<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="/style/rss/rss_feed.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="/style/rss/rss_feed.css" type="text/css" media="screen" ?><rss version="2.0"><channel><title>Clipmarks | serkanserttop's clips</title><link>http://clipmarks.com/clipper/serkanserttop/</link><feedUrl>http://rss.clipmarks.com/clipper/serkanserttop/</feedUrl><ttl>15</ttl><description>Clip, tag and save information that's important to you. Bookmarks save entire pages...Clipmarks save the specific content that matters to you!</description><language>en-us</language><item><title>eksi sql injection</title><link>http://clipmarks.com/clipmark/14609763-B3DA-4082-A342-8BD09BDEAC5E/</link><description>&lt;b&gt;clipped by:&lt;/b&gt; &lt;a href="http://clipmarks.com/clipper/serkanserttop/"&gt;serkanserttop&lt;/a&gt;&lt;br&gt;&lt;div border="2" style="margin-top: 10px; border:#000000 1px solid;" width="90%"&gt;&lt;div style="background-color:"&gt;&lt;div align="center" width="100%" style="padding:4px;margin-bottom:4px;background-color:#666666;overflow:hidden;"&gt;&lt;span style="color:#FFFFFF;font-weight:bold;"&gt;Clip Source: &lt;a style="color:#FFFFFF;" href="http://sozluk.sourtimes.org/show.asp?t=sql+injection" title="http://sozluk.sourtimes.org/show.asp?t=sql+injection"&gt;sozluk.sourtimes.org&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="padding: 10px;"&gt;&lt;div style="text-align:left;"&gt;&lt;LI id="d9343613" value="10"&gt;site uzerinde bu açığı kullanmak için ilk dikkat etmeniz gereken şey hangi formu submit ettiğinizde veritabanı sorgusu sonucu size ordan bazı verileri gösterecektir. örnek olarak search formları veya çoklu dataları kısaltan veri giriş noktaları verilebilir.&lt;BR /&gt;bizim amacımız genelde bu form submitlerinden sonra o tabloların ustune yeni tablolar çekmektir. formları nasıl bulucam diye düşünenlere firefox kullanmaları ve sayfaya sağ tıklayıp view page info dedikten sonra forms kısmına bakmalarıdır. ordan hangi adresin hangi değişkeni aldığı görülebilir.&lt;BR /&gt;mesela www.hedehede.com/uyelistesi.asp?sehir=istanbul&amp;ilce=adalar&lt;BR /&gt;şimdi biz burda bu tablonun altına yeni bir tablo almaya çalışıcaz&lt;BR /&gt;www.hedehede.com/uyelistesi.asp?sehir=istanbul&amp;ilce=adalar ' union select table_name from information_schema.tables--&lt;BR /&gt;bu bize serverdaki tabloların isimlerini verir. ancak union operatoru gereği bizim istediğimiz tablonun kolon sayısı ile üstteki tablonun kolon sayısı aynı olmak zorundadır. bu nedenle o tip bir mesaj alırsanız table_name, table_name şeklinde arttırarak denemelerinize devam edebilirsiniz. &lt;BR /&gt;eğer tablo isimlerini çekebildiyseniz istediğiniz tabloyu gözünüze kesitebilir ' union select column_name from information_schema.columns where table_name='tablename'-- şeklinde o tablonunun column namelerini çekebilirsiniz. ondan sonra istediğiniz bilgiye hangi tablodan ulaşabileceğinizi tahmin edip sorgu çekmektir.&lt;BR /&gt;sql injection yeme potansiyeli yuksek olan formlar değişkenini bir linkten okuyan formlardır.&lt;BR /&gt;bu sql injection yöntemi ozellikle forumlarda çok yoğun bir şekilde kullanılabilir.&lt;DIV class="aul"&gt;(&lt;A href="http://sozluk.sourtimes.org/show.asp?t=liontrainer"&gt;liontrainer&lt;/A&gt;, 31.03.2006 01:08)&lt;SPAN&gt;&lt;TABLE id="m9343613"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD class="ei"&gt;&lt;A href="javascript:alert('This link contains javascript. Please visit the clip source to follow this link.');" target="_self"&gt;#9343613&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD title="%24ikayet%20et" class="but"&gt;&lt;A class="icon" href="javascript:alert('This link contains javascript. Please visit the clip source to follow this link.');" target="_self"&gt; !? &lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;br&gt;&lt;div style="margin-bottom: 40px;"&gt;Tags: &lt;a href="http://clipmarks.com/tags/sql+injections/" rel="tag"&gt;sql injections&lt;/a&gt;&lt;/div&gt;</description><clipSource>http://sozluk.sourtimes.org/show.asp?t=sql+injection</clipSource><pubDate>Sat, 23 Dec 2006 16:42:27 