How to learn SQL injection

In my previous post in the hacker series https://decisionstats.com/2013/03/20/hacking-for-beginners-top-website-hacks/ , we noted that SQL Injection remains a top method for security vulnerabilities. Accordingly- here is a list of resources to learn SQL Injection

Definition

SQL injection is a code injection technique that exploits a security vulnerability in an application’s software. The vulnerability happens when user input is either incorrectly filtered for string literal escape characters embedded in SQL statements or user input is not strongly typed and unexpectedly executed. SQL injection is mostly known as an attack vector for websites but can be used to attack any type of SQL database.

Basic Tools

  • SQL Inject Me

https://addons.mozilla.org/en-us/firefox/addon/sql-inject-me/

SQL Inject Me is the Exploit-Me tool used to test for SQL Injection vulnerabilities.

The tool works by submitting your HTML forms and substituting the form value with strings that are representative of an SQL Injection attack.The tool works by sending database escape strings through the form fields. It then looks for database error messages that are output into the rendered HTML of the page.

The tool does not attempting to compromise the security of the given system. It looks for possible entry points for an attack against the system. There is no port scanning, packet sniffing, password hacking or firewall attacks done by the tool.

  • Hackbar

https://addons.mozilla.org/en-US/firefox/addon/hackbar/

and http://code.google.com/p/hackbar/

This toolbar will help you in testing sql injections, XSS holes and site security. It is NOT a tool for executing standard exploits and it will NOT teach you how to hack a site

  • SQLMap

http://sqlmap.org/

sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers.

Basic Tutorials ( in order of learning)

http://sqlzoo.net/hack/

A site for testing SQL Injection attacks. It is a test system and can be used for honing your SQL Skills.

hbar1

Intermediate Tutorials on End to End SQL Injection

Step 1: Finding Vulnerable Website:

Step 2: Checking the Vulnerability:

To check the vulnerability , add the single quotes(‘) at the end of the url and hit enter.

If you got an error message , then it means that the site is vulnerable

Step 3: Finding Number of columns:

Step 4: Find the Vulnerable columns:

Step 5: Finding version,database,user

Step 6: Finding the Table Name

Step 8: Finding the Admin Panel:

from http://www.breakthesecurity.com/2010/12/hacking-website-using-sql-injection.html

 

  • Next Tutorial uses an automated tool called Havij  from

http://www.itsecteam.com/products/havij-v116-advanced-sql-injection/

and the tutorial is at

http://cybersucks.blogspot.in/2013/01/hacking-website-using-sql-injectionfull.html

Hacking for Beginners- Top Website Hacks

I really liked this 2002 presentation on Website Hacks at blackhat.com/presentations/bh-asia-02/bh-asia-02-shah.pdf . It explains in a easy manner some common fundamentals in hacking websites. Take time to go through this- its a good example of how hacking tutorials need to be created if you want to expand the number of motivated hackers.

However a more recent list of hacks is here-

https://blog.whitehatsec.com/top-ten-web-hacking-techniques-of-2012/

The Top Ten

  1. CRIME (12, 3 4) by Juliano Rizzo and Thai Duong
  2. Pwning via SSRF (memcached, php-fastcgi, etc) (23, 4, 5)
  3. Chrome addon hacking (2345)
  4. Bruteforce of PHPSESSID
  5. Blended Threats and JavaScript
  6. Cross-Site Port Attacks
  7. Permanent backdooring of HTML5 client-side application
  8. CAPTCHA Re-Riding Attack
  9. XSS: Gaining access to HttpOnly Cookie in 2012
  10. Attacking OData: HTTP Verb Tunneling, Navigation Properties for Additional Data Access, System Query Options ($select)

Honorable Mention

11. Using WordPress as a intranet and internet port scanner

12. .Net Cross Site Scripting – Request Validation Bypassing (1)

13. Bruteforcing/Abusing search functions with no-rate checks to collect data

14. Browser Event Hijacking (23)

But a more widely used ranking method for Website Hacking is here. Note it is a more formal but probably a more recent document than the pdf above. If only it could be made into an easier to read tutorial, it would greatly improve website exploit security strength.

https://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project

The Release Candidate for the OWASP Top 10 for 2013 is now available here: OWASP Top 10 – 2013 – Release Candidate

The OWASP Top 10 – 2013 Release Candidate includes the following changes as compared to the 2010 edition:

  • A1 Injection
  • A2 Broken Authentication and Session Management (was formerly A3)
  • A3 Cross-Site Scripting (XSS) (was formerly A2)
  • A4 Insecure Direct Object References
  • A5 Security Misconfiguration (was formerly A6)
  • A6 Sensitive Data Exposure (merged from former A7 Insecure Cryptographic Storage and former A9 Insufficient Transport Layer Protection)
  • A7 Missing Function Level Access Control (renamed/broadened from former A8 Failure to Restrict URL Access)
  • A8 Cross-Site Request Forgery (CSRF) (was formerly A5)
  • A9 Using Known Vulnerable Components (new but was part of former A6 – Security Misconfiguration)
  • A10 Unvalidated Redirects and Forwards


Once again, I am presenting this as an example of how lucid documentation can help spread technological awareness to people affected by technical ignorance and lacking the savvy and chops for self-learning. If you need better cyber security, you need better documentation and tutorials on hacking for improving the quantity and quality of the pool of available hackers and bringing in young blood to enhance your cyber security edge.

