<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Hacking Articles &#187; SQL Injection</title>
	<atom:link href="http://hackingarticles.com/category/hacks-2/sql-injection/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackingarticles.com</link>
	<description>&#34;Know Hacking! But No Hacking!&#34;</description>
	<lastBuildDate>Thu, 19 Aug 2010 21:47:32 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>A Beginner&#8217;s Guide to Ethical Hacking [E-Book]</title>
		<link>http://hackingarticles.com/beginners-guide-ethical-hacking/</link>
		<comments>http://hackingarticles.com/beginners-guide-ethical-hacking/#comments</comments>
		<pubDate>Thu, 19 Aug 2010 21:45:11 +0000</pubDate>
		<dc:creator>Bhanu Chawla</dc:creator>
				<category><![CDATA[Crack Wifi]]></category>
		<category><![CDATA[Downloads]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Facebook Hacks]]></category>
		<category><![CDATA[Hack MSN/Hotmail]]></category>
		<category><![CDATA[Hack using keyloggers]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Hacking Software]]></category>
		<category><![CDATA[Hacking tools]]></category>
		<category><![CDATA[Hacks]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Proxies]]></category>
		<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Tutorials]]></category>
		<category><![CDATA[Virus Creation]]></category>
		<category><![CDATA[Website Hacking]]></category>
		<category><![CDATA[google hacking]]></category>
		<category><![CDATA[hack computer]]></category>
		<category><![CDATA[hack facebook]]></category>
		<category><![CDATA[hack gmail]]></category>
		<category><![CDATA[a beginner's guide to ethical hacking]]></category>
		<category><![CDATA[ethical hacking]]></category>
		<category><![CDATA[hacking book]]></category>
		<category><![CDATA[hacking ebook]]></category>
		<category><![CDATA[hacking guide]]></category>
		<category><![CDATA[hacking tutorials]]></category>
		<category><![CDATA[learn hacking]]></category>
		<category><![CDATA[learn how to hack]]></category>

		<guid isPermaLink="false">http://hackingarticles.com/?p=869</guid>
		<description><![CDATA[Learn What It Takes to Become a Master Hacker A Beginner&#8217;s Guide to Ethical Hacking is a complete path for newbie hackers who  are curious to Learn Ethical Hacking Techniques. The Information given in this book will make you a Master in Hacking. How will the information in the book affect you? You will learn [...]<p><a href="http://hackingarticles.com/beginners-guide-ethical-hacking/">A Beginner&#8217;s Guide to Ethical Hacking [E-Book]</a> is a post from: <a href="http://hackingarticles.com">Learn How To Hack</a>
If you enjoyed this post, make sure you <a href="http://feeds2.feedburner.com/HackingArticles">Subscribe to my RSS feed!</a></p>



