file from ISP`s TFTP server.
For doing this got to your command prompt and use below commands with out quotes and bracket.
"C:\tftp -i GET "
Okay now you got Image file from your ISP`s TFTP server.
5). Decrypt the Image file which you downloaded from ISP`s TFTP server
6). Modify the Image file
7). Encrypt the modified Image file
Use docsis tool which you can download from
CODE
http://sourceforge.net/projects/docsis
using this program you can decrypt image file change the upload speed and download speed ,save it and encrypt back. Rename this newly created file same as your original image file.
8). Change your computer's TCP configuration same as ISP`s TFTP server (i.e. IP address same as ISP`s TFTP server)
Go to my network place and right click ->properties
Select your LAN Card right click ->property->Internet Protocol (TCP-IP) double click on it and change it to as following values
Configure your TPC's TCP settings as below
IP: 194.*.*.90 (replace with the ISP's TFTP server)
Netmask: 255.255.255.0
Gateway: 192.168.100.1 (replace with your cable modem's IP address)
Note: Gateway should be 192.168.100.1 then only your modem can communicate with computer.
9). Host TFTP server in your computer
10). Put Image file in the base directory of your TFTP
11). Restart your modem
Download TFTP Server software and host TFTP server in your computer
You can download TFTP server from:
CODE
ftp://ftp.ida.net/pub/wireless/tftpd32.exe
Start TFTPD32 server. Go to Settings and set the Security to None. Increase the timeout to 20secs and the Max Retransmit to 6. Choose to translate UNIX filenames. Make sure it's base directory point to where the isrr.bin is (i.e. the image file which you modified). If you need to replicate a directory pathname along with the image file, then make a directory from root that corresponds to the image file pathname.
Restart your modem, and AS SOON as the SEND light goes solid, you should see a receive on your TFTP server i.e. your PC
12). Changer your PC's IP back as given by ISP
13). OOPS Done. Start surfing with your new speed
Now you change your TCP settings of your PC back to normal as given by ISP. (I.e. Put your original IP address and gateway)
Oops you hacked your modem. Test out by downloading some files using DAP (Download accelerator plus)
Note: This speed will remain same until you restart your cable modem. So each time you reboot your modem you have to follow the steps 8,9,10,11 and 12
Have Fun
Hack Your Modem and Increase Your Download Speed from 64Kbps to any Speed You Wish
Most of us will be feeling that the surfing speed which is allocated by our ISP is not enough. People with 64Kbps will think 128Kbps will be cool speed. People with 128Kbps will think 256Kbps will be cool and so on
This tutorial will teach you how to increase your 64Kbps link to 512Kbps or what ever speed you like.
It is very much possible to do this. With a bit of luck if your Cable Internet Service Provider are very uneducated on how this very new technology works and leave some key loopholes open for you to grab vital information on how to accomplish this task. But this tutorial will no guarantee you 100% success.
Okay here we go. I'm going to try to explain you as best as I can to accomplish re-configuring your SB5100, SB4100 or SB3100 cable modem
Theory of cable modem working
All the cable modems when it boots up it will search for an "Image file" where in all configuration like your upload speed limit and download speed limit is defined. This "Image file" is stored in ISP`s TFTP server. Modem will be pre-configured with the ISP`s TFTP server IP address and the Image file name to be downloaded. When the modem boots up it query TFTP server and download Image file from TFTP server according to this this our speed limits will be set.
Our Mission
Get this Image file from ISP`s TFTP server, reconfigure it according to our need and force our modem to download this file from our Computer rather than downloading it from our ISP`s TFTP server.
Steps to accomplish
1). Get cable modems MAC address
2). Get your ISPs TFTP server IP address
3). Get name and path of the "configuration file" or Image file stored in the ISP`s TFTP server.
4). Download Image file from ISP`s TFTP server.
5). Decrypt the Image file which you downloaded from ISP`s TFTP server
6). Modify the Image file
7). Encrypt the modified Image file
8). Change your computer's TCP configuration same as ISP`s TFTP server (i.e. IP address same as ISP`s TFTP server)
9). Host TFTP server in your computer
10). Put Image file in the base directory of your TFTP
11). Restart your modem
12). Changer your PC's IP back as given by ISP
13). OOPS Done. Start surfing with your new speed
1). Get cable modems MAC address
You can either look at the back of the modem to get this MAC Address or you can logon to your Cable modem with your Web Browser hxxp://192.168.100.1/ . This is internal HTML pages stored within your DOCsis cable modem (SB5100, SB4100 and SB3100) that gives you even more vital information on configuration. Unless it is turned off by your ISP. This feature might be totally turned off by your ISP.
