did something stupid today..hope it's not serious

Discussion in 'General Chat' started by gunjack07, Sep 8, 2007.

  1. #1
    today i read about sql injection etc... i wanted to try it on 2 sites...(these are 2 sites i very often visit and like very much)...i just wanted to see whether they were sql injection proof....nothing malicious... would have informed the webmaster if they weren't..

    but now feeling guilty and worried... is it serious what i did??
     
    gunjack07, Sep 8, 2007 IP
  2. bacanze

    bacanze Peon

    Messages:
    2,419
    Likes Received:
    127
    Best Answers:
    0
    Trophy Points:
    0
    #2
    What did you do?
     
    bacanze, Sep 8, 2007 IP
  3. gunjack07

    gunjack07 Peon

    Messages:
    6
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #3
    just a very minor sql injection trick to login without an account... i was just experimenting... i experimented on my own website and my site was vulnerable lol... just discovered about sql injection today
     
    gunjack07, Sep 8, 2007 IP
  4. mailboxstas1254

    mailboxstas1254 Banned

    Messages:
    4
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #4
    it's bad. I cant believe there is still sql injection exists
     
    mailboxstas1254, Sep 8, 2007 IP
  5. bogart

    bogart Notable Member

    Messages:
    10,911
    Likes Received:
    509
    Best Answers:
    0
    Trophy Points:
    235
    #5
    Don't do it
     
    bogart, Sep 8, 2007 IP
  6. gunjack07

    gunjack07 Peon

    Messages:
    6
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #6
    yeah i was just experimenting..won't do it again
     
    gunjack07, Sep 8, 2007 IP
  7. Grumps

    Grumps Peon

    Messages:
    592
    Likes Received:
    13
    Best Answers:
    0
    Trophy Points:
    0
    #7
    Most programmer often forget to filter up sql injection when they are coding their site. Did you tell the guy after you did it?
     
    Grumps, Sep 9, 2007 IP
  8. Cash4master

    Cash4master Banned

    Messages:
    233
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #8
    man,it is hacking what you did:eek:.Please don't do it again or you will fall in trouble.
    So far as i know it is used for hacking private things like username or passwords and etc thing.
    Please donot try it ever!
     
    Cash4master, Sep 9, 2007 IP
  9. flash902007

    flash902007 Banned

    Messages:
    750
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    0
    #9
    i never even heard of it before. lol
     
    flash902007, Sep 9, 2007 IP
  10. mightyb

    mightyb Banned

    Messages:
    6,566
    Likes Received:
    405
    Best Answers:
    0
    Trophy Points:
    0
    #10
    You are such a script kiddie! At least you have conscience :D


    Don't worry about it, youl be fine. But if you do get caught you will have problems explaining what you did. Experiment excuse might not work. Just don't do it again.
     
    mightyb, Sep 9, 2007 IP
  11. gunjack07

    gunjack07 Peon

    Messages:
    6
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #11
    yep won't do it again.... was just curious whether people are protected or not against sql injection... apparently most are aware of it.... and at least with this thread some are now aware about sql injection....

    btw any good guide to protect against sql injection..i just used addslashes() in php..it's not sufficient i guess isn't it?
     
    gunjack07, Sep 9, 2007 IP
  12. mightyb

    mightyb Banned

    Messages:
    6,566
    Likes Received:
    405
    Best Answers:
    0
    Trophy Points:
    0
    #12
    Well i guess most php scripts have some sort of vulnerability. Its just too easy to write something quickly and sell it. Even more serious scripts like VB update all the time as more holes are discovered.
     
    mightyb, Sep 9, 2007 IP
  13. dariusdegreat

    dariusdegreat Banned

    Messages:
    22
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #13
    interesting. I will have to do some reading about SQL injection and make my sites safe ...
     
    dariusdegreat, Sep 9, 2007 IP
  14. Village_Idiot

    Village_Idiot Peon

    Messages:
    162
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #14
    Many programmers don't clean queries. If you didn't do any permanent damage, you are fine. Ive hacked more login systems then I can count, I take a screenshot in the admins account then email him. I have no care to do any damage to a site, I offer my services to them however.

    Its a good business tactic, I've never ran into anyone who was mad for what I did. They also trust the knowledge of someone who can hack.
     
    Village_Idiot, Sep 9, 2007 IP