Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 12 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
ChicagoCon 2008f
chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Featuresarrow Skillzarrow Examplesarrow Example 1: Winners
Ethical Hacker Community Forums
August 29, 2008, 12:51:03 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Registration Now Open for ChicagoCon 2008f Oct 27 - Nov 2! Visit www.chicagocon.com.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Example 1: Winners  (Read 2234 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2229


Editor-In-Chief


View Profile WWW
« on: April 11, 2006, 10:30:44 PM »

See Original Announcement at http://www.counterhack.net/trinity_winners.html

The competition for this Trinity-themed CRACK THE HACKER challenge was intense. We received over 50 entries, and many had very solid answers. I've picked the five best, which certainly wasn't an easy task. Of these five seriously smart dudes, the top two winners will receive a copy of my Counter Hack book.

While lots of you got the right answer, several folks asked about that IP address. While it is indeed registered to someone in the Netherlands and houses a variety of different web servers, it is also the home of little ol' www.counterhack.net, my own web site.

Also, many people were confused by the second set of user input:

irsfile.asp?username='test'+UNION+SELECT+name,1,'1',1,'1'+FROM+irs_dbase..sy sobjects+WHERE+xtype+=+'U';--

With this input, Trinity is using a UNION statement to merge the results of the built-in database query with a SELECT statement of her own. Trinity's own SELECT statement is asking for the "name" field (followed by a bunch of 1's to make the UNION between the original ASP's SELECT and Trinity's SELECT parallel with the same number and type of fields). But she's getting the "name" from the irs_dbase...sysobjects file. In a Microsoft SQL Server database, the [database_name]..sysobjects file is a metadata table holding information about the structure of the database itself, including the names of tables and columns. It doesn't hold user names; it contains data about the database. The xtype='U' simply means that Trinity wants to retrieve user-defined table names from the metadata. So, by running this command, Trinity is looking for the name of tables in the database. She can then query those tables to get more information.

Each winner did a solid job, and I'd like to congratulate them on their prowess. They took on the role of Agent Smith and nailed the technical details of the case. In fact, they assumed the role of Agent Smith a bit too easily, if you ask me. Perhaps these guys aren't quite what they seem?  ; )

The winners are:

Raul Siles... whose answer is here. His very detailed analysis is simply wonderful, and quite educational. I very much enjoyed reading it, and strongly recommend it to you if you want to learn more about SQL Injection against web applications using Microsoft SQL Server databases. Raul does a great job of documenting how the attack worked, with nice references for more information. EXCELLENT JOB!

Joe Klein... whose answer is here. His answer is technically right-on, and quite fun.

The runners up (sorry, no book this time!) are:

Mike Poor... whose answer is here. Mr. Poor's answer made me laugh out loud. He had the best answer to the first and second questions! Spot on.

Mike Luedke... whose answer is here. Mr. Luedke had a very nice technical answer to the "ping" question.  I also like the part about his reference to the "ancient" security guy, Ed Skoudis.  ; )

Camillo Särs... whose answer is here.  Amazingly, Mr. Särs even manages to sneak in a few Dilbert references into his response. Nice!

Good work, folks. Please stay tuned for another challenge, in the July/August timeframe. In the mean time, enjoy your countless viewings of Matrix Reloaded.

--Ed.
Logged

CISSP, MCSE, CEH, Security+ SME
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.5 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.045 seconds with 24 queries.
 

EH-Net's
2nd Annual
Tweener Party
 

Thanks all. Click HERE for details.

Polls
Best for daily desktop use:
 
Support EH-Net
chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f
 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.