<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1539550101889367295</id><updated>2012-02-01T14:41:48.030-08:00</updated><category term='firefox'/><category term='hack'/><category term='eklenti'/><category term='test lab'/><category term='çözüm'/><category term='nasa'/><category term='sql sızma'/><category term='sql'/><category term='slight'/><category term='extension'/><category term='html'/><category term='arama'/><category term='sql hata'/><category term='owasp'/><category term='hackbar'/><category term='ferruh mavituna'/><category term='alıntı'/><category term='nasıl'/><category term='add-on'/><category term='sql test'/><category term='sql injection'/><category term='mssql'/><category term='oracle'/><category term='google'/><title type='text'>Sql injection</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://sqlinject.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://sqlinject.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>sql injection</name><uri>http://www.blogger.com/profile/04352566823640857875</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>23</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1539550101889367295.post-6225483460817605298</id><published>2007-09-19T04:55:00.000-07:00</published><updated>2007-09-19T05:02:13.663-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='alıntı'/><title type='text'></title><content type='html'>&lt;a name="_system_tables"&gt;&lt;/a&gt;System Tables (T-SQL)&lt;br /&gt;The information used by Microsoft® SQL Server™ and its components are stored in special tables known as system tables.&lt;br /&gt;Note System tables should not be altered directly by any user. For example, do not attempt to modify system tables with DELETE, UPDATE, or INSERT statements, or user-defined triggers.&lt;br /&gt;Applications should not be written to query the system tables directly. Applications should instead use any of these components to retrieve information stored in the system tables:&lt;br /&gt;Information schema views&lt;br /&gt;System stored procedures&lt;br /&gt;Transact-SQL statements and functions&lt;br /&gt;SQL-DMO&lt;br /&gt;Database application programming interfaces (API) catalog functions&lt;br /&gt;These components constitute a published API for obtaining system information from SQL Server. Microsoft maintains the compatibility of these components from release to release. The format of the system tables is dependent upon the internal architecture of SQL Server and may change from release to release. Therefore, applications that directly access the system tables may have to be changed before they can access a later version of SQL Server.&lt;br /&gt;System Tables in the master Database Only&lt;br /&gt;These tables store server-level system information.&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-a_2.htm"&gt;sysaltfiles&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-d_2.htm"&gt;sysdevices&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-o_1.htm"&gt;sysoledbusers&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-c.htm"&gt;syscacheobjects&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-l.htm"&gt;syslanguages&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-p.htm"&gt;sysperfinfo&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-c_2.htm"&gt;syscharsets&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-l_1.htm"&gt;syslockinfo&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-p_2.htm"&gt;sysprocesses&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-c_5.htm"&gt;sysconfigures&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-l_2.htm"&gt;syslogins&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-r_1.htm"&gt;sysremotelogins&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-c_7.htm"&gt;syscurconfigs&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-m_6.htm"&gt;sysmessages&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-s.htm"&gt;sysservers&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-d.htm"&gt;sysdatabases&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;System Tables in Every Database&lt;br /&gt;These tables store database-level system information for each database.&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-a_1.htm"&gt;sysallocations&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-f.htm"&gt;sysfiles&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-o.htm"&gt;sysobjects&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-c_3.htm"&gt;syscolumns&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-f_2.htm"&gt;sysforeignkeys&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-p_1.htm"&gt;syspermissions&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-c_4.htm"&gt;syscomments&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-f_3.htm"&gt;sysfulltextcatalogs&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-p_3.htm"&gt;sysprotects&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-c_6.htm"&gt;sysconstraints&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-i.htm"&gt;sysindexes&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-r.htm"&gt;sysreferences&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-d_1.htm"&gt;sysdepends&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-i_1.htm"&gt;sysindexkeys&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-t_4.htm"&gt;systypes&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-f_1.htm"&gt;sysfilegroups&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-m.htm"&gt;sysmembers&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-u.htm"&gt;sysusers&lt;/a&gt;&lt;br /&gt;SQL Server Agent Tables in the msdb Database&lt;br /&gt;These tables store information used by SQL Server Agent.&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-a.htm"&gt;sysalerts&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-j_1.htm"&gt;sysjobschedules&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-t.htm"&gt;systargetservergroupmembers&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-c_1.htm"&gt;syscategories&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-j_3.htm"&gt;sysjobservers&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-t_1.htm"&gt;systargetservergroups&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-d_3.htm"&gt;sysdownloadlist&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-j_4.htm"&gt;sysjobsteps&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-t_2.htm"&gt;systargetservers&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-j.htm"&gt;sysjobhistory&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-n.htm"&gt;sysnotifications&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-t_3.htm"&gt;systaskids&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-j_2.htm"&gt;sysjobs&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-o_2.htm"&gt;sysoperators&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Tables in the msdb Database&lt;br /&gt;These tables store information used by database backup and restore operations.