导航

Web安全手册

分享本身就是件快乐的事 我因别人得到帮助而感到幸福

« XSS Tunnel入侵骗子站xuehk.com全过程 »

Sql Injection Challenge How-to

The Sql Injection Challenge has already been completed, so here is a video demonstration on how to find this Sql Injection flaw and exploited it to extract password hashes. In this video I use a firefox plugin ‘Data Tamper’ that can be download here

  • quote 4.anti
  • 文件大小规模65M,速度当然慢了,查源码,直接下载本地不就完了.Tr4c3.
    Tr4c3 于 2009-5-28 12:58:09 回复
    我这里在线看也比较流畅,不用下回来的。
  • 2009-5-28 1:27:42 回复该留言
  • quote 2.xi4oyu
  • 很赞啊,国内的教程啥时候能这么详细就好了,呵呵
  • 2008-11-29 11:17:33 回复该留言
  • quote 1.lAnG
  • Cool.
    Another very useful tool is Fiddler, which works as a HTTP proxy, monitoring and pre processing all the HTTP requests and responses.(Require .Net runtime support)
    People can set conditional break point, stop and modify the request/response data, build new request from an existing request, or even, write scripts(in C#) to handle the requests automaticly.

    哈哈,装一下 ^_^
    Tr4c3 于 2008-10-6 17:54:41 回复
    还有几个代理程序都不错,改天做个比较一并整理贴出来。
  • 2008-10-6 12:45:55 回复该留言

发表评论:

◎欢迎参与讨论,请在这里发表您的看法、交流您的观点。

Powered By Z-Blog .Theme from Google黑板报 By Washun

Copyright 2008-2009 Pcsec.org. Some Rights Reserved.苏ICP备08110306号

Search

网站分类

文章归档

最新评论及回复

最近发表