<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; mysql</title>
	<atom:link href="http://www.darknet.org.uk/tag/mysql/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>MySQLPasswordAuditor &#8211; Free MySQL Audit/Password Recovery &amp; Cracking Tool</title>
		<link>http://www.darknet.org.uk/2011/12/mysqlpasswordauditor-free-mysql-auditpassword-recovery-cracking-tool/</link>
		<comments>http://www.darknet.org.uk/2011/12/mysqlpasswordauditor-free-mysql-auditpassword-recovery-cracking-tool/#comments</comments>
		<pubDate>Mon, 19 Dec 2011 19:12:34 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Password Cracking]]></category>
		<category><![CDATA[database-security]]></category>
		<category><![CDATA[hacking mysql]]></category>
		<category><![CDATA[mysql]]></category>
		<category><![CDATA[mysql password auditing]]></category>
		<category><![CDATA[mysql password cracking]]></category>
		<category><![CDATA[mysql password recovery]]></category>
		<category><![CDATA[mysql security]]></category>
		<category><![CDATA[mysqlpasswordauditor]]></category>
		<category><![CDATA[password-recovery]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3119</guid>
		<description><![CDATA[MysqlPasswordAuditor is the FREE Mysql password recovery and auditing software. Mysql is one of the popular and powerful database software used by most of the web based and server side applications. If you have ever lost or forgotten your Mysql database password then MysqlPasswordAuditor can help in recovering it easily. It can also help you [...]]]></description>
			<content:encoded><![CDATA[<p>MysqlPasswordAuditor is the FREE Mysql password recovery and auditing software. Mysql is one of the popular and powerful database software used by most of the web based and server side applications.</p>
<p>If you have ever lost or forgotten your Mysql database password then MysqlPasswordAuditor can help in recovering it easily. It can also help you to audit Mysql database server setup in an corporate environment by discovering the weak password configurations. This makes it one of the must have tool for IT administrators &#038; Penetration Testers.</p>
<p>MysqlPasswordAuditor is very easy to use with the simple dictionary based password recovery method. By default it includes small password list file, however you can find more password dictionary files at OpenWall collection. You can also use tools like Crunch, Cupp to generate custom password list files on your own and then use it with MysqlPasswordAuditor.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p>MysqlPasswordAuditor works on wide range of platforms starting from Windows XP to latest operating system Windows 7.</p>
<p><strong>Features</strong></p>
<ul>
<li>Free and Simple software to Recover/Audit Mysql Password.</li>
<li>Very useful for IT administrators &#038; Penetration Testers</li>
<li>Dictionary based Password Recovery method</li>
<li>Detailed statistics such as  tested passwords, elapsed time, progress bar is displayed during Audit operation.</li>
<li>Simple, easy to use GUI interface</li>
<li>Integrated Installer for local Installation &#038; Uninstallation. </li>
</ul>
<p>You can download MysqlPasswordAuditor here:</p>
<p><a href="http://securityxploded.net/getfile.php?file=MysqlPasswordAuditor.zip">MysqlPasswordAuditor.zip</a></p>
<p>Or read more <a href="http://securityxploded.com/mysql-password-auditor.php">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=MySQLPasswordAuditor+%E2%80%93+Free+MySQL+Audit%2FPassword+Recovery+%26+Cracking+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3119+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/12/mysqlpasswordauditor-free-mysql-auditpassword-recovery-cracking-tool/&amp;t=MySQLPasswordAuditor+%E2%80%93+Free+MySQL+Audit%2FPassword+Recovery+%26+Cracking+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/12/mysqlpasswordauditor-free-mysql-auditpassword-recovery-cracking-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/12/mysqlpasswordauditor-free-mysql-auditpassword-recovery-cracking-tool/&amp;title=MySQLPasswordAuditor+%E2%80%93+Free+MySQL+Audit%2FPassword+Recovery+%26+Cracking+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/12/mysqlpasswordauditor-free-mysql-auditpassword-recovery-cracking-tool/&amp;title=MySQLPasswordAuditor+%E2%80%93+Free+MySQL+Audit%2FPassword+Recovery+%26+Cracking+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/12/mysqlpasswordauditor-free-mysql-auditpassword-recovery-cracking-tool/&amp;title=MySQLPasswordAuditor+%E2%80%93+Free+MySQL+Audit%2FPassword+Recovery+%26+Cracking+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/12/mysqlpasswordauditor-free-mysql-auditpassword-recovery-cracking-tool/&amp;title=MySQLPasswordAuditor+%E2%80%93+Free+MySQL+Audit%2FPassword+Recovery+%26+Cracking+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F12%2Fmysqlpasswordauditor-free-mysql-auditpassword-recovery-cracking-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/12/mysqlpasswordauditor-free-mysql-auditpassword-recovery-cracking-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>sqlsus 0.7.1 Released &#8211; MySQL Injection &amp; Takeover Tool</title>