&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys_00_1.htm"&gt;backupfile&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys_00_4.htm"&gt;backupset&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_35.htm"&gt;restorefilegroup&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys_00_2.htm"&gt;backupmediafamily&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_34.htm"&gt;restorefile&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_36.htm"&gt;restorehistory&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys_00_3.htm"&gt;backupmediaset&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Tables Used to Store Replication Information&lt;br /&gt;These tables are used by replication and stored in the master database.&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-a_3.htm"&gt;sysarticles&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-p_4.htm"&gt;syspublications&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-s.htm"&gt;sysservers&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-d.htm"&gt;sysdatabases&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-r_2.htm"&gt;sysreplicationalerts&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-s_1.htm"&gt;syssubscriptions&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-o.htm"&gt;sysobjects&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;These tables are used by replication and stored in the distribution database.&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table.htm"&gt;MSagent_parameters&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_10.htm"&gt;MSmerge_agents&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_25.htm"&gt;Msrepl_originators&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_1.htm"&gt;MSagent_profiles&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_14.htm"&gt;MSmerge_history&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_26.htm"&gt;MSrepl_transactions&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_2.htm"&gt;MSarticles&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_16.htm"&gt;MSmerge_subscriptions&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_27.htm"&gt;MSrepl_version&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_3.htm"&gt;MSdistpublishers&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_18.htm"&gt;MSpublication_access&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_28.htm"&gt;MSsnapshot_agents&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_4.htm"&gt;MSdistributiondbs&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_19.htm"&gt;Mspublications&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_29.htm"&gt;MSsnapshot_history&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_5.htm"&gt;MSdistribution_agents&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_20.htm"&gt;Mspublisher_databases&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_30.htm"&gt;MSsubscriber_info&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_6.htm"&gt;MSdistribution_history&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_21.htm"&gt;MSreplication_objects&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_31.htm"&gt;MSsubscriber_schedule&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_7.htm"&gt;MSdistributor&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_22.htm"&gt;MSreplication_subscriptions&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_32.htm"&gt;MSsubscriptions&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_8.htm"&gt;MSlogreader_agents&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_23.htm"&gt;MSrepl_commands&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_33.htm"&gt;MSsubscription_properties&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_9.htm"&gt;MSlogreader_history&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_24.htm"&gt;MSrepl_errors&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;These tables are used by replication and stored in the user’s database.&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_11.htm"&gt;MSmerge_contents&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_17.htm"&gt;MSmerge_tombstone&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-m_3.htm"&gt;sysmergeschemachange&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_12.htm"&gt;MSmerge_delete_conflicts&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-a_4.htm"&gt;sysarticleupdates&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-m_4.htm"&gt;sysmergesubscriptions&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_13.htm"&gt;MSmerge_genhistory&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-m_1.htm"&gt;sysmergearticles&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-m_5.htm"&gt;sysmergesubsetfilters&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/ms-table_15.htm"&gt;MSmerge_replinfo&lt;/a&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/sys-m_2.htm"&gt;sysmergepublications&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://doc.ddart.net/mssql/sql70/8_gs_00_8.htm"&gt;(c) 1988-98 Microsoft Corporation. All Rights Reserved. &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1539550101889367295-6225483460817605298?l=sqlinject.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sqlinject.blogspot.com/feeds/6225483460817605298/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1539550101889367295&amp;postID=6225483460817605298' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/6225483460817605298'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/6225483460817605298'/><link rel='alternate' type='text/html' href='http://sqlinject.blogspot.com/2007/09/system-tables-t-sql-information-used-by.html' title=''/><author><name>sql injection</name><uri>http://www.blogger.com/profile/04352566823640857875</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1539550101889367295.post-1108597607593193549</id><published>2007-09-14T22:58:00.000-07:00</published><updated>2007-09-14T23:01:16.141-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='slight'/><category scheme='http://www.blogger.com/atom/ns#' term='owasp'/><title type='text'>Advanced Topics on SQL Injection Protection by OWASP</title><content type='html'>&lt;embed src="https://s3.amazonaws.com/slideshare/ssplayer.swf?id=78443&amp;amp;doc=advanced-topics-on-sql-injection-protection4056" type="application/x-shockwave-flash" height="500" width="500"&gt;&lt;/embed&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1539550101889367295-1108597607593193549?l=sqlinject.