@Limplementeur Bien rรฉsumรฉ, la base peut aussi lancer des commandes systรจme dans certaines conditions, donc danger.
Des outils open source existent pour รฉtudier la faille et s'amuser sur un systรจme local ou contrรดlรฉ (ex. https://t.co/pacfG19RxN)
The SQL injection Error strategy simply works on the Blind and Time rooms by @tryhackme.
Does jSQL Injection handle the levels more easily than planned?
I guess it's not expected by the platform, the learning material does not mention Error strategy.
Create shell with jSQL on https://t.co/YW3awjMVZf to learn SQLi fundamentals and mitigation.
By @hackthebox_eu (mostly free platform, so free ads).
How-to:
1. Paste URL, click on 'Start injection'
2. Select '/var/www/html/', click on 'Create a shell'
You're in. #infosec#edu
Shout-out back to team @kalilinux and congrats for the 2023.3 release: https://t.co/NvdKnTWpMX
jSQL bumped in Kali to latest v0.91 with fresh homepage: https://t.co/cKMk0QywNq
Get your own distro with range of security tools and contribute like I did: https://t.co/LPz4P06PSw
Reviewing multibit strategy described by @tr3w_: https://t.co/goA0O8bhym
You get characters by groups of bits, provided the target returns a distinct page for a group.
It's 57% faster using groups of 3 bits compared to single bit, which means thousands less queries. #infosec
@offbyfour I guess with a XLS sheet then you require a correct matching with all the duplicated values.
And if I SELECT both columns "users_sex" and "last_name" then the columns joining is restored.
Query is more tricky to remove duplicates but it may give some results.
It's paper time again, jSQL quoted among three "state-of-the-art" tools by the team of researcher @offbyfour and doctor aquynh.
I heard feedbacks sounding worse than that.
- jSQL deduplicates values which leads to "values detached from their indices" and "loss of information"
Hmm, it just avoids wasting time, no loss, I don't get the point here.
Though I'm glad it has been noticed, sure we see that removing duplicates is efficient on the chart.
- "inefficient implementation of jSQL search algorithm"
I honestly agree, currently algorithm is kind of awful and buggy, so if anyone want to try it's just there:
https://t.co/24dJniolSa
@ZachWeiner On voit pas mal de rostbifs en colรจre que Biden les a publiquement dรฉnigrรฉ en faveur de l'Irlande, mais vraiment imaginez cette frustration pour les amรฉricains d'avoir un prรฉsident ayant la parfaite occasion de sortir "perfide Albion" et qu'il l'a loupe complรจtement.
@ZachWeiner@Miss_Hideko Floral would be more with a complete expression like 'C'est un jardin floral'. You're right here "C'est fleuri" would be better (no -s because the conjugaison is not so facile).
@gchampeau S'agit-il de pub ou de contenu? Dans le 1er cas, beaucoup n'utilisent pas les bloqueurs de pub (mรชme dans l'IT). D'ailleurs quelle raison aurait Musk de ne pas utiliser un bloqueur... un intรฉrรชt dans cette pub? Dans le 2e cas avez-vous des goรปts, disons, singuliers ๐?
@moviexpres Custom payload is done using panels we see on the screenshots.
Also just use any convenient tool, I made jSQL because some part of the job done by other tools was not efficient to me.
Still most important is to give valuable feedbacks to developers for the tools to be improved.
New release: jSQL Injection v0.84
- Script sandbox for Tamper and SQL works now with Java 15
- Restore Scan results
- Fix display for UTF-8 languages on Mac
- Fix various GUI discrepancies on Mac
#infosec
@stack_labs@bridgecrewio@terraformsf@kubernetesio We also use checkov along with tools cfn-lint and cfripper for our AWS stacks, just pip install the tools in your pipelines then analyze your beloved Yโค๏ธML files.
A very excellent write up on #Log4Shell from @jongallimore
Hint: this is not just an RCE and can also be used to obtain potentially secret information
https://t.co/54VYvotx7f