		<link>http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/</link>
		<comments>http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/#comments</comments>
		<pubDate>Mon, 21 Nov 2011 14:15:08 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[database-security]]></category>
		<category><![CDATA[hacking mysql]]></category>
		<category><![CDATA[hacking toold]]></category>
		<category><![CDATA[mysql]]></category>
		<category><![CDATA[mysql hacking tool]]></category>
		<category><![CDATA[mysql injection]]></category>
		<category><![CDATA[mysql injection tool]]></category>
		<category><![CDATA[mysql security]]></category>
		<category><![CDATA[mysql takeover]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[sql-injection-tool]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1680</guid>
		<description><![CDATA[sqlsus is an open source MySQL injection and takeover tool, written in perl. Via a command line interface, you can retrieve the database(s) structure, inject your own SQL queries (even complex ones), download files from the web server, crawl the website for writable directories, upload and control a backdoor, clone the database(s), and much more&#8230;Whenever [...]]]></description>
			<content:encoded><![CDATA[<p>sqlsus is an open source MySQL injection and takeover tool, written in perl. Via a command line interface, you can retrieve the database(s) structure, inject your own SQL queries (even complex ones), download files from the web server, crawl the website for writable directories, upload and control a backdoor, clone the database(s), and much more&#8230;Whenever relevant, sqlsus will mimic a MySQL console output.</p>
<p>sqlsus focuses on speed and efficiency, optimising the available injection space, making the best use (I can think of) of MySQL functions. It uses stacked subqueries and an powerful blind injection algorithm to maximise the data gathered per web server hit. Using multithreading on top of that, sqlsus is an extremely fast database dumper, be it for inband or blind injection.If the privileges are high enough, sqlsus will be a great help for uploading a backdoor through the injection point, and takeover the web server.</p>
<p>It uses SQLite as a backend, for an easier use of what has been dumped, and integrates a lot of usual features (see below) such as cookie support, socks/http proxying, https..</p>
<p><strong>What&#8217;s New</strong></p>
<p>Starting with version 0.7, sqlsus now supports time-based blind injection and automatically detects web server / suhosin / etc.. length restrictions.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<ul>
<li>Added time-based blind injection support (added option &#8220;blind_sleep&#8221;, and renamed &#8220;string_to_match&#8221; to &#8220;blind_string&#8221;).</li>
<li>It is now possible to force sqlsus to exit when it&#8217;s hanging (i.e.: retrieving data), by hitting Ctrl-C more than twice.</li>
<li>Rewrite of &#8220;autoconf max_sendable&#8221;, so that sqlsus will properly detect which length restriction applies (WEB server / layer above). (removed option &#8220;max_sendable&#8221;, added options &#8220;max_url_length&#8221; and &#8220;max_inj_length&#8221;)</li>
<li>Uploading a file now sends it into chunks under the length restriction.</li>
<li>sqlsus now saves variables after each command, so that forcing it to quit (or killing it) will not discard the changes that were made.</li>
<li>Added a progress bar to inband mode, sqlsus now determines the number of rows to be returned prior to fetching them.</li>
<li>get db (tables/columns) in inband mode now uses multithreading (like everything else).</li>
<li>clone now uses count(*) if available (set by &#8220;get count&#8221; / &#8220;get db&#8221;), instead of using fetch-ahead.</li>
<li>In blind mode, &#8220;start&#8221; will now test if things work the way they should, by injecting 2 queries : one true and one false.</li>