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sqlinject.blogspot.com/feeds/1108597607593193549/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1539550101889367295&amp;postID=1108597607593193549' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/1108597607593193549'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/1108597607593193549'/><link rel='alternate' type='text/html' href='http://sqlinject.blogspot.com/2007/09/advanced-topics-on-sql-injection.html' title='Advanced Topics on SQL Injection Protection by OWASP'/><author><name>sql injection</name><uri>http://www.blogger.com/profile/04352566823640857875</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1539550101889367295.post-3539040192931353967</id><published>2007-09-07T00:01:00.000-07:00</published><updated>2007-09-07T00:07:00.886-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ferruh mavituna'/><category scheme='http://www.blogger.com/atom/ns#' term='nasa'/><title type='text'>Kurcalarken-Gezerken:Nasa Hacker' ı ile Röportaj</title><content type='html'>Bugün Ferruh Mavituna'nın günlüğünü okurken oradan onun başka bir yazısına geçtim. Nasa sistemine giren hacker ile ilgili yazısı şurada:&lt;a href="http://ferruh.mavituna.com/makale/nasa-hacker-i-ile-roportaj"&gt;http://ferruh.mavituna.com/makale/nasa-hacker-i-ile-roportaj&lt;/a&gt;&lt;br /&gt;Ama benim o hacker'dan çok vurgulamak istediğim yazıdaki şurası:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;p align="left"&gt;...&lt;br /&gt;Zincir ve zayıf halka teorisinin kuralının en büyük örneklerinden biri&lt;br /&gt;olsa gerek. &lt;strong&gt;&lt;span style="font-size:130%;"&gt;Eğer yeterince sistemi tararsanız açık&lt;br /&gt;bulabilirsiniz. &lt;/span&gt;&lt;/strong&gt;Zamanında yahoo' da benzer bir şekilde&lt;br /&gt;normalde internette hiç bir yerde bağlantısı olmayan bir iç proxy ile&lt;br /&gt;hacklenmişti.&lt;br /&gt;...&lt;/p&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Bence açık bulmak için çok doğru ve yeterli bir yöntem, yeteri kadar sistemi taramak&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1539550101889367295-3539040192931353967?l=sqlinject.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sqlinject.blogspot.com/feeds/3539040192931353967/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1539550101889367295&amp;postID=3539040192931353967' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/3539040192931353967'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/3539040192931353967'/><link rel='alternate' type='text/html' href='http://sqlinject.blogspot.com/2007/09/kurcalarken-gezerkennasa-hacker-ile.html' title='Kurcalarken-Gezerken:Nasa Hacker&apos; ı ile Röportaj'/><author><name>sql injection</name><uri>http://www.blogger.com/profile/04352566823640857875</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1539550101889367295.post-3224381958451592109</id><published>2007-09-04T00:06:00.001-07:00</published><updated>2007-09-04T00:09:34.900-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='alıntı'/><title type='text'>Top 15 free SQL Injection Scanners</title><content type='html'>&lt;a href="http://www.security-hacks.com/2007/05/18/top-15-free-sql-injection-scanners"&gt;http://www.security-hacks.com/2007/05/18/top-15-free-sql-injection-scanners&lt;/a&gt;&lt;br /&gt;--------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;&lt;a title="Top 15 free SQL Injection Scanners" href="http://www.security-hacks.com/2007/05/18/top-15-free-sql-injection-scanners" rel="bookmark"&gt;Top 15 free SQL Injection Scanners&lt;/a&gt;&lt;br /&gt;Friday, 18 May 2007 - 15:05 EST    &lt;a title="View all posts in Tools" href="http://www.security-hacks.com/category/tools/" rel="category tag"&gt;Tools&lt;/a&gt;, &lt;a title="View all posts in Web Security" href="http://www.security-hacks.com/category/web-security/" rel="category tag"&gt;Web Security&lt;/a&gt;, &lt;a title="View all posts in Network" href="http://www.security-hacks.com/category/network/" rel="category tag"&gt;Network&lt;/a&gt;&lt;br /&gt;While the adoption of web applications for conducting online business has enabled companies to connect seamlessly with their customers, it has also exposed a number of security concerns stemming from improper coding. Vulnerabilities in web applications allow hackers to gain direct and public access to sensitive information (e.g. personal data, login credentials).&lt;br /&gt;Web applications allow visitors to submit and retrieve data to/from a database over the Internet. Databases are the heart of most web applications. They hold data needed for web applications to deliver specific content to visitors and provide information to customers, suppliers etc.&lt;a id="more-53"&gt;&lt;/a&gt;&lt;br /&gt;SQL Injection is perhaps the most common web-application hacking technique which attempts to pass SQL commands through a web application for execution by the back-end database. The vulnerability is presented when user input is incorrectly sanitized and thereby executed.&lt;br /&gt;Checking for SQL Injection vulnerabilities involves auditing your web applications and the best way to do it is by using automated SQL Injection Scanners. We’ve compiled a list of free SQL Injection Scanners we believe will be of a value to both web application developers and professional security auditors.&lt;br /&gt;SQLIer - SQLIer takes a vulnerable URL and attempts to determine all the necessary information to exploit the SQL Injection vulnerability by itself, requiring no user interaction at all. &lt;a href="http://bcable.net/project.php?sqlier" target="_blank"&gt;Get SQLIer&lt;/a&gt;.&lt;br /&gt;SQLbftools - SQLbftools is a collection of tools to retrieve MySQL information available using a blind SQL Injection attack. &lt;a href="http://www.reversing.org/node/view/11" target="_blank"&gt;Get SQLbftools&lt;/a&gt;.&lt;br /&gt;SQL Injection Brute-forcer - SQLibf is a tool for automatizing the work of detecting and exploiting SQL Injection vulnerabilities. SQLibf can work in Visible and Blind SQL Injection. It works by doing simple logic SQL operations to determine the exposure level of the vulnerable application. &lt;a href="http://www.open-labs.org/sqlibf19beta1.tar.gz" target="_blank"&gt;Get SQLLibf&lt;/a&gt;.&lt;br /&gt;SQLBrute - SQLBrute is a tool for brute forcing data out of databases using blind SQL injection vulnerabilities. It supports time based and error based exploit types on Microsoft SQL Server, and error based exploit on Oracle. It is written in Python, uses multi-threading, and doesn’t require non-standard libraries. &lt;a href="http://www.justinclarke.com/security/sqlbrute.py" target="_blank"&gt;Get SQLBrute&lt;/a&gt;.&lt;br /&gt;BobCat - BobCat is a tool to aid an auditor in taking full advantage of SQL injection vulnerabilities. It is based on &lt;a href="http://www.appsecinc.com/presentations/Manipulating_SQL_Server_Using_SQL_Injection.pdf" target="_blank"&gt;AppSecInc&lt;/a&gt; research. It can list the linked severs, database schema, and allow the retrieval of data from any table that the current application user has access to. &lt;a href="http://www.northern-monkee.co.uk/projects/bobcat/bobcat.html" target="_blank"&gt;Get BobCat&lt;/a&gt;.