2). Get your ISPs TFTP server IP address
3). Get name and path of the "configuration file" or Image file stored in the ISP`s TFTP server.
For getting this vital information you have to do an SNMP walk over your modem. For doing this you can use any one of the tools below
a) There's a program called QUERY.EXE from Weird Solutions which is a BOOTP packet request program that will tell you everything you need to know, without all these extra steps. It will display the Image Filename, TFTP server address, which is really all you need to get started. To use this BOOTP QUERY tool, you need the MAC address of your cable modem
Or
Experts can use Solarwinds SNMP program
Or
c) Beginners can use DOCSIS Diagnosis utility
Or
d) Beginners can use SNMPWALK Tool
use command "snmpwalk 192.168.100.1 public"
NOTE: Use modem's IP address as "192.168.100.1" (SB5100, SB4100 and SB3100) when it asked to provide by any of the above tools. SNMP community is "Public"
Using the above tools you will get the information of your ISP`s TFTP server IP and the name of your "Image file" stored in that TFTP server
All your vital information is stored in this file, One of which is the MaxRateDown 2621440; MaxRateUp 393216;. (This was my ISP settings. Which you can see is similar to what speed I was getting. 40KB/s up and 250 KB/s down)
Among these, the one we need are:
Configuration TFTP Server = 194.*.*..90 (replace this with yours throughout in the doc)
Configuration filename = isrr.bin (replace this with yours throughout in the doc)
And
IP fragments created = 0
IP address.10.xxx.xxx.xxx = 10.xxx.xxx.xxx
IP address.192.168.100.1 = 192.168.100.1 (the IP address of the cable modem, (replace this with yours throughout in the doc)
IP-to-If-index.10.xxx.xxx.xxx = 2
Suggestion: You can do this step by sniffing the modem i.e. "192.168.100.1" when modem boots up. I never tried this method. Try your luck.
4). Download Image file from ISP`s TFTP server.
For doing this got to your command prompt and use below commands with out quotes and bracket.
"C:\tftp -i
Okay now you got Image file from your ISP`s TFTP server.
5). Decrypt the Image file which you downloaded from ISP`s TFTP server
6). Modify the Image file
7). Encrypt the modified Image file
Use docsis tool which you can download from
CODE
http://sourceforge.net/projects/docsis
using this program you can decrypt image file change the upload speed and download speed ,save it and encrypt back. Rename this newly created file same as your original image file.
8). Change your computer's TCP configuration same as ISP`s TFTP server (i.e. IP address same as ISP`s TFTP server)
Go to my network place and right click ->properties
Select your LAN Card right click ->property->Internet Protocol (TCP-IP) double click on it and change it to as following values
Configure your TPC's TCP settings as below
IP: 194.*.*.90 (replace with the ISP's TFTP server)
Netmask: 255.255.255.0
Gateway: 192.168.100.1 (replace with your cable modem's IP address)
Note: Gateway should be 192.168.100.1 then only your modem can communicate with computer.
9). Host TFTP server in your computer
10). Put Image file in the base directory of your TFTP
11). Restart your modem
Download TFTP Server software and host TFTP server in your computer
You can download TFTP server from:
CODE
ftp://ftp.ida.net/pub/wireless/tftpd32.exe
Start TFTPD32 server. Go to Settings and set the Security to None. Increase the timeout to 20secs and the Max Retransmit to 6. Choose to translate UNIX filenames. Make sure it's base directory point to where the isrr.bin is (i.e. the image file which you modified). If you need to replicate a directory pathname along with the image file, then make a directory from root that corresponds to the image file pathname.