<li>sqlsus now prints what configuration options are overridden (when a saved value differs from the configuration file).</li>
</ul>
<p>You can download sqlsus 0.7.1 here:</p>
<p><a href="http://sourceforge.net/projects/sqlsus/files/sqlsus/sqlsus-0.7.1.tgz/download">sqlsus-0.7.1.tgz</a></p>
<p>Or read more <a href="http://sqlsus.sourceforge.net/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=sqlsus+0.7.1+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1680+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/&amp;t=sqlsus+0.7.1+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/&amp;title=sqlsus+0.7.1+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/&amp;title=sqlsus+0.7.1+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/&amp;title=sqlsus+0.7.1+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/&amp;title=sqlsus+0.7.1+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F11%2Fsqlsus-0-7-1-released-mysql-injection-takeover-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MySQL.com Compromised &amp; Spreading Malware</title>
		<link>http://www.darknet.org.uk/2011/09/mysql-com-compromised-spreading-malware/</link>
		<comments>http://www.darknet.org.uk/2011/09/mysql-com-compromised-spreading-malware/#comments</comments>
		<pubDate>Tue, 27 Sep 2011 06:02:47 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[blackhole exploit kit]]></category>
		<category><![CDATA[hacking mysql]]></category>
		<category><![CDATA[hacking mysql.com]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[mwjs159]]></category>
		<category><![CDATA[mysql]]></category>
		<category><![CDATA[mysql.com compromised]]></category>
		<category><![CDATA[mysql.com hack]]></category>
		<category><![CDATA[mysql.com spreading malware]]></category>
		<category><![CDATA[mysql.com trojan]]></category>
		<category><![CDATA[sucuri security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3193</guid>
		<description><![CDATA[The latest story doing the rounds is that MySQL.com got hacked and was serving malware which put it on the Google malware block list. It appears to be in the clear now though and it&#8217;s accessible again via Google. It seems to be a similar case with that of the recent Linux.com and Kernel.org hacks [...]]]></description>
			<content:encoded><![CDATA[<p>The latest story doing the rounds is that <a href="http://mysql.com/">MySQL.com</a> got hacked and was serving malware which put it on the Google malware block list.</p>
<p>It appears to be in the clear now though and it&#8217;s accessible again via <a href="http://www.darknet.org.uk/tag/google/">Google</a>. It seems to be a similar case with that of the recent Linux.com and Kernel.org hacks &#8211; in which the sites were compromised via developers who had access.</p>
<p>In this case it seems MySQL.com was compromised by <a href="http://www.darknet.org.uk/category/virustrojanswormsrootkits/">malware</a> that spreads itself via FTP from client machines, it then uploads malicious JavaScript to any sites the client machine has access to and propagates malware using those sites.</p>
<blockquote><p>Hackers recently compromised the website hosting the open-source MySQL database management system and caused it to infect the PCs of visitors who used unpatched browsers and plug-ins, security researchers said.</p>
<p>MySQL.com was infected with mwjs159, website malware that often spreads when compromised machines are used to access restricted FTP clients, a blog post from Sucuri Security reported. The hack caused people visiting the site to be redirected to a site that attempted to install malware on visitors&#8217; computers using code from the Blackhole exploit kit, separate researchers from Armorize said.</p>
<p>“It exploits the visitor&#8217;s browsing platform (the browser, the browser plugins like Adobe Flash, Adobe PDF, etc, Java, &#8230;), and upon successful exploitation, permanently installs a piece of malware into the visitor&#8217;s machine, without the visitor&#8217;s knowledge,” Armorize researchers warned. “The visitor doesn&#8217;t need to click or agree to anything; simply visiting mysql.com with a vulnerable browsing platform will result in an infection.”</p>
<p>Officials with the Oracle-owned MySQL didn&#8217;t respond to email seeking comment for this post.</p></blockquote>
<p>I would say MySQL.com is a fairly high traffic site so this attack may have triggered a fair amount of infections &#8211; especially if the people visiting were using outdated versions of <a href="http://www.darknet.org.uk/category/windows-hacking/">Windows</a> or old versions of Internet Explorer.</p>