&lt;br /&gt;SQLMap - SQLMap is an automatic blind SQL injection tool, developed in python, capable to perform an active database management system fingerprint, enumerate entire remote databases and much more. The aim of SQLMap is to implement a fully functional database management system tool which takes advantages of web application programming security flaws which lead to SQL injection vulnerabilities. &lt;a href="http://sqlmap.sourceforge.net/" target="_blank"&gt;Get SQLMap&lt;/a&gt;.&lt;br /&gt;Absinthe - Absinthe is a GUI-based tool that automates the process of downloading the schema and contents of a database that is vulnerable to Blind SQL Injection. &lt;a href="http://www.0x90.org/releases/absinthe/download.php" target="_blank"&gt;Get Absinthe&lt;/a&gt;.&lt;br /&gt;SQL Injection Pen-testing Tool - The SQL Injection Tool is a GUI-based utility designed to examine database through vulnerabilities in web-applications. &lt;a href="http://sqltool.itdefence.ru/indexeng.html" target="_blank"&gt;Get SQL Injection Pen-testing tool&lt;/a&gt;.&lt;br /&gt;SQID - SQL Injection digger (SQLID) is a command line program that looks for SQL injections and common errors in websites. It can perform the follwing operations: look for SQL injection in a web pages and test submit forms for possible SQL injection vulnerabilities. &lt;a href="http://sqid.rubyforge.org/" target="_blank"&gt;Get SQID&lt;/a&gt;.&lt;br /&gt;Blind SQL Injection Perl Tool - bsqlbf is a Perl script that lets auditors retrieve information from web sites that are vulnerable to SQL Injection. &lt;a href="http://www.unsec.net/download/bsqlbf.pl" target="_blank"&gt;Get Blind SQL Injection Perl Tool&lt;/a&gt;.&lt;br /&gt;SQL Power Injection Injector - SQL Power Injection helps the penetration tester to inject SQL commands on a web page. It’s main strength is its capacity to automate tedious blind SQL injection with several threads. &lt;a href="http://www.sqlpowerinjector.com/" target="_blank"&gt;Get SQL Power Injection&lt;/a&gt;.&lt;br /&gt;FJ-Injector Framwork - FG-Injector is a free open source framework designed to help find SQL injection vulnerabilities in web applications. It includes a proxy feature for intercepting and modifying HTTP requests, and an interface for automating SQL injection exploitation. &lt;a href="http://sourceforge.net/project/showfiles.php?group_id=183841" target="_blank"&gt;Get FJ-Injector Framework&lt;/a&gt;.&lt;br /&gt;SQLNinja - SQLNinja is a tool to exploit SQL Injection vulnerabilities on a web application that uses Microsoft SQL Server as its back-end database. &lt;a href="http://sqlninja.sourceforge.net/" target="_blank"&gt;Get SQLNinja&lt;/a&gt;.&lt;br /&gt;Automagic SQL Injector - The Automagic SQL Injector is an automated SQL injection tool designed to help save time on penetration testing. It is only designed to work with vanilla Microsoft SQL injection holes where errors are returned. &lt;a href="http://www.indianz.ch/tools/attack/automagic.zip" target="_blank"&gt;Get Automagic SQL Injector&lt;/a&gt;.&lt;br /&gt;NGSS SQL Injector - NGSS SQL Injector exploit vulnerabilities in SQL injection on disparate database servers to gain access to stored data. It currently supports the following databases: Access, DB2, Informix, MSSQL, MySQL, Oracle, Sysbase. &lt;a href="http://www.indianz.ch/tools/attack/sqlinjector.zip" target="_blank"&gt;Get NGSS SQL Injector&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1539550101889367295-3224381958451592109?l=sqlinject.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sqlinject.blogspot.com/feeds/3224381958451592109/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1539550101889367295&amp;postID=3224381958451592109' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/3224381958451592109'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/3224381958451592109'/><link rel='alternate' type='text/html' href='http://sqlinject.blogspot.com/2007/09/top-15-free-sql-injection-scanners.html' title='Top 15 free SQL Injection Scanners'/><author><name>sql injection</name><uri>http://www.blogger.com/profile/04352566823640857875</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1539550101889367295.post-2740938435751305138</id><published>2007-08-03T13:38:00.000-07:00</published><updated>2007-09-03T03:34:07.831-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='alıntı'/><category scheme='http://www.blogger.com/atom/ns#' term='html'/><title type='text'>HTML 4.01 Entities Reference</title><content type='html'>&lt;p&gt;HTML 4.01 supports the ISO 8859-1 (Latin-1) character set.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;The lower part of ISO-8859-1 (codes from 0-127) is the&lt;br /&gt;&lt;a href="http://www.w3schools.com/tags/ref_ascii.asp"&gt;original 7-BIT ASCII&lt;br /&gt;standard&lt;/a&gt;. &lt;/p&gt;&lt;p&gt;Most of these characters can be used without a character reference.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;The higher part of ISO-8859-1 (codes from 160-255) can all be used using&lt;br /&gt;character entity names.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1539550101889367295-2740938435751305138?l=sqlinject.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sqlinject.blogspot.com/feeds/2740938435751305138/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1539550101889367295&amp;postID=2740938435751305138' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/2740938435751305138'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/2740938435751305138'/><link rel='alternate' type='text/html' href='http://sqlinject.blogspot.com/2007/08/html-401-entities-reference.html' title='HTML 4.01 Entities Reference'/><author><name>sql injection</name><uri>http://www.blogger.com/profile/04352566823640857875</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1539550101889367295.post-4771387772665907812</id><published>2007-07-19T07:56:00.000-07:00</published><updated>2007-07-19T08:15:48.401-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql sızma'/><category scheme='http://www.blogger.com/atom/ns#' term='nasıl'/><category scheme='http://www.blogger.com/atom/ns#' term='test lab'/><title type='text'>Sql sızma( injection) için gerçek siteleri nereden bulacağım?</title><content type='html'>Sitelerdeki sql sızma açıklarını bulmak hiç de zor değil. Kendinizi sql, mssql, mysql ya da herhangi bir veritabanı konusunda geliştirmek için ihtiyacanız olan deneme tahtalarını bulmak hiç zor değil.&lt;br /&gt;Google'dan arama yaparak rahatlıklar bulabilirsiniz.&lt;br /&gt;&lt;br /&gt;Benim denediğim yöntemle, özellikle toplu açıkları bulanabilir.&lt;br /&gt;&lt;br /&gt;Google'da "online alışveriş çözümleri", "eticare çözümleri", "kurumsal web sitesi" kelime gruplarını arattırırsanız. Web tasarımı yapan, ticari web sitesi paketleri, alışveriş sitesi paketleri sunan biçok siteyle karşılacaksınız. Bu sitelerin referans bölümlerinden yaptıkları sitelere ulaşabilir. Referans sitedeki bağlantıları deneyerek açklar bulanabilir.