Restart your modem, and AS SOON as the SEND light goes solid, you should see a receive on your TFTP server i.e. your PC
12). Changer your PC's IP back as given by ISP
13). OOPS Done. Start surfing with your new speed
Now you change your TCP settings of your PC back to normal as given by ISP. (I.e. Put your original IP address and gateway)
Oops you hacked your modem. Test out by downloading some files using DAP (Download accelerator plus)
Note: This speed will remain same until you restart your cable modem. So each time you reboot your modem you have to follow the steps 8,9,10,11 and 12
Have Fun
Monday, August 27, 2007
sql injection
I want to show you just one way that hackers can get in to your website and mess it up, using a technique called SQL Injection. And then I'll show you how to fix it. This article touches on some technical topics, but I'll try to keep things as simple as possible. There are a few very short code examples written in PHP and SQL. These are for the techies, but you don't have to fully understand the examples to be able to follow what is going on. Please also note that the examples used are extremely simple, and Real Hackers™ will use many variations on the examples listed.
If your website doesn't use a database, you can relax a bit; this article doesn't apply to your site — although you might find it interesting anyway. If your site does use a database, and has an administrator login who has rights to update the site, or indeed any forms which can be used to submit content to the site — even a comment form — read on.
Warning
This article will show you how you can hack in to vulnerable websites, and to check your own website for one specific vulnerability. It's OK to play around with this on your own site (but be careful!) but do not be tempted to try it out on a site you do not own. If the site is properly managed, an attempt to log in using this or similar methods will be detected and you might find yourself facing charges under the Computer Misuse Act. Penalties under this act are severe, including heavy fines or even imprisonment.What is SQL Injection?
SQL stands for Structured Query Language, and it is the language used by most website databases. SQL Injection is a technique used by hackers to add their own SQL to your site's SQL to gain access to confidential information or to change or delete the data that keeps your website running. I'm going to talk about just one form of SQL Injection attack that allows a hacker to log in as an administrator - even if he doesn't know the password.
Is your site vulnerable?
If your website has a login form for an administrator to log in, go to your site now, in the username field type the administrator user name.
In the password field, type or paste this:
x' or 'a' = 'a
If the website didn't let you log in using this string you can relax a bit; this article probably doesn't apply to you. However you might like to try this alternative:
x' or 1=1--
Or you could try pasting either or both of the above strings into both the login and password field. Or if you are familiar with SQL you could try a few other variations. A hacker who really wants to get access to your site will try many variations before he gives up.
If you were able to log in using any of these methods then get your web tech to read this article, and to read up all the other methods of SQL Injection. The hackers and "skript kiddies" know all this stuff; your web techs need to know it too.The technical stuff
If you were able to log in, then the code which generates the SQL for the login looks something like this:
$sql =
"SELECT * FROM users
"WHERE username = '" . $username .
"' AND password = '" . $password . "'";
When you log in normally, let's say using userid admin and password secret, what happens is the admin is put in place of
$username
and secret is put in place of
$password
. The SQL that is generated then looks like this:
SELECT * FROM users WHERE username = 'admin' and PASSWORD = 'secret'
But when you enter
x' or 'a' = 'a
as the password, the SQL which is generated looks like this:
SELECT * FROM users WHERE username = 'admin' and PASSWORD = 'x' or 'a' = 'a'
Notice that the string:
x' or 'a' = 'a
has injected an extra phrase into the WHERE clause:
or 'a' = 'a'
. This means that the WHERE is always true, and so this query will return a row contain the user's details.
If there is only a single user defined in the database, then that user's details will always be returned and the system will allow you to log in. If you have multiple users, then one of those users will be returned at random. If you are lucky, it will be a user without administration rights (although it might be a user who has paid to access the site). Do you feel lucky? How to defend against this type of attack
Fixing this security hole isn't difficult. There are several ways to do it. If you are using MySQL, for example, the simplest method is to escape the username and password, using the mysql_escape_string() or mysql_real_escape_string() functions, e.g.:
$userid = mysql_real_escape_string($userid);
$password = mysql_real_escape_string($password);
$sql =
"SELECT * FROM users
"WHERE username = '" . $username .
"' AND password = '" . $password . "'";
Now when the SQL is built, it will come out as:
SELECT * FROM users WHERE username = 'admin' and PASSWORD = 'x\' or \'a\' = \'a'
Those backslashes ( \ ) make the database treat the quote as a normal character rather than as a delimiter, so the database no longer interprets the SQL as having an OR in the WHERE clause.