<p>But then again, I&#8217;d find that fairly unlikely &#8211; people browsing to the site of the #1 Open Source RDBMS would most likely be using Linux, or fully updated Windows systems with <a href="http://www.darknet.org.uk/tag/chrome/">Chrome</a> or <a href="http://www.darknet.org.uk/tag/firefox/">Firefox</a>.</p>
<p>That&#8217;s what I&#8217;d like to think anyway&#8230;</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>The reported breach is the latest to affect the distribution system for a widely used piece of open-source software. The kernel.org and Linux.com websites used to develop and distribute the Linux operating system remain inaccessible four weeks after it was infected with malware that gained root access, modified system software, and logged passwords and transactions of the people who used them. Representatives haven&#8217;t said when they expect the sites to be operational again.</p>
<p>Besides sullying the reputation of open-source software as more secure alternative to competing applications from Microsoft and other for-profit companies, the compromises have sparked concerns about the purity of the code the sites host. If attackers were able to secretly alter the code with backdoors, they could potentially surveil or gain control over sensitive networks that rely on the applications.</p>
<p>In the MySQL.com hack, the attackers appear to have aimed for the less ambitious goal of infecting the desktop machines of those who visited the site. At time of writing, just five of the top 44 antivirus providers were detecting the threat, according to this analysis from VirusTotal.</p>
<p>Sucuri speculated the site was infected after a MySQL developer was compromised and had his password stolen.</p></blockquote>
<p>It doesn&#8217;t seem to be as serious as the Linux.com/Kernel.org compromises as in this case it&#8217;s simply JavaScript uploaded via FTP from a developer account &#8211; the actual server hosting MySQL.com wasn&#8217;t really hacked and there was no root access gained.</p>
<p>It seems like they have cleared the infection up now, I wonder if they have any stats on how many people were effected by the malware?</p>
<p>Source: <a href="http://www.theregister.co.uk/2011/09/26/mysql_hacked/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=MySQL.com+Compromised+%26+Spreading+Malware+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3193+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/09/mysql-com-compromised-spreading-malware/&amp;t=MySQL.com+Compromised+%26+Spreading+Malware" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/09/mysql-com-compromised-spreading-malware/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/09/mysql-com-compromised-spreading-malware/&amp;title=MySQL.com+Compromised+%26+Spreading+Malware" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/09/mysql-com-compromised-spreading-malware/&amp;title=MySQL.com+Compromised+%26+Spreading+Malware" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/09/mysql-com-compromised-spreading-malware/&amp;title=MySQL.com+Compromised+%26+Spreading+Malware" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/09/mysql-com-compromised-spreading-malware/&amp;title=MySQL.com+Compromised+%26+Spreading+Malware" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F09%2Fmysql-com-compromised-spreading-malware%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/09/mysql-com-compromised-spreading-malware/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Damn Vulnerable Web App &#8211; Learn &amp; Practise Web Hacking</title>
		<link>http://www.darknet.org.uk/2009/07/damn-vulnerable-web-app-learn-practise-web-hacking/</link>
		<comments>http://www.darknet.org.uk/2009/07/damn-vulnerable-web-app-learn-practise-web-hacking/#comments</comments>
		<pubDate>Wed, 15 Jul 2009 08:39:59 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[damn vulnerable web app]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[hacking-websites]]></category>
		<category><![CDATA[lfi]]></category>
		<category><![CDATA[mysql]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[php mysql]]></category>
		<category><![CDATA[practise web hacking]]></category>
		<category><![CDATA[rfi]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[vulnerable web app]]></category>
		<category><![CDATA[vulnerable web application]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1913</guid>