&lt;br /&gt;&lt;br /&gt;Ben sql/sızma/injection konusunda fazla tecrübeli olmamama rağmen google'da arattırdeğım birçok sitede açık bulabildim. Bu açıklar o kadar kötü açıklardı ki sitedeki ürünlerin fiyatlarını bile değiştirebiliyordum.&lt;br /&gt;&lt;br /&gt;Aklınızdan herkes artık önlemini alıyor diye geçirebilirsiniz. Fakat yanılıyorsunuz. Bu siteleri yapanlar da sonuçta insan. Bir sitenin en az 10 tane sayfası oluyor. Bunların alt sayfaları eklentileri derken, hepsindeki sorguları, ifadeleri denetimden geçirmek kolay değil. Genellikle üye giriş sayfalarındaki formlarda süzme işlevleri kullanırlar. Fakat www.xxx.com/haber/resim.asp?resimid?=145 gibi bir sayfada "resimid"  değerini süzmek ile uğraşmazlar. Çünkü bu bir resimin bağlantısıdır. Zaten javascript ile bir pencerede gösteriliyordur ve adresi görünmüyordur. Böyle küçük hatalarla - hata demeyelim önlem almamak- büyük açıklar oluşabiliyor.&lt;br /&gt;&lt;br /&gt;Bir işyerinin referanslarının birinde açık bulduysanız, bu demektir ki onlarca sitenin açığını bulmuşsunuz. Diğer referans sitelerin bir yerinde illaki bir açık vardır.&lt;br /&gt;&lt;span style="font-size:180%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-size:180%;"&gt;&lt;span style="font-style: italic;"&gt;İnsan bu, "Beşer şaşar".&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;span style="font-family: lucida grande;"&gt;Ama dikkat edilmelidir ki bu referans siteler ticari kurumların siteleridir ve içindeki bilgilerin, sahibinden izinsiz olarak ele geçirilmesi suçtur. Hırsızlık kapsamına girer. Siteki bilgilerin değiştirilmesi, silinmesi - örneğin bir ürünün fiyatının değiştirilmesi- o firmanın adresine gidip, ürünlerini kırmaktan farksızdır.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: lucida grande;"&gt;Sql konusunda, denemelerinizi yaparken dikkatli olun. Evden vs. giriyorsanız yakalanma olasılığınız yüksektir. Dikkatli olun!&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1539550101889367295-4771387772665907812?l=sqlinject.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sqlinject.blogspot.com/feeds/4771387772665907812/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1539550101889367295&amp;postID=4771387772665907812' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/4771387772665907812'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/4771387772665907812'/><link rel='alternate' type='text/html' href='http://sqlinject.blogspot.com/2007/07/sql-szma-injection-iin-gerek-siteleri.html' title='Sql sızma( injection) için gerçek siteleri nereden bulacağım?'/><author><name>sql injection</name><uri>http://www.blogger.com/profile/04352566823640857875</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1539550101889367295.post-6464284918689688679</id><published>2007-07-19T05:55:00.000-07:00</published><updated>2007-09-04T00:15:52.699-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql sızma'/><category scheme='http://www.blogger.com/atom/ns#' term='arama'/><category scheme='http://www.blogger.com/atom/ns#' term='sql hata'/><category scheme='http://www.blogger.com/atom/ns#' term='mssql'/><title type='text'>Google araması ile sql test sitesi</title><content type='html'>&lt;a href="http://www.driverara.org/sorudetay.asp?id=4715%27" 1="'1;--"&gt;http://www.driverara.org/sorudetay.asp?id=4715%27 having 1=1;--&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;Microsoft OLE DB Provider for SQL Server&lt;/span&gt; &lt;span style="font-family:Arial;font-size:85%;"&gt;error '80040e14'&lt;/span&gt; &lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;Column 'soru.cat' is invalid in the select list because it is not contained in an aggregate function and there is no GROUP BY clause.&lt;/span&gt; &lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;/sorudetay.asp&lt;/span&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;, line 72&lt;/span&gt; &lt;/p&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1539550101889367295-6464284918689688679?l=sqlinject.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sqlinject.blogspot.com/feeds/6464284918689688679/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1539550101889367295&amp;postID=6464284918689688679' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/6464284918689688679'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/6464284918689688679'/><link rel='alternate' type='text/html' href='http://sqlinject.blogspot.com/2007/07/google-aramas-ile-sql-test-sitesi_19.html' title='Google araması ile sql test sitesi'/><author><name>sql injection</name><uri>http://www.blogger.com/profile/04352566823640857875</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1539550101889367295.post-1256380358069907994</id><published>2007-07-19T05:26:00.000-07:00</published><updated>2007-07-19T05:28:00.388-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='arama'/><category scheme='http://www.blogger.com/atom/ns#' term='sql hata'/><category scheme='http://www.blogger.com/atom/ns#' term='oracle'/><title type='text'>Google araması ile sql test sitesi</title><content type='html'>&lt;a href="http://www.prc.gov/dockets.asp?ID=R2006-1%27"&gt;http://www.prc.gov/dockets.asp?ID=R2006-1'&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Sunucu:Oracle&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Hata:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p style="font-weight: bold;"&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;Microsoft OLE DB Provider for ODBC Drivers&lt;/span&gt; &lt;span style="font-family:Arial;font-size:85%;"&gt;error '80004005'&lt;/span&gt; &lt;/p&gt;&lt;p&gt; &lt;span style="font-family:Arial;font-size:85%;"&gt;[Oracle][ODBC][Ora]ORA-01756: quoted string not properly terminated &lt;/span&gt; &lt;/p&gt;&lt;p&gt; &lt;span style="font-family:Arial;font-size:85%;"&gt;/dockets.asp&lt;/span&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;, line 41&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p style="font-weight: bold;"&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;&lt;/span&gt; &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1539550101889367295-1256380358069907994?l=sqlinject.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sqlinject.blogspot.com/feeds/1256380358069907994/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1539550101889367295&amp;postID=1256380358069907994' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/1256380358069907994'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/1256380358069907994'/><link rel='alternate' type='text/html' href='http://sqlinject.blogspot.com/2007/07/google-aramas-ile-sql-test-sitesi.html' title='Google araması ile sql test sitesi'/><author><name>sql injection</name><uri>http://www.blogger.com/profile/04352566823640857875</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1539550101889367295.post-8704672002410786433</id><published>2007-07-19T04:54:00.000-07:00</published><updated>2007-07-19T05:02:30.349-07:00</updated><title type='text'></title><content type='html'>&lt;a href="http://www.trb.org/news/blurb_detail.asp?id=2326%27"&gt;http://www.trb.org/news/blurb_detail.asp?id=2326'&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;Microsoft OLE DB Provider for SQL Server&lt;/span&gt; &lt;span style="font-family:Arial;font-size:85%;"&gt;error '80040e14'&lt;/span&gt; &lt;/p&gt;&lt;p&gt; &lt;span style="font-family:Arial;font-size:85%;"&gt;Line 1: Incorrect syntax near ',','.