<b>Related posts:<ol></b><li><a href='http://hackingarticles.com/how-to-hack-passwords/' rel='bookmark' title='Permanent Link: How To Hack Passwords'>How To Hack Passwords</a></li>
<li><a href='http://hackingarticles.com/record-pc-activity-elite-keylogger-47/' rel='bookmark' title='Permanent Link: Record PC activity with Elite Keylogger 4.7'>Record PC activity with Elite Keylogger 4.7</a></li>
<li><a href='http://hackingarticles.com/eltima-powered-keylogger-track-pc-activity-passwords-keystrokes/' rel='bookmark' title='Permanent Link: Eltima Powered Keylogger &#8211; Track PC activity, passwords and all keystrokes'>Eltima Powered Keylogger &#8211; Track PC activity, passwords and all keystrokes</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<h2 style="text-align: center;"><a target="_blank" href="https://www.plimus.com/jsp/buynow.jsp?contractId=2859842&amp;referrer=sniperspy"><img class="aligncenter size-full wp-image-871" title="A Beginners Guide to Ethical Hacking" src="http://hackingarticles.com/wp-content/uploads/A-Beginners-Guide-to-Ethical-Hacking1.jpg" alt="Hacking Guide" width="424" height="534" /></a></h2>
<h2 style="text-align: center;">Learn What It Takes to Become a Master Hacker</h2>
<p><a target="_blank" href="https://www.plimus.com/jsp/buynow.jsp?contractId=2859842&amp;referrer=sniperspy" target="_blank"><strong>A Beginner&#8217;s Guide to Ethical Hacking</strong></a> is a complete path for newbie hackers who  are curious to <strong>Learn Ethical Hacking Techniques</strong>. The Information given in this book will make you a Master in Hacking.</p>
<p>How will the information in the book affect you?</p>
<ul>
<li> You will learn All Ethical hacking techniques and also you will learn to apply them in real world situation.</li>
</ul>
<ul>
<li> You will start to think like Hackers.</li>
</ul>
<ul>
<li> Secure your computer from trojans, worms,  adwares etc.</li>
</ul>
<ul>
<li> Amaze your friends with your newly learned tricks.</li>
</ul>
<ul>
<li> You will be able to protect your self from future hack attacks.</li>
<li></li>
</ul>
<h2 style="text-align: center;"><span style="color: #ff0000;">Bonus 1</span></h2>
<h2 style="text-align: center;"><a href="http://hackingarticles.com/wp-content/uploads/bonus1.jpg.png"><img class="aligncenter size-medium wp-image-872" title="1000 Hacking Tutorials" src="http://hackingarticles.com/wp-content/uploads/bonus1.jpg-249x300.png" alt="1000 Hacking Tutorials" width="249" height="300" /></a></h2>
<h2 style="text-align: center;">1000 Hacking Tutorials</h2>
<h2 style="text-align: center;">For a limited time only , with the purchase of “<a target="_blank" href="https://www.plimus.com/jsp/buynow.jsp?contractId=2859842&amp;referrer=sniperspy">A Beginner’s Guide to Ethical Hacking</a>” you will receive the following bonus package! 1000 Hacking Tutorials contains 1000 of the best hacking tutorials of 2010 leaked on the internet!</h2>
<h2 style="text-align: center;"><span style="color: #ff0000;">Bonus 2</span></h2>
<h2 style="text-align: center;"><span style="color: #ff0000;"><br />
</span></h2>
<h2 style="text-align: center;">Set of Phishers</p>
<p>With the purchase of “<a target="_blank" href="https://www.plimus.com/jsp/buynow.jsp?contractId=2859842&amp;referrer=sniperspy">A Beginner’s Guide to Ethical Hacking</a>” you will also get a set of 30+ Phishers(Fake Login Pages) already created by the Author!</h2>
<h2 style="text-align: center;">Its Decision Time!</h2>
<p style="text-align: left;">Now you have heard it all so what are you waiting for.</p>
<p>This book does not demand any prior knowledge about Hacking. So if you are a newbie to the concept of hacking and want to master it from the basics, then this book is for you.</p>
<p>The information given in this underground handbook will put you into a hacker’s mindset and teach you all of the hacker’s secret.So what are you waiting for? Grab &#8220;A Beginner&#8217;s Guide to Ethical hacking&#8221; and start your Hacking Journey.</p>
<div class="tboxred" style="border: 3px dashed #cc0000; margin-left: 20px; margin-right: 20px; padding: 10px;">
<h1 style="text-align: center;"><span style="color: #ff0000;"><span id="order_price" style="text-decoration: none;">Regular Price <span style="text-decoration: line-through;">$67.00</span> Today&#8217;s Price $20.00</span></span></h1>
<div style="text-align: center;"><span id="order_price" style="text-decoration: none;"> </span> <a target="_blank" href="https://www.plimus.com/jsp/buynow.jsp?contractId=2859842&amp;referrer=sniperspy"><img src="http://hackingarticles.com/wp-content/uploads/download.jpg" border="0" alt="download A Beginners Guide to Ethical Hacking [E Book]"  title="A Beginners Guide to Ethical Hacking [E Book]" /></a></div>
</div>
<p><a href="http://hackingarticles.com/beginners-guide-ethical-hacking/">A Beginner&#8217;s Guide to Ethical Hacking [E-Book]</a> is a post from: <a href="http://hackingarticles.com">Learn How To Hack</a>
If you enjoyed this post, make sure you <a target="_blank" href="http://feeds2.feedburner.com/HackingArticles">Subscribe to my RSS feed!</a></p>


