full-disclosure-uk January 2010 archive
Main Archive Page > Month Archives  > full-disclosure-uk archives
full-disclosure-uk: [Full-disclosure] Some SQL inj and including

[Full-disclosure] Some SQL inj and including hints

From: Vladimir Vorontsov <vladimir.vorontsov_at_nospam>
Date: Thu Jan 14 2010 - 13:39:37 GMT
To: Full disclosure <full-disclosure@lists.grok.org.uk>


Hi all,

  1. On Win systems use short directories names like that: Progra~1 == "Program Files" Docume~1 == "Documents and Settings" if you want to create file in space contained folder using INTO OUTFILE/INTO DUMPFILE injection/ Example: http://localhost/inj.php?id='/**/INTO/**/OUTFILE/**/%22C:/PROGRA~1/APACHE/VAR/WWW/index.php%22

In other cases your can't write file using MySQL if their absoute path have a spaces.

2. Use .phtml extension instead of .php to fraud WebApplicationFirewalls and filters.
Default apache2 configuration file like this:

<IfModule mod_php5.c>

AddType application/x-httpd-php .php .phtml .php3 AddType application/x-httpd-php-source .phps
</IfModule>

Sorry for my bests English. -- ----------------------------------------------------------------- Best regards! Vladimir Vorontsov, security expert. ONsec: turn on security _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/