		<description><![CDATA[Damn Vulnerable Web App (DVWA) is a PHP/MySQL web application that is damn vulnerable. Its main goals are to be light weight, easy to use and full of vulnerabilities to exploit. Used to learn or teach the art of web application security. Vulnerabilities SQL Injection XSS (Cross Site Scripting) LFI (Local File Inclusion) RFI (Remote [...]]]></description>
			<content:encoded><![CDATA[<p>Damn Vulnerable Web App (DVWA) is a PHP/MySQL web application that is damn vulnerable. Its main goals are to be light weight, easy to use and full of vulnerabilities to exploit. Used to learn or teach the art of web application security.</p>
<p><strong>Vulnerabilities</strong></p>
<ul>
<li>SQL Injection</li>
<li>XSS (Cross Site Scripting)</li>
<li>LFI (Local File Inclusion)</li>
<li>RFI (Remote File Inclusion)</li>
<li>Command Execution</li>
<li>Upload Script</li>
<li>Login Brute Force</li>
</ul>
<p><strong>Changes</strong></p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<ul>
<li>Added Acunetix scan report.</li>
<li>All links use http://hiderefer.com to hide referrer header.</li>
<li>Updated/added ‘more info’ links.</li>
<li>Moved change log info to CHANGELOG.txt.</li>
<li>Fixed the exec.php UTF-8 output.</li>
<li>Moved Help/View source buttons to footer.</li>
<li>Fixed phpInfo bug. </li>
<li>Made DVWA IE friendly.</li>
<li>Fixed html bugs.</li>
<li>Improved README.txt and fixed typos.</li>
<li>Made SQL injection possible in sqli_med.php.</li>
</ul>
<p><strong>WARNING</strong></p>
<p>It should come as no shock..but this application is damn vulnerable! Do not upload it to your hosting provider’s public html folder or any working web server as it will be hacked. It&#8217;s recommend that you download and install XAMP onto a local machine inside your LAN which is used solely for testing.</p>
<p>You can download DVWA 1.0.4 here:</p>
<p><a href="http://sourceforge.net/projects/dvwa/files/dvwa/dvwa_v1.0.4.zip/download">dvwa_v1.0.4.zip</a></p>
<p>Or read more <a href="http://sourceforge.net/projects/dvwa/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Damn+Vulnerable+Web+App+%E2%80%93+Learn+%26+Practise+Web+Hacking+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1913+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/07/damn-vulnerable-web-app-learn-practise-web-hacking/&amp;t=Damn+Vulnerable+Web+App+%E2%80%93+Learn+%26+Practise+Web+Hacking" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/07/damn-vulnerable-web-app-learn-practise-web-hacking/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/07/damn-vulnerable-web-app-learn-practise-web-hacking/&amp;title=Damn+Vulnerable+Web+App+%E2%80%93+Learn+%26+Practise+Web+Hacking" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/07/damn-vulnerable-web-app-learn-practise-web-hacking/&amp;title=Damn+Vulnerable+Web+App+%E2%80%93+Learn+%26+Practise+Web+Hacking" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/07/damn-vulnerable-web-app-learn-practise-web-hacking/&amp;title=Damn+Vulnerable+Web+App+%E2%80%93+Learn+%26+Practise+Web+Hacking" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/07/damn-vulnerable-web-app-learn-practise-web-hacking/&amp;title=Damn+Vulnerable+Web+App+%E2%80%93+Learn+%26+Practise+Web+Hacking" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F07%2Fdamn-vulnerable-web-app-learn-practise-web-hacking%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/07/damn-vulnerable-web-app-learn-practise-web-hacking/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Who is Haydies? Me my self and quite possibly some one else.</title>
		<link>http://www.darknet.org.uk/2006/03/who-is-haydies-me-my-self-and-quite-possibly-some-one-else/</link>
		<comments>http://www.darknet.org.uk/2006/03/who-is-haydies-me-my-self-and-quite-possibly-some-one-else/#comments</comments>
		<pubDate>Thu, 16 Mar 2006 07:45:58 +0000</pubDate>
		<dc:creator>Haydies</dc:creator>
				<category><![CDATA[Authors]]></category>
		<category><![CDATA[author]]></category>
		<category><![CDATA[darknet]]></category>
		<category><![CDATA[delphi]]></category>
		<category><![CDATA[haydies]]></category>
		<category><![CDATA[mysql]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[programmer]]></category>
		<category><![CDATA[window]]></category>
		<category><![CDATA[writer]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/03/who-is-haydies-me-my-self-and-quite-possibly-some-one-else/</guid>