<p><b>Related posts:<ol></b><li><a href='http://hackingarticles.com/how-to-hack-passwords/' rel='bookmark' title='Permanent Link: How To Hack Passwords'>How To Hack Passwords</a></li>
<li><a href='http://hackingarticles.com/record-pc-activity-elite-keylogger-47/' rel='bookmark' title='Permanent Link: Record PC activity with Elite Keylogger 4.7'>Record PC activity with Elite Keylogger 4.7</a></li>
<li><a href='http://hackingarticles.com/eltima-powered-keylogger-track-pc-activity-passwords-keystrokes/' rel='bookmark' title='Permanent Link: Eltima Powered Keylogger &#8211; Track PC activity, passwords and all keystrokes'>Eltima Powered Keylogger &#8211; Track PC activity, passwords and all keystrokes</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://hackingarticles.com/beginners-guide-ethical-hacking/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Video Tutorial on SQL Injection</title>
		<link>http://hackingarticles.com/sql-injection-video/</link>
		<comments>http://hackingarticles.com/sql-injection-video/#comments</comments>
		<pubDate>Thu, 14 May 2009 23:46:21 +0000</pubDate>
		<dc:creator>Bhanu Chawla</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[Tutorials]]></category>
		<category><![CDATA[crackers]]></category>
		<category><![CDATA[cracking]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hack admin]]></category>
		<category><![CDATA[hack passwords]]></category>
		<category><![CDATA[hack website]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking tutorial]]></category>
		<category><![CDATA[hacking tutorials]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[sql attack]]></category>

		<guid isPermaLink="false">http://hackingarticles.com/?p=168</guid>
		<description><![CDATA[Do subscribe and say thanks, If you like this video tutorial.. You can download the shown strings in the video from Here: Click Here To Download! Video only for educational purposes only! Video Tutorial on SQL Injection is a post from: Learn How To Hack If you enjoyed this post, make sure you Subscribe to [...]<p><a href="http://hackingarticles.com/sql-injection-video/">Video Tutorial on SQL Injection</a> is a post from: <a href="http://hackingarticles.com">Learn How To Hack</a>
If you enjoyed this post, make sure you <a href="http://feeds2.feedburner.com/HackingArticles">Subscribe to my RSS feed!</a></p>



<b>Related posts:<ol></b><li><a href='http://hackingarticles.com/what-is-sql-injection/' rel='bookmark' title='Permanent Link: What is SQL Injection?'>What is SQL Injection?</a></li>
<li><a href='http://hackingarticles.com/tutorial-on-ardamax-30-keyloggers/' rel='bookmark' title='Permanent Link: Tutorial On Ardamax 3.0 Keyloggers'>Tutorial On Ardamax 3.0 Keyloggers</a></li>
<li><a href='http://hackingarticles.com/how-to-hack-orkut-accounts-through-cookie-stealing/' rel='bookmark' title='Permanent Link: How to Hack Orkut Accounts through Cookie Stealing?'>How to Hack Orkut Accounts through Cookie Stealing?</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="350" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="quality" value="high" /><param name="src" value="http://www.youtube.com/v/t1ueX4GQfMY" /><embed type="application/x-shockwave-flash" width="425" height="350" src="http://www.youtube.com/v/t1ueX4GQfMY" quality="high"></embed></object></p>
<p>Do subscribe and say thanks, If you like this video tutorial..</p>
<p>You can download the shown strings in the video from <a target="_blank" href="http://rapidshare.com/files/259879594/strings.txt" target="_blank">Here</a>:</p>
<p><a target="_blank" href="http://rapidshare.com/files/259879594/strings.txt" target="_blank">Click Here To Download!</a></p>
<p>Video only for educational purposes only!</p>
<p><a href="http://hackingarticles.com/sql-injection-video/">Video Tutorial on SQL Injection</a> is a post from: <a href="http://hackingarticles.com">Learn How To Hack</a>
If you enjoyed this post, make sure you <a target="_blank" href="http://feeds2.feedburner.com/HackingArticles">Subscribe to my RSS feed!</a></p>