&lt;/span&gt; &lt;/p&gt;&lt;p&gt; &lt;span style="font-family:Arial;font-size:85%;"&gt;/news/blurb_detail.asp&lt;/span&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;, line 24&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;br /&gt;Sql sızma denemeleri...&lt;br /&gt;Sql injection&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1539550101889367295-8704672002410786433?l=sqlinject.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sqlinject.blogspot.com/feeds/8704672002410786433/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1539550101889367295&amp;postID=8704672002410786433' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/8704672002410786433'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/8704672002410786433'/><link rel='alternate' type='text/html' href='http://sqlinject.blogspot.com/2007/07/httpwww_5308.html' title=''/><author><name>sql injection</name><uri>http://www.blogger.com/profile/04352566823640857875</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1539550101889367295.post-1240956143436910387</id><published>2007-07-19T04:48:00.000-07:00</published><updated>2007-07-19T04:54:14.434-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='arama'/><category scheme='http://www.blogger.com/atom/ns#' term='sql hata'/><category scheme='http://www.blogger.com/atom/ns#' term='sql test'/><title type='text'>Google araması ile sql test sitesi</title><content type='html'>&lt;span style="font-weight: bold;"&gt;id=25013 having 1=1&lt;/span&gt;&lt;br /&gt;&lt;a href="http://www.aiim.org/standards.asp?id=25013%20having%201=1"&gt;http://www.aiim.org/standards.asp?id=25013%20having%201=&lt;/a&gt;&lt;a href="http://www.aiim.org/standards.asp?id=25013%20having%201=1"&gt;1&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;Microsoft OLE DB Provider for ODBC Drivers&lt;/span&gt; &lt;span style="font-family:Arial;font-size:85%;"&gt;error '80040e14'&lt;/span&gt; &lt;/p&gt;&lt;p&gt; &lt;span style="font-family:Arial;font-size:85%;"&gt;[Microsoft][ODBC SQL Server Driver][SQL Server]Column 'vwwebarticles.ProductID' is invalid in the select list because it is not contained in an aggregate function and there is no GROUP BY clause.&lt;/span&gt; &lt;/p&gt;&lt;p&gt; &lt;span style="font-family:Arial;font-size:85%;"&gt;/GetArticle.asp&lt;/span&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;, line 101&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;&lt;/span&gt; &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1539550101889367295-1240956143436910387?l=sqlinject.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sqlinject.blogspot.com/feeds/1240956143436910387/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1539550101889367295&amp;postID=1240956143436910387' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/1240956143436910387'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/1240956143436910387'/><link rel='alternate' type='text/html' href='http://sqlinject.blogspot.com/2007/07/httpwww_19.html' title='Google araması ile sql test sitesi'/><author><name>sql injection</name><uri>http://www.blogger.com/profile/04352566823640857875</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1539550101889367295.post-2129727530314347039</id><published>2007-07-17T09:01:00.000-07:00</published><updated>2007-07-17T09:52:33.488-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql hata'/><category scheme='http://www.blogger.com/atom/ns#' term='çözüm'/><category scheme='http://www.blogger.com/atom/ns#' term='mssql'/><title type='text'>Çözüm</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Adres: &lt;/span&gt;http://www.xxx.com/default.asp?id=15 having 1=1;--&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Hata:&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;span style=";font-family:Arial;font-size:85%;"  &gt;&lt;/span&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;&lt;span style=";font-family:Arial;font-size:85%;"  &gt;Microsoft OLE DB Provider for SQL Server&lt;/span&gt; &lt;span style=";font-family:Arial;font-size:85%;"  &gt;error '80040e07'&lt;/span&gt; &lt;/p&gt;&lt;p&gt; &lt;span style=";font-family:Arial;font-size:85%;"  &gt;Syntax error converting the varchar value '15 having 1=1;--' to a column of data type int.&lt;/span&gt; &lt;/p&gt;&lt;p&gt; &lt;span style=";font-family:Arial;font-size:85%;"  &gt;/default.asp&lt;/span&gt;&lt;span style=";font-family:Arial;font-size:85%;"  &gt;, line 61&lt;/span&gt; &lt;/p&gt;&lt;/blockquote&gt;&lt;span style="font-weight: bold;"&gt;Çözüm:&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:georgia;"&gt;http://www.xxx.com/default.asp?id=15&lt;/span&gt;&lt;span style="font-weight: bold;font-family:georgia;" &gt;'  having 1=1;--&lt;br /&gt;&lt;br /&gt;Kaynak:&lt;a href="http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=243810&amp;SiteID=1"&gt;http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=243810&amp;amp;SiteID=1&lt;/a&gt;&lt;br /&gt;Alıntı:&lt;br /&gt;&lt;/span&gt;&lt;blockquote&gt;&lt;span style="font-weight: bold;font-family:georgia;" &gt;&lt;br /&gt;- &lt;/span&gt;&lt;span id="_ctl0_MainContent_PostFlatView"  style="font-family:georgia;"&gt;&lt;span class="txt5"&gt;&lt;span id="_ctl0_MainContent_PostFlatView__ctl0_PostRepeater__ctl0_Subject" style="font-weight: bold;"&gt;Syntax error converting the varchar value 'a' to a column of data type int&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span id="_ctl0_MainContent_PostFlatView"  style="font-family:georgia;"&gt;&lt;span&gt;&lt;p&gt;I have a table(&lt;strong&gt;tab1&lt;/strong&gt;) with a column(&lt;strong&gt;col1&lt;/strong&gt;) of type varchar. I insert a row with an integer value(&lt;strong&gt;1&lt;/strong&gt;). And when i query the table using the sql, &lt;strong&gt;select col1 from tab1 where col1 = 1&lt;/strong&gt;, it works fine. &lt;/p&gt; &lt;p&gt;But after i insert a varchar, say '&lt;strong&gt;a&lt;/strong&gt;' and then do the same query, i get an error message saying, "Syntax error converting the varchar value 'a' to a column of data type int.". Why is this so? Please reply.