		<description><![CDATA[Shaolin introduced him self, and said he had asked every one to do like wise. News to me mate :-P or did that slip my mind? Can&#8217;t see how it could but one never knows&#8230; So, any way, who the hell am I? I have known Shaolin for years, he might have some idea how [...]]]></description>
			<content:encoded><![CDATA[<p>Shaolin introduced him self, and said he had asked every one to do like wise. News to me mate :-P or did that slip my mind? Can&#8217;t see how it could but one never knows&#8230;</p>
<p>So, any way, who the hell am I? I have known Shaolin for years, he might have some idea how many, I am on that old darknet site he mentioned, but do me and favour, and don&#8217;t look there, please? I look terrible and I&#8217;m ashamed :-P</p>
<p>Like Shaolin I to started with the whole computer thing when I was little. The order is a little haszy, but I am fairly sure I had the TI 994A before the little old specy. Though my use of them was a little differant. True, I did for a while spend many hours typeing code to find out later it didn&#8217;t work&#8230;. but before long I was coding my own stuff. In basic on the TI, and z80 assembler on the specy, pascal and modual 2 to on the Amstrad CPC, 6800 assembler and C on the ST&#8230;.</p>
<p>TI, Spectrum, Comador, Atari ST, 386 and beyond, I have always live with a computer, though shockingly never games. My first consol was a ps2 and that is only 4 years old.</p>
<p>After many years of bedroom activites I definatly should be ashamed of (all with a keyboard &#8211; and check this? no net connection) I emerged in the bright old world, a whole host of dead technology and languages no one has used since the romans under my belt, and windows gaining popularity.</p>
<p>Fast forward, past VB, pal, and various noddy little things and I&#8217;m in to Delphi, oh my, was I in to Delphi. For 7 years I lived, breathed and probably bathed in the windows API and OOP. Gone was Delphi&#8217;s native event handlers, to slow, give me the raw message cue&#8230;. mutli threaded servers, no problem, n-tier CORBA clients&#8230; you name it, I did it.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-BodyRec */
google_ad_slot = "8649785837";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div></p>
<p><em>Then I got bored.</em></p>
<p>But thats ok, no one wants desk top or server applications any more. So, a bit late to the party I had a go at ASP, and damn that stuffs ugly. PHP how ever, now thats the nuts, and thus I entered web development.</p>
<p>Some one once said I&#8217;d never be a web developer, but my first ever professional site went live to 2.5 million unique IPs in the first 48 hours, truely one of my proudest hours.</p>
<p>I&#8217;ve been doing PHP ever since, MySQL for most part but if its SQL, its all the same. Date in and data out, its all fairly much simple. Introduce some AJAX just to spice it up a bit, and we&#8217;re all having fun.</p>
<p>Where I am going from here, nobody knows, but I code, there for I am so what ever happens, what ever changes&#8230; I am a programmer :-)</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Who+is+Haydies%3F+Me+my+self+and+quite+possibly+some+one+else.+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D115+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/03/who-is-haydies-me-my-self-and-quite-possibly-some-one-else/&amp;t=Who+is+Haydies%3F+Me+my+self+and+quite+possibly+some+one+else." title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/03/who-is-haydies-me-my-self-and-quite-possibly-some-one-else/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/03/who-is-haydies-me-my-self-and-quite-possibly-some-one-else/&amp;title=Who+is+Haydies%3F+Me+my+self+and+quite+possibly+some+one+else." title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/03/who-is-haydies-me-my-self-and-quite-possibly-some-one-else/&amp;title=Who+is+Haydies%3F+Me+my+self+and+quite+possibly+some+one+else." title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/03/who-is-haydies-me-my-self-and-quite-possibly-some-one-else/&amp;title=Who+is+Haydies%3F+Me+my+self+and+quite+possibly+some+one+else." title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/03/who-is-haydies-me-my-self-and-quite-possibly-some-one-else/&amp;title=Who+is+Haydies%3F+Me+my+self+and+quite+possibly+some+one+else." title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F03%2Fwho-is-haydies-me-my-self-and-quite-possibly-some-one-else%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/03/who-is-haydies-me-my-self-and-quite-possibly-some-one-else/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