<p><b>Related posts:<ol></b><li><a href='http://hackingarticles.com/what-is-sql-injection/' rel='bookmark' title='Permanent Link: What is SQL Injection?'>What is SQL Injection?</a></li>
<li><a href='http://hackingarticles.com/tutorial-on-ardamax-30-keyloggers/' rel='bookmark' title='Permanent Link: Tutorial On Ardamax 3.0 Keyloggers'>Tutorial On Ardamax 3.0 Keyloggers</a></li>
<li><a href='http://hackingarticles.com/how-to-hack-orkut-accounts-through-cookie-stealing/' rel='bookmark' title='Permanent Link: How to Hack Orkut Accounts through Cookie Stealing?'>How to Hack Orkut Accounts through Cookie Stealing?</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://hackingarticles.com/sql-injection-video/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
		<item>
		<title>What is SQL Injection?</title>
		<link>http://hackingarticles.com/what-is-sql-injection/</link>
		<comments>http://hackingarticles.com/what-is-sql-injection/#comments</comments>
		<pubDate>Thu, 14 May 2009 20:52:20 +0000</pubDate>
		<dc:creator>Bhanu Chawla</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[crackers]]></category>
		<category><![CDATA[cracking]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hack website]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking website]]></category>
		<category><![CDATA[inject website]]></category>
		<category><![CDATA[injection]]></category>
		<category><![CDATA[sql]]></category>

		<guid isPermaLink="false">http://hackingarticles.com/?p=159</guid>
		<description><![CDATA[SQL injection is most common methodology employed by a hacker to exploit vulnerabilities in software applications. Vulnerabilities are basically weak links in the software that exposes unauthorized data/information to a user. SQL injection occurs when the user input is incorrectly filtered for embedded SQL statements. The technique is powerful enough not only to expose the [...]<p><a href="http://hackingarticles.com/what-is-sql-injection/">What is SQL Injection?</a> is a post from: <a href="http://hackingarticles.com">Learn How To Hack</a>
If you enjoyed this post, make sure you <a href="http://feeds2.feedburner.com/HackingArticles">Subscribe to my RSS feed!</a></p>