&lt;/p&gt;&lt;p&gt;&lt;span id="_ctl0_MainContent_PostFlatView"&gt;&lt;span&gt;- Try &lt;span id="_ctl0_MainContent_PostFlatView"&gt;&lt;span&gt;&lt;strong&gt;select col1 from tab1 where col1 = '1'&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt; The ' around the 1 tells SQL server it is comparing the charater 1 not the number 1    &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;/span&gt;                &lt;/span&gt;&lt;span id="_ctl0_MainContent_PostFlatView"&gt;&lt;span class="txt5"&gt;&lt;span id="_ctl0_MainContent_PostFlatView__ctl0_PostRepeater__ctl0_Subject" style="font-weight: bold;"&gt;&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1539550101889367295-2129727530314347039?l=sqlinject.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sqlinject.blogspot.com/feeds/2129727530314347039/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1539550101889367295&amp;postID=2129727530314347039' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/2129727530314347039'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/2129727530314347039'/><link rel='alternate' type='text/html' href='http://sqlinject.blogspot.com/2007/07/zm.html' title='Çözüm'/><author><name>sql injection</name><uri>http://www.blogger.com/profile/04352566823640857875</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1539550101889367295.post-2058807572621031057</id><published>2007-07-15T06:19:00.000-07:00</published><updated>2007-07-19T04:48:04.318-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql sızma'/><category scheme='http://www.blogger.com/atom/ns#' term='sql'/><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sql test'/><category scheme='http://www.blogger.com/atom/ns#' term='google'/><title type='text'>Google araması ile sql test için site bulma</title><content type='html'>&lt;a href="http://www.google.com.tr/search?q=inurl:%22asp?id=%22"&gt;http://www.google.com.tr/search?q=inurl:"asp?id="&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Arama kutusuna&lt;span style="font-weight: bold;"&gt; &lt;a href="http://www.google.com.tr/search?q=inurl:%22asp?id=%22"&gt;inurl:"asp?id=" &lt;/a&gt;&lt;/span&gt;veya &lt;span style="font-weight: bold;"&gt;&lt;a href="http://www.google.com.tr/search?q=inurl:%22php?id=%22"&gt;inurl:"php?id="&lt;/a&gt; &lt;/span&gt;vs. anahtar ifadeleriyle kendiniz için bir test ortamı sunacak site bulabilirsiniz.&lt;br /&gt;Tabi sitenin sahibinin bu testi sunduğundan haberi olmayacak başka&lt;br /&gt;&lt;br /&gt;&lt;a style="font-weight: bold;" href="http://www.google.com.tr/search?hl=tr&amp;q=inurl%3A%22asp%3F%25id%25%3D0..999999"&gt;inurl:"asp?%id%=0..999999"&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.google.com.tr/search?hl=tr&amp;amp;q=inurl%3A%22asp%3F%25id%25%3D0..999999"&gt;http://www.google.com.tr/search?hl=tr&amp;q=inurl%3A%22asp%3F%25id%25%3D0..999999&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1539550101889367295-2058807572621031057?l=sqlinject.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sqlinject.blogspot.com/feeds/2058807572621031057/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1539550101889367295&amp;postID=2058807572621031057' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/2058807572621031057'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/2058807572621031057'/><link rel='alternate' type='text/html' href='http://sqlinject.blogspot.com/2007/07/google-aramas-ile-sql-test-iin-site.html' title='Google araması ile sql test için site bulma'/><author><name>sql injection</name><uri>http://www.blogger.com/profile/04352566823640857875</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1539550101889367295.post-6607955135643829236</id><published>2007-07-15T06:15:00.000-07:00</published><updated>2007-07-15T06:18:43.981-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql sızma'/><category scheme='http://www.blogger.com/atom/ns#' term='sql'/><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sql test'/><title type='text'>http://www.hayatiminhatasi.com</title><content type='html'>http://www.hayatiminhatasi.com&lt;br /&gt;Üye giriş ekranında bariz hata var. Biraz kurcaladıktan sonra site sahibine ve üyelerine iletmek gerekli :D&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1539550101889367295-6607955135643829236?l=sqlinject.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sqlinject.blogspot.com/feeds/6607955135643829236/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1539550101889367295&amp;postID=6607955135643829236' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/6607955135643829236'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/6607955135643829236'/><link rel='alternate' type='text/html' href='http://sqlinject.blogspot.com/2007/07/httpwwwhayatiminhatasicom.html' title='http://www.hayatiminhatasi.com'/><author><name>sql injection</name><uri>http://www.blogger.com/profile/04352566823640857875</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1539550101889367295.post-1835036446283416524</id><published>2007-07-15T06:12:00.000-07:00</published><updated>2007-07-15T06:14:52.085-07:00</updated><title type='text'>http://www.onlineyayin.net/tv_yayin.asp?id</title><content type='html'>&lt;span style="font-weight: bold;font-size:130%;" &gt;&lt;/span&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;Microsoft OLE DB Provider for ODBC Drivers&lt;/span&gt; &lt;span style="font-family:Arial;font-size:85%;"&gt;error '80040e14'&lt;/span&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;span style="font-family:Arial;font-size:85%;"&gt;[MySQL][ODBC 3.51 Driver][mysqld-4.0.23a]You have an error in your SQL syntax. Check the manual that corresponds to your MySQL server version for the right syntax to use near ''' at line 1&lt;/span&gt; &lt;/p&gt;&lt;p&gt; &lt;span style="font-family:Arial;font-size:85%;"&gt;/inc_sayac.asp&lt;/span&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;, line 33&lt;/span&gt; &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1539550101889367295-1835036446283416524?l=sqlinject.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sqlinject.blogspot.com/feeds/1835036446283416524/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1539550101889367295&amp;postID=1835036446283416524' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/1835036446283416524'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/1835036446283416524'/><link rel='alternate' type='text/html' href='http://sqlinject.blogspot.com/2007/07/httpwwwonlineyayinnettvyayinaspid.html' title='http://www.onlineyayin.net/tv_yayin.asp?id'/><author><name>sql injection</name><uri>http://www.blogger.com/profile/04352566823640857875</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1539550101889367295.post-7493062212795217575</id><published>2007-07-15T06:00:00.001-07:00</published><updated>2007-07-19T09:52:50.225-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql sızma'/><category scheme='http://www.blogger.com/atom/ns#' term='sql'/><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sql test'/><category scheme='http://www.blogger.com/atom/ns#' term='mssql'/><title type='text'></title><content type='html'>&lt;span style="font-weight: bold;font-size:130%;" &gt;&lt;a href="http://www.cnbce.com/dizi.asp?ID=3%20having%201=1"&gt;http://www.cnbce.com/dizi.asp?ID=3 having 1=1&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;p&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;Microsoft OLE DB Provider for SQL Server&lt;/span&gt; &lt;span style="font-family:Arial;font-size:85%;"&gt;error '80040e14'&lt;/span&gt; &lt;/p&gt;&lt;p&gt; &lt;span style="font-family:Arial;font-size:85%;"&gt;Column 'Serials.SerialID' is invalid in the select list because it is not contained in an aggregate function and there is no GROUP BY clause.