2 Visitor Messages

  1. View Conversation
    Hi.....
    Garage4hackers Forum - SQL Injection Via XSS
    answer plz (^_^)
    TNX
Showing Visitor Messages 1 to 2 of 2
About amolnaik4

Basic Information


About amolnaik4
Biography:
Full-Time Security Consultant, Part-Time Vulnerability Researcher
Location:
webr00t

Statistics


Total Posts
Total Posts
269
Posts Per Day
0.39
Visitor Messages
Total Messages
2
Most Recent Message
03-02-2012 12:42 PM
Total Thanks
Total Thanks
24
  • Thanked 180 Times in 100 Posts
General Information
Last Activity
05-22-2013 07:07 PM
Join Date
07-06-2011
Referrals
2
View amolnaik4's Blog

Recent Entries

SQL Injection Via XSS

by amolnaik4 on 02-07-2012 at 12:19 AM
One of the G4H member mandi from Garage4hackers Forums - Home (my second home) asked few days before about xsssqli attack. He had a scenario where the main site is having a cross-site scripting vulnerability and the admin panel has SQL Injection. The page having sql injection in admin panel is only accessible to admin. The question was is it possible to use xss on main site to exploit sql injection on admin panel to get admin account pwned?

Here is my answer with following scenario:

Read More

Updated 02-14-2012 at 01:05 PM by amolnaik4

Categories
Uncategorized

SQL Injection in INSERT Query

by amolnaik4 on 02-03-2012 at 09:53 AM
SQL injection is being one of the mostly exploited issues in web application security and has found a place in OWASP Top 10 since 2004. There are many blog posts, papers available on SELECT query injection exploiting WHERE or HAVING clauses. Today I’m going to discuss SQL injection in INSERT query.

Here is PDF of the same.
SQL Injection in INSERT Query.pdf

Any suggestions, comments are welcome.

Cheers,
AMol NAik

Updated 02-03-2012 at 10:10 AM by amolnaik4

Categories
Uncategorized

ClubHack 2011 preCON CTF walkthrough

by amolnaik4 on 12-21-2011 at 11:02 AM
This paper is based on the steps I executed to win ClubHack 2011 preCON CTF challenge.

Hope you will like it.

ClubHack 2011, India’s Hacker conference, was held on 3-4 Feb 2011 at Pune, India. They had a pre-conference hacking competition, called as WEBWAR, whose winners can win a free entry to the clubhack event. The winners also qualified to play Treasure Hunt, a physical CTF at clubhack conference.

This post is a walk through for this preCON CTF challenge.

Read More

Updated 12-22-2011 at 09:35 AM by amolnaik4

Categories
Uncategorized

127 Likes

Page 1 of 9 123 ... LastLast
  1. dexter
    dexter liked post by amolnaik4 On thread : Road to Web Application Security
    Hello friends, Here I'm posting the process I followed to learn web application security and I thing this will help many new comers who wanted to do their carrier in web application security....
    Liked On: 02-24-2013, 12:39 PM
  2. Inxroot
    Inxroot liked article by amolnaik4 On : SQL Injection Via XSS
    One of the G4H member mandi from Garage4hackers Forums - Home (http://www.garage4hackers.com) (my second home) asked few days before about xsssqli attack. He had a scenario where the main site is...
    Liked On: 02-22-2013, 11:10 PM
  3. 1.4m.1nd14n
    1.4m.1nd14n liked post by amolnaik4 On thread : Newbie from NYC
    Welcome to garage .... learn & share the knowledge :)
    Liked On: 01-25-2013, 04:40 PM
  4. fb1h2s
    fb1h2s liked post by amolnaik4 On thread : TRACE method
    @karthikp: there is an attack called as Cross-Site Tracing (XST). You should read about this and find out is it still applicable to modern browsers. I'm sure after reading about this attack and...
    Liked On: 12-25-2012, 02:16 PM
  5. d4rkpyth0n
    d4rkpyth0n liked post by amolnaik4 On thread : Road to Web Application Security
    Hey firesail, Web Application Hackers Handbook is a good start as well but the book is more about testing the web applications. It is necessory to have a web development experience to become a good...
    Liked On: 12-13-2012, 04:39 AM
  6. prakhar
    prakhar liked post by amolnaik4 On thread : POST based CSRF attack against Web Applications that use JSON RPC
    You should check this; JSON Hijacking Demystified - SpiderLabs Anterior (http://blog.spiderlabs.com/2012/09/json-hijacking-demystified.html) AMol NAik
    Liked On: 12-11-2012, 06:46 PM
  7. d4rkpyth0n
    d4rkpyth0n liked post by amolnaik4 On thread : Flash XSS Cheat Sheet
    Flash XSS Cheat Sheet: http://demo.testfire.net/vulnerable.swf Amol NAik
    Liked On: 12-10-2012, 11:53 PM
  8. Mr.C1Ph3r
    Mr.C1Ph3r liked post by amolnaik4 On thread : POST based CSRF attack against Web Applications that use JSON RPC
    You should check this; JSON Hijacking Demystified - SpiderLabs Anterior (http://blog.spiderlabs.com/2012/09/json-hijacking-demystified.html) AMol NAik
    Liked On: 12-09-2012, 10:42 PM
  9. RahulB
    RahulB liked post by amolnaik4 On thread : Road to Web Application Security
    Hello friends, Here I'm posting the process I followed to learn web application security and I thing this will help many new comers who wanted to do their carrier in web application security....
    Liked On: 12-08-2012, 11:02 PM
  10. Mr.C1Ph3r
    Mr.C1Ph3r liked post by amolnaik4 On thread : Road to Web Application Security
    Hello friends, Here I'm posting the process I followed to learn web application security and I thing this will help many new comers who wanted to do their carrier in web application security....
    Liked On: 12-05-2012, 11:41 PM
  11. AnArKI
    AnArKI liked post by amolnaik4 On thread : My journey to OSCP
    Hello All, Here is the write-up for my OSCP experience: Secure Belief: My Journey to OSCP (http://amolnaik4.blogspot.com/2012/11/my-journey-to-oscp.html) AMol NAik
    Liked On: 12-03-2012, 02:59 PM
  12. pop3_zxcv
    pop3_zxcv liked post by amolnaik4 On thread : My journey to OSCP
    Hello All, Here is the write-up for my OSCP experience: Secure Belief: My Journey to OSCP (http://amolnaik4.blogspot.com/2012/11/my-journey-to-oscp.html) AMol NAik
    Liked On: 12-02-2012, 12:38 PM
  13. RahulB
    RahulB liked post by amolnaik4 On thread : My journey to OSCP
    Hello All, Here is the write-up for my OSCP experience: Secure Belief: My Journey to OSCP (http://amolnaik4.blogspot.com/2012/11/my-journey-to-oscp.html) AMol NAik
    Liked On: 11-22-2012, 01:17 PM
  14. fb1h2s
    fb1h2s liked post by amolnaik4 On thread : Breaking in to Security
    THis is a nice presentation by @digininja at BSides London. All your questions are answered here. PPT: http://www.digininja.org/files/breaking_in_bsides_slides.pdf post: Breaking in to...
    Liked On: 11-02-2012, 11:21 AM
  15. prakhar
    prakhar liked post by amolnaik4 On thread : MySQL: Blind Injection steps - Manually
    While preparing for an upcoming presentation, I came across Blind SQL Injection. Following steps I found helpful and you might find it useful. There are 2 types of Blind SQL Injections: 1. Normal...
    Liked On: 10-23-2012, 03:30 AM
Page 1 of 9 123 ... LastLast