Monday, May 12, 2008

Yet Another SQL injection

I was boring the other day, so here i am again toying and playing with SQL injection. Wow, for this particular site, not only they did not turn off debugging, they also allow me to view other very juicy information. I must say if i am determined to hack the site, i can successful grab lotsa juicy information. Not only that, because it is a online shopping site, i can change information and buy things at a much much cheaper price. Check out the information leakage!!





The Hacka Man

2 comments:

Mark said...

Mmm, but is possible to do SQL injection over aspx? (ASP.NET IIS 6.0)

Do u have more info about howto?

-mark

bernard n. shull said...

i did a little research after you told me about your "thing", and if you want a way to make more money using your your blog you can enter this site: link. bye.