<b>Related posts:<ol></b><li><a href='http://hackingarticles.com/sql-injection-video/' rel='bookmark' title='Permanent Link: Video Tutorial on SQL Injection'>Video Tutorial on SQL Injection</a></li>
<li><a href='http://hackingarticles.com/hacking-im-e-mail-and-other-accounts/' rel='bookmark' title='Permanent Link: How do The Crackers Crack IM, E-Mail and other accounts?'>How do The Crackers Crack IM, E-Mail and other accounts?</a></li>
<li><a href='http://hackingarticles.com/tutorial-on-ardamax-30-keyloggers/' rel='bookmark' title='Permanent Link: Tutorial On Ardamax 3.0 Keyloggers'>Tutorial On Ardamax 3.0 Keyloggers</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="aligncenter" title="SQL Injection" src="http://farm3.static.flickr.com/2116/3531266995_2a9248df9c.jpg" alt="SQL Injection" width="400" height="266" /></p>
<p>SQL injection is most common methodology employed by a hacker to exploit vulnerabilities in software applications. Vulnerabilities are basically weak links in the software that exposes unauthorized data/information to a user. SQL injection occurs when the user input is incorrectly filtered for embedded SQL statements.<br />
The technique is powerful enough not only to expose the information to the user but also modify and delete the content which could prove disastrous to the company.</p>
<p>SQL injection vulnerabilities have three forms:  <span id="more-159"></span></p>
<p><strong> </strong></p>
<p><strong><span style="font-size: 12pt;">Incorrectly filtered special characters: escape characters</span></strong></p>
<p>This form of SQL injection occurs when the user manipulates the SQL statements using characters such as  &#8217;.  For instance consider that you need to enter username and password while logging into your account. The SQL statement generated will be:<br />
&#8220;SELECT * FROM users WHERE password =    &#8217;&#8221; + password + &#8220;&#8216;;&#8221;</p>
<p>Now suppose the userName and/or password so entered are”  ‘ or ‘1’=’1”. So the SQL statement reaching the back end will be:</p>
<p>&#8220;SELECT * FROM users WHERE password =&#8217;  ‘or ‘1’=’1 &#8216;;&#8221;</p>
<p>Look closely at this statement. It is deciphered by the database as select everything from the table “user” having field name equal to ‘ ‘ or 1=1. During authentication process, this condition will always be valid as 1 will always equal 1. Thus this way the user is given unauthorized access.</p>
<p>List of Some Important inputs used by hackers to use SQL Injection technique are:<br />
a)  ‘ or ‘a’=’a<br />
b)  ‘ or 1=1 &#8211;<br />
c)  ‘ or 1=1; &#8211;<br />
d)  ‘; select * from *; &#8211;<br />
e)  ‘ (Single quote)(Here we look at the error)<br />
f)  ‘; drop table users –</p>
<p>On some SQL servers such as MS SQL Server any valid SQL command may be injected via this method, including the execution of multiple statements. The following value of &#8220;username&#8221; in the statement below would cause the deletion of the &#8220;users&#8221; table as well as the selection of all data from the &#8220;data&#8221; table (in essence revealing the information of every user):<br />
a&#8217;;DROP TABLE users; SELECT * FROM data WHERE name LIKE &#8216;%</p>
<p><strong><span style="font-size: 12pt;">Incorrectly handling input data type</span></strong></p>
<p>This form of SQL injection occurs when the user input is not strongly typed i.e. , the input by the user is not checked for data type constraint. For example consider a field where you are asked to enter your phone number. Since the phone number input is of numeric data type, therefore the input must be checked whether it is numeric or not. If not checked, then the user can send alphanumeric input and embedded SQL statements. Consider the following SQL statement:<br />
“SELECT * FROM user WHERE telephone = “+ input +”;”<br />
Now if I can input alphanumeric data say “11111111;DROP TABLE user” then I have embedded an SQL statement to delete the entire table “user”. This might prove detrimental to the company!!!</p>
<p>If you happen to know the database table name and column names, then any user can perform SQL injection using the following inputs:</p>
<ol>
<li>&#8216; having 1=1 &#8211;</li>
<li>&#8216; group by user.id having 1=1 &#8211;</li>
<li>&#8216; group by users.id, users.username, users.password, users.privs having 1=1—</li>
<li>&#8216; union select sum(users.username) from users—</li>
<li>&#8216; union select sum(id) from users –</li>
</ol>
<p><strong><span style="font-size: 12pt;">Vulnerabilities inside the database server</span></strong></p>
<p>Sometimes vulnerabilities can exist within the database server software itself, as was the case with the MySQL server&#8217;s real_escape_chars() functions.<br />
If the database server is not properly configured then the access to the database can easily be found out by the hacker.<br />
The hacker can get information regarding the database server using the following input:<br />
&#8216; union select @@version,1,1,1—</p>
<ol>
<li>Extended Stored Procedure Attacks</li>
<li>sp_who: this will show all users that are currently connected to the database.</li>
<li>xp_readmail, , , , ,@peek=’false’ : this will read all the mails and leave the message as unread.</li>
</ol>
<p>In the same way there is a list of such extended stored procedures that can be used by the hacker to exploit vulnerabilities existing in software application at the database layer.</p>
<p><a href="http://hackingarticles.com/what-is-sql-injection/">What is SQL Injection?</a> is a post from: <a href="http://hackingarticles.com">Learn How To Hack</a>
If you enjoyed this post, make sure you <a target="_blank" href="http://feeds2.feedburner.com/HackingArticles">Subscribe to my RSS feed!</a></p>


<p><b>Related posts:<ol></b><li><a href='http://hackingarticles.com/sql-injection-video/' rel='bookmark' title='Permanent Link: Video Tutorial on SQL Injection'>Video Tutorial on SQL Injection</a></li>
<li><a href='http://hackingarticles.com/hacking-im-e-mail-and-other-accounts/' rel='bookmark' title='Permanent Link: How do The Crackers Crack IM, E-Mail and other accounts?'>How do The Crackers Crack IM, E-Mail and other accounts?</a></li>
<li><a href='http://hackingarticles.com/tutorial-on-ardamax-30-keyloggers/' rel='bookmark' title='Permanent Link: Tutorial On Ardamax 3.0 Keyloggers'>Tutorial On Ardamax 3.0 Keyloggers</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://hackingarticles.com/what-is-sql-injection/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
	</channel>
</rss>
