Page 1 of 1 [ 6 posts ] 

Vexcalibur
Veteran
Veteran

User avatar

Joined: 17 Jan 2008
Age: 41
Gender: Male
Posts: 5,398

03 Aug 2011, 12:05 am

http://www.guardian.co.uk/commentisfree ... cy-hacking

The article claims that SQL injections are easy. And it is true, but they do require you to infiltrate networks.

DDoS when you are not using zombie computers is not only extremely easy, it is also not real "infiltration" or hacking. It is the online equivalent to a march holding signs on a road blocking the path. If you use your computer to be part of a DoS attack, your own connection will be the one that will suffer the most because of the 'attack'. So, the article is really true in the case of DDoS attacks. It truly is online protesting.


_________________
.


blauSamstag
Veteran
Veteran

User avatar

Joined: 5 Apr 2011
Age: 50
Gender: Male
Posts: 3,026

03 Aug 2011, 12:16 am

Vexcalibur wrote:
http://www.guardian.co.uk/commentisfree/2011/aug/01/online-dissent-democracy-hacking

The article claims that SQL injections are easy. And it is true, but they do require you to infiltrate networks.


Not always. Some websites and web-based applications are so poorly written that you can inject sql right through the url, or in a submission form.

I don't see how that is "infiltration". It's like having a bank teller who will give out free money to anyone who comes to the window and knows the magic word.



Vexcalibur
Veteran
Veteran

User avatar

Joined: 17 Jan 2008
Age: 41
Gender: Male
Posts: 5,398

03 Aug 2011, 12:26 am

The second you are injecting code through a form it requires you to reverse engineer the system on the other side (Even if it is trivial reverse engineering, it is still it, you would have to try all the form fields looking for ways to inject code). And once you run your code in the server you are infiltrating on it. In your example, you would need to infiltrate the bank to find out the bank employee is doing that and also to find out the magic word.

Many times it is brain dead easy. But it is a crossing of boundaries.


_________________
.


blauSamstag
Veteran
Veteran

User avatar

Joined: 5 Apr 2011
Age: 50
Gender: Male
Posts: 3,026

03 Aug 2011, 12:30 am

Vexcalibur wrote:
The second you are injecting code through a form it requires you to reverse engineer the system on the other side (Even if it is trivial reverse engineering, it is still it, you would have to try all the form fields looking for ways to inject code). And once you run your code in the server you are infiltrating on it. In your example, you would need to infiltrate the bank to find out the bank employee is doing that and also to find out the magic word.

Many times it is brain dead easy. But it is a crossing of boundaries.


"Results in" is not the same thing as "Requires".

Sometimes you can learn enough about the database from the exposed code for a well placed truncate statement.



Philologos
Veteran
Veteran

User avatar

Joined: 21 Jan 2010
Age: 83
Gender: Male
Posts: 6,987

04 Aug 2011, 11:09 am

YOU oppose dissing dissent?



blauSamstag
Veteran
Veteran

User avatar

Joined: 5 Apr 2011
Age: 50
Gender: Male
Posts: 3,026

04 Aug 2011, 12:01 pm

Philologos wrote:
YOU oppose dissing dissent?


which you?

I still say that if you can learn the magic words to get free money from the bank teller without ever seeing the other side of the teller's window, you haven't infiltrated anything. And it's their own fault if nobody thinks it's unusual that you keep walking in and asking the teller strange questions.