GMT</pubDate></item><item><title>hackthroughforms</title><link>http://clipmarks.com/clipmark/42149479-422A-4471-8D92-77C54A9A7FEE/</link><description>&lt;b&gt;clipped by:&lt;/b&gt; &lt;a href="http://clipmarks.com/clipper/serkanserttop/"&gt;serkanserttop&lt;/a&gt;&lt;br&gt;&lt;div border="2" style="margin-top: 10px; border:#000000 1px solid;" width="90%"&gt;&lt;div style="background-color:"&gt;&lt;div align="center" width="100%" style="padding:4px;margin-bottom:4px;background-color:#666666;overflow:hidden;"&gt;&lt;span style="color:#FFFFFF;font-weight:bold;"&gt;Clip Source: &lt;a style="color:#FFFFFF;" href="http://forum.joomla.org/index.php/topic,86525.300.html" title="http://forum.joomla.org/index.php/topic,86525.300.html"&gt;forum.joomla.org&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="padding: 10px;"&gt;&lt;div style="text-align:left;"&gt;&lt;DIV class="post"&gt;&lt;DIV&gt;Big thanks to all for the information provided.&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;Today I received 222 emails instantly from a spammer trying to find security holes in one of my joomla sites.  Lots of injection headings and etc it looked like.  I ftp'd in to get the log files and ban the offending IP.&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;I noticed my media directory had an updated date of today which was wrong and inside I found a scanner that had just been uploaded and started running.  The date matched the email time so I figure one of the spam emails submited gave info on a security hole which was probably that gloabls were on by server default.&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;I'm running only FacileForms and Bookmarks on the site in question only.&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;The scanner was generating files as I was looking so I turned global registers off, removed all the files and so far it hasn't restarted.&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;I just thought it was interesting that they would do injection querys by contat form?  Just a heads up!  Thanks again for the info on how to turn these off in htaccess.&lt;/DIV&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;br&gt;&lt;div style="margin-bottom: 40px;"&gt;Tags: &lt;a href="http://clipmarks.com/tags/hack/" rel="tag"&gt;hack&lt;/a&gt;, &lt;a href="http://clipmarks.com/tags/sql+injections/" rel="tag"&gt;sql injections&lt;/a&gt;, &lt;a href="http://clipmarks.com/tags/forms/" rel="tag"&gt;forms&lt;/a&gt;&lt;/div&gt;</description><clipSource>http://forum.joomla.org/index.php/topic,86525.300.html</clipSource><pubDate>Sat, 23 Dec 2006 14:38:20 GMT</pubDate></item><item><title>joomla globals</title><link>http://clipmarks.com/clipmark/EA63396D-771D-4BE9-8240-9F5FD7486634/</link><description>&lt;b&gt;clipped by:&lt;/b&gt; &lt;a href="http://clipmarks.com/clipper/serkanserttop/"&gt;serkanserttop&lt;/a&gt;&lt;br&gt;&lt;div border="2" style="margin-top: 10px; border:#000000 1px solid;" width="90%"&gt;&lt;div style="background-color:"&gt;&lt;div align="center" width="100%" style="padding:4px;margin-bottom:4px;background-color:#666666;overflow:hidden;"&gt;&lt;span style="color:#FFFFFF;font-weight:bold;"&gt;Clip Source: &lt;a style="color:#FFFFFF;" href="http://forum.joomla.org/index.php/topic,89866.msg455550.html" title="http://forum.joomla.org/index.php/topic,89866.msg455550.html"&gt;forum.joomla.org&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="padding: 10px;"&gt;&lt;div style="text-align:left;"&gt;&lt;DIV class="post"&gt;&lt;B&gt;WARNING! &lt;BR /&gt;------------GLOBAL MOD EDIT: last minute small bug found in admin.mambots.php&lt;BR /&gt;&lt;DIV&gt;While waiting for new package (1.0.12), find file below.&lt;/DIV&gt;&lt;BR /&gt;This is an official fix!&lt;/B&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;EDIT: You have to be registered on this forum to see the link to download the file. Sorry for this inconvenience.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;Unzip file and place into "/administrator/components/com_mambots"&lt;/DIV&gt;&lt;/div&gt;&lt;/div&gt;&lt;hr size="2" color="#666666" /&gt;&lt;div style="padding: 10px;"&gt;&lt;div style="text-align:left;"&gt;&lt;table background="undefined" bgcolor=""&gt;&lt;tr&gt;&lt;TD width="85%" valign="bottom" class="smalltext"&gt;