Countering Communist China’s CyberWar

How the West Counters China

  • Using United Nations and WTO to present evidence to push for financial penalties
  • Define Cyber- Retaliation rules of engagement and doctrine for hacking attacks
  • Delineate the obfuscation between Anonymous, State Sponsored Hacks, Hactivism, Cyber Criminals- and build clear rules of engagement
  • Provoke Chinese Naval and Air Assets (using the Opium War’s lessons)
  • Create a digital cyber-warfare alliance using Australia, Japan, Taiwan, South Korea, India , Tibetan Exiles and NATO

How China can counter the West

  • Build a dossier of false or misplaced allegations that are leveled at China and use them when something sticks
  • Highlight Western Government’s breaches of citizen privacy and digital surveillance
  • Highlight efforts of intellectual property theft, monopolistic actions and industrial espionage in the West
  • Host more black hat conferences within Macau and Hong Kong if not mainland China
  • Support Anonymous and Digital Activism as potential allies

The supreme art of war is to subdue the enemy without fighting.” ― Sun Tzu

The rise of the global MOOCs ( Massively Open Online Course)

Threatening the monopoly of corrupted universities that cater to rising educational aspirations with mediocre , recycled courses, the MOOC revolution now breaks out of North America to reach global universities.Of course, Coursera leads and I liked the tight integration with Meetup.com –

May I suggest they look at codeacademy and build much more gamification than  currently available in their own courses.

 

From-

http://blog.coursera.org/post/43625628117/29-new-schools-92-new-courses-5-languages-4

Today we’re welcoming 29 new universities to the Coursera community of 2.7 million students and 33 existing universities across 4 continents!

also see

http://viz.coursera.org/2013-02-20-globe/

mooc1

and

https://www.edx.org/press/edx-expands-internationally

To date, edX has more than 700,000 individuals on its platform, who account for more than 900,000 course enrollments.

EdX, the not-for-profit online learning enterprise founded by Harvard University and the Massachusetts Institute of Technology (MIT), announced today the international expansion of its X University Consortium with the addition of six new global higher education institutions. The Australian National University (ANU), Delft University of Technology in the Netherlands, École Polytechnique Fédérale de Lausanne (EPFL) in Switzerland, McGill University and the University of Toronto in Canada, and Rice University in the United States are joining the Consortium

Do you want a 100,000 extra analysts in your platform or language. Why don’t you let your training department design a MOOC for these platforms. Because the more people that are trained in your software or platform, the more brand ambassadors you have to selling it to future clients. Companies like 10gen are already doing it for MongoDB. And Oracle is doing it for R Enterprise ( see https://decisionstats.com/2012/10/23/10gen-and-online-education-mongodb/)

What is a MOOC?

http://en.wikipedia.org/wiki/Massive_open_online_course

A massive open online course (MOOC) is an online course aiming at large-scale participation and open access via the web. MOOCs are a recent development in distance education using open educational resources. They are similar to college courses, but typically do not offer academic credit. Other forms of assessment or certification may be available including those based on learning analytics for online environments.

MOOCs originated within the open educational resources (OER) movement and connectivist roots. Several MOOC-type projects have emerged independently, such as Coursera, Udacity, and edX.[1] Others, like Canvas Network and CourseSites by Blackboard Inc have evolved from learning management systems.

Also see-

http://www.mooc-list.com/  list of Massive Open Online Courses (free online courses) offered by the best universities and entities.

Download all your tweets

Now that the Government of the United States of America has the legal power to request your information without a warrant  (The Chinese love this!)

Anyways- you can also download your own twitter data. Liberate your data.

Have you looked at your own data? Go there at https://twitter.com/settings/account and review the changes.

t  t2

 

 

SAS Thought Leader declares war on data scientists on Valentine Eve

 

It all started because of the Google Guy, Hal Varian

Feb 25, 2009 – I keep saying the sexy job in the next ten years will be statisticians Hal Varian, The McKinsey Quarterly, January 2009.

Then these guys ( Thomas H. Davenport and D.J. Patil)  made us sexy -that too in the Harvard Business Review.

Jill Dyche* is a thought leader. That’s what her job says. that too at SAS  which took over her start-up Baseline Consulting. (* In addition to this, she writes forewords for struggling poets here )

She says here

If the importance of data scientists is growing with the advent of big data, the sooner we understand what exactly it is they do, the better.

That is fair enough. But to add grievous injury to data scientists, She adds

(For fun I wrote a blog post on being a data scientist’s girlfriend.)

Actually the blog post was-Why I Wouldn’t Have Sex with a Data Scientist

But there’s no use. The data scientist is preoccupied. Preoccupied with finding, accessing, analyzing, validating, cleansing, integrating, provisioning, modeling, verifying, and explaining data to his management, colleagues, end-users, and friends.

And this is the year of the statistician ??

This is bare knuckles tactics. The art of Vaseline Insulting? Perish the thought. Geeks and Data Scientists  rule.

Dont we? and we are perfect? right.

We statisticians (and data scientists and big dataists and data miners and business analysts and …)

are bringing sexy back!

Justin+Timberlake+JT+PNG+1(and we need a hug too.)

The dichotomy in being a writer on open source with a non-open access publisher

  • The publisher adds credibility to your work

versus

  • A self fulfilling prophecy where researchers want to publish in exclusive journals and closed -access books, for the sole reason that others did so as well before them and thereby donate their knowledge and money to the publisher

aaronswartz-v2

The dichotomy in being a writer on open source with a non-open access publisher?

  • I write on open source R , 
  • and I have been published (one book )
  • and am on contract to write two more ( R for Cloud Computing) and (R for Web and Social Media Analytics)
  • My publisher does have open access journals.
  • But the book is at $50. Most of India lives at less than 2$ per day. Thats 800 million people in my country alone.

But the publisher is the most reputed in this field. So what are my choices? How do I get more people to have choices to read books.

Take open knowledge , curate it, and turn it behind a $50 paywall. I am sorry, Aaron. People like me are the reason ……