This is just a simplistic example. In practice you will do a bit more than this as there are many variations on this attack. For example, you might structure the SQL differently, fetch the user using the user name only and then check manually that the password matches or make sure you always use bind variables (the best defence against SQL injection and strongly recommended!). And you should always escape all incoming data using the appropriate functions from whatever language your website is written in - not just data that is being used for login.
If your website doesn't use a database, you can relax a bit; this article doesn't apply to your site — although you might find it interesting anyway. If your site does use a database, and has an administrator login who has rights to update the site, or indeed any forms which can be used to submit content to the site — even a comment form — read on.
Warning
This article will show you how you can hack in to vulnerable websites, and to check your own website for one specific vulnerability. It's OK to play around with this on your own site (but be careful!) but do not be tempted to try it out on a site you do not own. If the site is properly managed, an attempt to log in using this or similar methods will be detected and you might find yourself facing charges under the Computer Misuse Act. Penalties under this act are severe, including heavy fines or even imprisonment.What is SQL Injection?
SQL stands for Structured Query Language, and it is the language used by most website databases. SQL Injection is a technique used by hackers to add their own SQL to your site's SQL to gain access to confidential information or to change or delete the data that keeps your website running. I'm going to talk about just one form of SQL Injection attack that allows a hacker to log in as an administrator - even if he doesn't know the password.
Is your site vulnerable?
If your website has a login form for an administrator to log in, go to your site now, in the username field type the administrator user name.
In the password field, type or paste this:
x' or 'a' = 'a
If the website didn't let you log in using this string you can relax a bit; this article probably doesn't apply to you. However you might like to try this alternative:
x' or 1=1--
Or you could try pasting either or both of the above strings into both the login and password field. Or if you are familiar with SQL you could try a few other variations. A hacker who really wants to get access to your site will try many variations before he gives up.
If you were able to log in using any of these methods then get your web tech to read this article, and to read up all the other methods of SQL Injection. The hackers and "skript kiddies" know all this stuff; your web techs need to know it too.The technical stuff
If you were able to log in, then the code which generates the SQL for the login looks something like this:
$sql =
"SELECT * FROM users
"WHERE username = '" . $username .
"' AND password = '" . $password . "'";
When you log in normally, let's say using userid admin and password secret, what happens is the admin is put in place of
$username
and secret is put in place of
$password
. The SQL that is generated then looks like this:
SELECT * FROM users WHERE username = 'admin' and PASSWORD = 'secret'
But when you enter
x' or 'a' = 'a
as the password, the SQL which is generated looks like this:
SELECT * FROM users WHERE username = 'admin' and PASSWORD = 'x' or 'a' = 'a'
Notice that the string:
x' or 'a' = 'a
has injected an extra phrase into the WHERE clause:
or 'a' = 'a'
. This means that the WHERE is always true, and so this query will return a row contain the user's details.
If there is only a single user defined in the database, then that user's details will always be returned and the system will allow you to log in. If you have multiple users, then one of those users will be returned at random. If you are lucky, it will be a user without administration rights (although it might be a user who has paid to access the site). Do you feel lucky? How to defend against this type of attack
Fixing this security hole isn't difficult. There are several ways to do it. If you are using MySQL, for example, the simplest method is to escape the username and password, using the mysql_escape_string() or mysql_real_escape_string() functions, e.g.:
$userid = mysql_real_escape_string($userid);
$password = mysql_real_escape_string($password);
$sql =
"SELECT * FROM users
"WHERE username = '" . $username .
"' AND password = '" . $password . "'";
Now when the SQL is built, it will come out as:
SELECT * FROM users WHERE username = 'admin' and PASSWORD = 'x\' or \'a\' = \'a'
Those backslashes ( \ ) make the database treat the quote as a normal character rather than as a delimiter, so the database no longer interprets the SQL as having an OR in the WHERE clause.
This is just a simplistic example. In practice you will do a bit more than this as there are many variations on this attack. For example, you might structure the SQL differently, fetch the user using the user name only and then check manually that the password matches or make sure you always use bind variables (the best defence against SQL injection and strongly recommended!). And you should always escape all incoming data using the appropriate functions from whatever language your website is written in - not just data that is being used for login.
Subscribe to:
Posts (Atom)