源码论坛新源代

 找回密码
 立即加入

QQ登录

只需一步,快速开始



香港云VPS只要28/月新源代香港VPS 站长建站必备文字广告30/月 Q 380559645
查看: 1538|回复: 5
收起左侧

凯文 米特尼克 脑子进水了???

[复制链接]

该用户从未签到

khjian 发表于 2007-10-26 09:05:35 | 显示全部楼层 |阅读模式

马上注册,下载更多源码!

您需要 登录 才可以下载或查看,没有账号?立即加入

x
The Art Of SQL Intrusion.


I have a book by Kevin Mitnick called: The Art Of Intrusion. I ordered it about a year ago and steadily read the book. I read it to page 100 or so because I got the feeling it was complete bullshit what he tried to explain in the book. No offense to Kevin, but I thought the book sucked bigtime. I heard different stories about him, and in no sense did it reflect in the book. So what was going on? I didn't know, and put the book back onto my bookshelf.

I really learned nothing, until today. I had nothing better to do and picked the book back up and opened it on a random page, page number 175 explained an SQL injection attack. Since I'm somewhat SQL injection savvy, I read a code snippet that goes:


' or where password like '%--


That query became:


select record from users where user = '' or where password like '%' and password = '' or where password like '%'



My jaw dropped... and I thought: No way, José... that query is impossible! I could not understand why this was written in this manner, because another WHERE statement after an OR statement is total bullshit. I never seen such SQL structure in my life. It is illegal and generates only errors. While thinking, well maybe he attacked an exotic SQL database server, but that seemed unlikely and still it makes no sense at all. I read further and he talked about ASP on a VPN login screen somewhere and that makes this totally impossible. I don't know if this is a flaw or something, but it seems to me that this is so strange I cannot believe he wrote it down like that. I really wonder if he actually tested it, or ever performed a single SQL injection himself, because anyone who is at home in the SQL language knows that this is an error prone query.

In any case it is impossible! I thought the book sucked before all this,
but now I really put it away into a very dark corner of my bookshelf.
  • TA的每日心情

    2020-11-1 15:30
  • 签到天数: 4 天

    连续签到: 1 天

    [LV.2]偶尔看看I

    记忆碎片 发表于 2007-10-26 10:32:35 | 显示全部楼层
    翻译一下:


    艺术的sql入侵。


    我有一本书,由凯文米尼克所谓:巧入侵。我命令,它在大约一年前,并稳步阅读这本书。我看了它以100页左右,因为我感觉这是完全bullshit什么,他试图解释在书中。没有进攻,以凯文的,但我认为,本书具有吸bigtime 。我听到不同的故事,对他的,在任何意义上没有反映在书中。那么是什么回事?我不知道,并把书上回我的书架上。

    我真的不知道,要么,直到今天。我没有什么好做拿起这本书回来了,打开它的一个随机页,页码175 ,说明了一个sql注入攻击。因为我有点sql注入悟性,我就阅读了一些代码片断即俗话:


    '或密码,像' % -


    这成为质疑:


    专责记录从用户那里用户= ''或密码,像' % '和密码= ''或密码,像' % '



    我的下巴下降… …我以为:没有办法,何塞… …这疑问是不可能的!我不明白为什么这是写在以这种方式,因为另一个地方的声明后或声明,是总bullshit 。我从来没有见过这样的sql结构,在我的生活。它是非法的,并产生唯一的失误。而思想,那么也许他攻击的异国情调sql数据库服务器,但似乎不太可能,但仍然是毫无意义可言。我看了再和他谈asp ,对vpn的登录屏幕某处,并使得这完全是不可能的。我不知道如果这是一个缺陷或某事,但在我看来,这是很古怪,我不相信他写下来一样。我真怀疑,如果他真的考验呢,还是以往任何时候都表演了单sql注入自己的,因为任何人是在家里,在sql语言都知道,这是一个错误,容易查询。

    在任何情况下,这是不可能的!我认为,本书吸之前所有这一切,
    但现在我真的把它收藏在一个非常黑暗的一个角落,我的书架上。

    该用户从未签到

     楼主| khjian 发表于 2007-10-26 11:36:27 | 显示全部楼层
    大哥,别用工具翻好不,一会我给你翻吧,真无语了~~~~
  • TA的每日心情
    难过
    昨天 10:55
  • 签到天数: 1227 天

    连续签到: 1 天

    [LV.10]以坛为家III

    小黄牛 发表于 2007-10-26 13:33:50 | 显示全部楼层
    呵呵!:) :) :) 支持 !!!!

    该用户从未签到

    indexsky 发表于 2009-1-8 15:38:43 | 显示全部楼层
    不认识这个人,他干吗的!

    该用户从未签到

    huigege 发表于 2014-6-11 16:21:43 | 显示全部楼层
    支持一下楼主,幸苦了
    您需要登录后才可以回帖 登录 | 立即加入

    本版积分规则

    QQ|小黑屋|手机版|注册|源码论坛 |网站地图

    GMT+8, 2024-5-7 00:56 , Processed in 0.187500 second(s), 22 queries .

    Powered by Discuz!

    © 2001-2023 新源代源码论坛 XYDAI.CN

    快速回复 返回顶部 返回列表