							&lt;TABLE width="100%" border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;
								&lt;TD width="100%" class="smalltext" colspan="2"&gt;
									&lt;HR width="100%" size="1" class="hrcolor" /&gt;
									&lt;DIV&gt;
										&lt;A href="http://forum.joomla.org/index.php?action=dlattach%3Btopic=89866.0%3Battach=19280" set="yes"&gt;&lt;IMG border="0" align="middle" alt="*" src="http://forum.joomla.org/Themes/joomla/images/icons/clip.gif" /&gt; admin.mambots.php.zip&lt;/A&gt; (4.14 KB - downloaded 14856 times.)&lt;BR /&gt;
									&lt;/DIV&gt;
								&lt;/TD&gt;
							&lt;/TR&gt;&lt;TR&gt;
								&lt;TD valign="bottom" class="smalltext"&gt;
									« &lt;I&gt;Last Edit: October 20, 2006, 11:55:33 PM by infograf768&lt;/I&gt; »
								&lt;/TD&gt;
								&lt;TD valign="bottom" align="right" class="smalltext"&gt;
									&lt;A href="http://forum.joomla.org/index.php?action=reporttm%3Btopic=89866.19%3Bmsg=455550"&gt;Report to moderator&lt;/A&gt;  
									&lt;IMG border="0" alt="" src="http://forum.joomla.org/Themes/joomla/images/ip.gif" /&gt;
									&lt;A class="help" href="http://forum.joomla.org/index.php?action=helpadmin%3Bhelp=see_member_ip"&gt;Logged&lt;/A&gt;
								&lt;/TD&gt;
							&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
							&lt;HR width="100%" size="1" class="hrcolor" /&gt;
							&lt;DIV class="signature"&gt;Jean-Marie Simonet / infograf · &lt;A target="_blank" href="http://www.info-graf.fr"&gt;http://www.info-graf.fr&lt;/A&gt; · GMT +1&lt;/DIV&gt;
						&lt;/TD&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;br&gt;&lt;div style="margin-bottom: 40px;"&gt;Tags: &lt;a href="http://clipmarks.com/tags/globals/" rel="tag"&gt;globals&lt;/a&gt;, &lt;a href="http://clipmarks.com/tags/php/" rel="tag"&gt;php&lt;/a&gt;&lt;/div&gt;</description><clipSource>http://forum.joomla.org/index.php/topic,89866.msg455550.html</clipSource><pubDate>Sat, 23 Dec 2006 13:33:19 GMT</pubDate></item><item><title>php globals</title><link>http://clipmarks.com/clipmark/5D3E7507-032F-4B08-9A0D-9B775E89D7E4/</link><description>&lt;b&gt;clipped by:&lt;/b&gt; &lt;a href="http://clipmarks.com/clipper/serkanserttop/"&gt;serkanserttop&lt;/a&gt;&lt;br&gt;&lt;div border="2" style="margin-top: 10px; border:#000000 1px solid;" width="90%"&gt;&lt;div style="background-color:"&gt;&lt;div align="center" width="100%" style="padding:4px;margin-bottom:4px;background-color:#666666;overflow:hidden;"&gt;&lt;span style="color:#FFFFFF;font-weight:bold;"&gt;Clip Source: &lt;a style="color:#FFFFFF;" href="http://www.jaguarpc.com/forums/showthread.php?t=14734" title="http://www.jaguarpc.com/forums/showthread.php?t=14734"&gt;www.jaguarpc.com&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="padding: 10px;"&gt;&lt;div style="text-align:left;"&gt;&lt;DIV id="post_message_99841"&gt;I put this near the top of my (root) .htaccess file... &lt;IMG border="0" class="inlineimg" title="Wink" alt="" src="http://www.jaguarpc.com/forums/images/smilies/wink.gif" /&gt;&lt;BR /&gt;
&lt;DIV&gt;
	&lt;DIV class="smallfont"&gt;Code:&lt;/DIV&gt;
	&lt;PRE class="alt2"&gt;&lt;DIV dir="ltr"&gt;# Offers protection during hack attacks by NOT disclosing error
# messages, server paths, et cetera, and turns off your globals.
php_flag display_errors off
php_flag register_globals off&lt;/DIV&gt;&lt;/PRE&gt;
&lt;/DIV&gt;&lt;/DIV&gt;&lt;/div&gt;&lt;/div&gt;&lt;hr size="2" color="#666666" /&gt;&lt;div style="padding: 10px;"&gt;&lt;div style="text-align:left;"&gt; &lt;IMG width="272" height="69" id="Clipmarks_HighlightDivChild" src="http://www.jaguarpc.com/forums/chrome://clipmarks/skin/clipped.png" /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;br&gt;&lt;div style="margin-bottom: 40px;"&gt;Tags: &lt;a href="http://clipmarks.com/tags/php/" rel="tag"&gt;php&lt;/a&gt;, &lt;a href="http://clipmarks.com/tags/settings/" rel="tag"&gt;settings&lt;/a&gt;, &lt;a href="http://clipmarks.com/tags/globals/" rel="tag"&gt;globals&lt;/a&gt;&lt;/div&gt;</description><clipSource>http://www.jaguarpc.com/forums/showthread.php?t=14734</clipSource><pubDate>Sat, 23 Dec 2006 13:29:43 GMT</pubDate></item></channel></rss>