professional documents
home
Profile
Upload
docsters
Blogs
Upload
about me
contact me
user photo
Guillaume
Student
submit clear
Word Document

SQL Injections center doc

technology > applications

 

ECE 4112 Internetwork Security SQL Injections Group number: _________________ Group members: ___________________________ ___________________________ Goal: The goal of this lab is to understand how SQL injections work, and the defenses against them. Summary: In this lab you will install the programs necessary to run a HTTP server using PHP and mySQL. You will then exploit the web pages given to you, using SQL injections. Background and Theory: SQL injections are when SQL code is given as user input. If the user input is not validated, the SQL code can be run. This vulnerability is common among amateur sites. It allows an attacker to login as a privileged user, edit, or outright delete database entries. Prelab Questions: None. Lab Scenario: This lab will be using web server programs run on your Windows XP virtual machine. WAMP5 is used for the web server, SQL server, and php server. Section 1: Setup and Basic Injections First we will install WAMP. This is an integrated package for Windows Apache MySQL and PHP. Copy wamp5_1.5.0c.exe from your CD into your tools folder. Run wamp5_1.5.0c.exe. Click Next Click I accept the agreement Click Next 4 times. Click Install. Click Ok. Click Open. Click Yes. Click Finish. Now you have Apache, MySQL, and PHP all running on your Windows virtual machine. Copy login.sql from the CD to your tools folder. Left click on the WAMP system tray icon (the speedometer). Choose MySQL, then choose MySQL console. At the console prompt: The default password is blank so just hit enter. mysql> source ; But replace with the full path of where you copied the login.sql file. Copy login.php, admin.php, user.php, and guest.php into c:\wamp\www Open up your browser and go to page http://localhost/login.php There are 3 users: admin, user, and guest. Try to log in to each user. Q1.1: What happened when you tried to login to each user? Often, the source code of a site may not be available to an attacker. Because of this some information gathering must be done. One way is too simply try different kinds of injections. Here are some common injection strings: ' or 'x'='x ') or ('x'='x ' or 1=1--" or 1=1--or 1=1--" or 0=0 --or 0=0 --' or 0=0 # " or 0=0 # ' or a=a--") or ("a"="a hi" or "a"="a hi" or 1=1 --hi' or 1=1 --hi") or ("a"="a Try putting these into the username field and logging in. Note: it is important that you put a space at the end of each string such as: “’ or ‘x’=’x “. Find an injection which when put into the username field will let you log in. Q1.2: Which injection string allowed you to login? Q1.3: What kind of user did you log in as? Now we are going to try to log in as admin. Put admin in the username field, and injection strings into the password field. Q1.4: Which injection string allowed you to login as admin? Section 2: Retreiving and Editing Data Log in as a guest. The guest page has a feature where you can look up a username and get their real name. We are going to use this feature to get the password of the admin. In the text box type: “ UNION SELECT password FROM logintable WHERE username=”admin” – Note: make sure to include an extra space at the end of the input Click on submit. Q2.1: What is the password of the admin? Q2.2: What is the password of the user? Log in as “user.” The user page has a feature where you can change your password. We are going to use this feature to change the password of the admin. In the textbox type: password” WHERE username=”admin” – Note: make sure to include an extra space at the end of the input Click on submit. The admin’s password has now been changed to password. Go back to the login page and try to login as admin using the new password. Q2.3: Were you able to login as the admin with the password “password”? Answer Sheet Group Number: _______________ Member Names: _________________________ _________________________ Section 1: Setup and Basic Injections Q1.1: What happened when you tried to login to each user? Q1.2: Which injection string allowed you to login? Q1.3: What kind of user did you log in as? Q1.4: Which injection string allowed you to login as admin? Section 2: Retreiving and Editing Data Q2.1: What is the password of the admin? Q2.2: What is the password of the user? Q2.3: Were you able to login as the admin with the password “password”? Suggested Additions and Future Enhancements: Answer Key Section 1: Setup and Basic Injections Q1.1: What happened when you tried to login to each user? If you don’t enter a password, admin and user will fail, but you will be able to login as guest. Q1.2: Which injection string allowed you to login? " or 1=1--" or 0=0 --" or 0=0 # Will all work, any one of these will be sufficient. Q1.3: What kind of user did you log in as? guest Q1.4: Which injection string allowed you to login as admin? " or 1=1--" or 0=0 --" or 0=0 # hi" or "a"="a hi" or 1=1 --Will all work, any one of these will be sufficient. Section 2: Retreiving and Editing Data Q2.1: What is the password of the admin? secure Q2.2: What is the password of the user? password Q2.3: Were you able to login as the admin with the password “password”? yes
rate this doc
email this doc
embed this doc
add to folder
digg reddit stumble delicious
flag this doc
250
20
not rated
0
11/15/2007
English
search termpage on Googletimes searched
Preview

Diabetes and injections information sheet

creativeinspiration 6/16/2008 | 44 | 1 | 0 | educational
Preview

SQL Server for BlackBaud Products

genesisf 3/5/2008 | 489 | 12 | 0 | technology
Preview

SQL Injection Whitepaper

D27 12/29/2007 | 259 | 35 | 0 | technology
Preview

Oracle SQL and PLSQL Bad Practice

eddieawad 3/7/2008 | 3374 | 137 | 0 | technology
Preview

SQL Inyection

Andr3z 7/5/2008 | 41 | 1 | 0 |
Preview

Diabetes from two to four injections information sheet

creativeinspiration 6/16/2008 | 31 | 1 | 0 | educational
Preview

TrophAmine amino acid injections

GovernmentDocs 5/5/2008 | 24 | 0 | 0 | legal
Preview

sql_help

honeytech 11/12/2007 | 251 | 26 | 0 |
Preview

Capacity Planning en SQL Server

conradopacheco 3/4/2008 | 636 | 24 | 0 | technology
Preview

sql server cheat sheet business document template guide

bamafun 1/1/2008 | 644 | 46 | 0 | technology
Preview

Apress Beginning SQL Server 2005 for Developers From Novice to Professional Jan 2006

kayrehn 8/7/2008 | 80 | 106 | 0 |
Preview

Manipulating SQL Server Using SQL Injection

cps1992 4/5/2008 | 152 | 13 | 0 | technology
Preview

YouTube-039-s-Official-Authorities- The-Users-70079

StarBoy 11/18/2007 | 737 | 11 | 0 | technology
Preview

YouTube-Fights-Against-Its-Father-G oogle-55082

StarBoy 11/18/2007 | 698 | 8 | 0 | technology
Preview

xna_launch_final_report

StarBoy 11/18/2007 | 624 | 4 | 0 | technology
Preview

XNA_Introduction

StarBoy 11/18/2007 | 595 | 56 | 0 | technology
Preview

xna

StarBoy 11/18/2007 | 505 | 4 | 0 | technology
Preview

XNA Development-1

StarBoy 11/18/2007 | 1140 | 6 | 0 | technology
Preview

xmas_05

StarBoy 11/18/2007 | 472 | 0 | 0 | technology
Preview

xerc_users_manual

StarBoy 11/18/2007 | 615 | 1 | 0 | technology
Preview

xbst

StarBoy 11/18/2007 | 576 | 0 | 0 | technology
Preview

Xbox Way

StarBoy 11/18/2007 | 665 | 0 | 0 | technology
 
review this doc