Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 40 guests and 1 member online
 
Advertisement

You are here: Home
EH-Net
May 20, 2013, 10:50:49 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1]
1  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: SQL injection string encoding on: August 20, 2011, 03:58:35 PM
Btw I have no idea why the text is formed like that. I didn't type it that way.
2  Ethical Hacking Discussions and Related Certifications / Web Applications / SQL injection string encoding on: August 20, 2011, 01:54:22 PM
What kind of encodings are used for bypassing SQL filters? Does Hex or Base64 work? What other kinds of encodings are used for this? And if I'm trying to test the filter of a login function,
can I just put the encoded string into the input field, or do I need to use an intercepting proxy?
I know a proxy has to be used for things that aren't editable like cookies, http headers etc but do I need a proxy for things I can directly edit, like input fields?
3  Ethical Hacking Discussions and Related Certifications / Programming / Re: Suggest me a e-book for understanding basics of buffer over flow? on: August 20, 2011, 11:16:41 AM
If you want a book, you should read Hacking: The Art Of Exploitation. Even if you cant program in C or Assembly it should get you into writing exploits. If you can do that well, you should read The Shellcoders Handbook, which goes a little bit further than The Art Of Exploitation but both will teach you how to write exploits, and how exploits work.
4  Ethical Hacking Discussions and Related Certifications / Programming / Re: Hello World Computer Programming - What Next? on: August 20, 2011, 11:13:44 AM
If you want to learn exploit development you're gonna have to learn C eventually, and possibly Assembly. Python will also be useful. But I would suggest reading Gray Hat Python for this.
5  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: XSS snatching cookie without domain on: August 19, 2011, 06:33:31 AM
Okay, thanks. That answers my question nicely  Grin
6  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: XSS snatching cookie without domain on: August 18, 2011, 04:31:25 PM
I thought Javascript code was limited to client-side browser stuff. Can Javascript even make a TCP connection? If it can, then yes that would answer my question very nicely. But I was thinking more along the lines of something like emailing the contents of the cookie, or some other web-related method of delivering it but that will work well. Thanks.
7  Ethical Hacking Discussions and Related Certifications / Web Applications / XSS snatching cookie without domain on: August 18, 2011, 01:39:29 PM
Okay I'm new to this site so I'm hoping me question doesn't come off as malicious. This is for school, so I'm not trying to do anything evil. Anyways, I was wondering if its possible to snatch a cookie using XSS, and deliver it to an attacker without sending it to an attacker controlled domain. Like if an attacker didn't own a domain, or if the domain was blocked, is there any other method or trick that can be used to recieve the cookie? I can code in Javascript relatively well, so you can talk about Javascript functions, methods etc. And thats encouraged because I'm interested in the coding perspective so please give me your ideas. Thanks.  Grin
8  Ethical Hacking Discussions and Related Certifications / Web Applications / Re: Learning Web Security on: August 18, 2011, 12:13:51 PM
I personally don't think so, but thats just my opinion. I would recommend reading books on Javascript. But w3schools should get you a great start at the very least, so its a good place to begin.
Pages: [1]
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.055 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.