&lt;/span&gt; &lt;/p&gt;&lt;p&gt; &lt;span style="font-family:Arial;font-size:85%;"&gt;/dizi.asp&lt;/span&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;, line 13&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;&lt;/span&gt; &lt;/p&gt;&lt;br /&gt;&lt;span style=";font-family:Arial;font-size:85%;"  &gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1539550101889367295-7493062212795217575?l=sqlinject.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sqlinject.blogspot.com/feeds/7493062212795217575/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1539550101889367295&amp;postID=7493062212795217575' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/7493062212795217575'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/7493062212795217575'/><link rel='alternate' type='text/html' href='http://sqlinject.blogspot.com/2007/07/httpwww_3741.html' title=''/><author><name>sql injection</name><uri>http://www.blogger.com/profile/04352566823640857875</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1539550101889367295.post-3369698397226968055</id><published>2007-07-15T05:48:00.000-07:00</published><updated>2007-07-15T05:49:38.456-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql sızma'/><category scheme='http://www.blogger.com/atom/ns#' term='sql'/><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sql test'/><title type='text'></title><content type='html'>&lt;span style="font-weight: bold;font-size:130%;" &gt;http://www.teknodijital.com/asp&lt;br /&gt;/listgroup.asp?group=&lt;br /&gt;&lt;br /&gt;(union)&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1539550101889367295-3369698397226968055?l=sqlinject.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sqlinject.blogspot.com/feeds/3369698397226968055/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1539550101889367295&amp;postID=3369698397226968055' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/3369698397226968055'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/3369698397226968055'/><link rel='alternate' type='text/html' href='http://sqlinject.blogspot.com/2007/07/httpwww_6122.html' title=''/><author><name>sql injection</name><uri>http://www.blogger.com/profile/04352566823640857875</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1539550101889367295.post-1797719252030922751</id><published>2007-07-15T05:45:00.001-07:00</published><updated>2007-07-15T05:45:30.470-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql sızma'/><category scheme='http://www.blogger.com/atom/ns#' term='sql'/><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><title type='text'></title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;http://www.stokburada.com/&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;index.php?k_id=&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1539550101889367295-1797719252030922751?l=sqlinject.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sqlinject.blogspot.com/feeds/1797719252030922751/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1539550101889367295&amp;postID=1797719252030922751' title='1 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/1797719252030922751'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/1797719252030922751'/><link rel='alternate' type='text/html' href='http://sqlinject.blogspot.com/2007/07/httpwww_6220.html' title=''/><author><name>sql injection</name><uri>http://www.blogger.com/profile/04352566823640857875</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1539550101889367295.post-9193467090459435479</id><published>2007-07-15T05:40:00.001-07:00</published><updated>2007-07-15T05:42:16.991-07:00</updated><title type='text'></title><content type='html'>&lt;span style="font-weight: bold;font-size:130%;" &gt;http://www.alisverissiteleri.net/&lt;br /&gt;siteler.asp?kategori=&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1539550101889367295-9193467090459435479?l=sqlinject.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sqlinject.blogspot.com/feeds/9193467090459435479/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1539550101889367295&amp;postID=9193467090459435479' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/9193467090459435479'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/9193467090459435479'/><link rel='alternate' type='text/html' href='http://sqlinject.blogspot.com/2007/07/httpwww_7923.html' title=''/><author><name>sql injection</name><uri>http://www.blogger.com/profile/04352566823640857875</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1539550101889367295.post-2864721387603645630</id><published>2007-07-15T05:03:00.000-07:00</published><updated>2007-07-15T05:15:40.722-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='eklenti'/><category scheme='http://www.blogger.com/atom/ns#' term='firefox'/><category scheme='http://www.blogger.com/atom/ns#' term='extension'/><category scheme='http://www.blogger.com/atom/ns#' term='add-on'/><category scheme='http://www.blogger.com/atom/ns#' term='hackbar'/><category scheme='http://www.blogger.com/atom/ns#' term='hack'/><title type='text'>HackBar 1.1.1 Firefox eklentisi</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;span style="font-size:100%;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://addons.mozilla.org/en-US/firefox/addon/3899"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 235px; height: 141px;" src="https://addons.mozilla.org/en-US/firefox/images/addon_preview/3899/1" alt="" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;HackBar bir firefox eklentisi, sql ile sitelere sızarken, sizi site adresiyle boşlukları kaldırmaktan,  gerekli fonksiyonları aramaktan vs. kurtarıyor. Çok kullanışlı bir eklenti&lt;br /&gt;&lt;a href="https://addons.mozilla.org/en-US/firefox/addon/3899"&gt;Bu adresten inceleyebilirsiniz ve indirebilirsiniz.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1539550101889367295-2864721387603645630?l=sqlinject.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sqlinject.blogspot.com/feeds/2864721387603645630/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1539550101889367295&amp;postID=2864721387603645630' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/2864721387603645630'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/2864721387603645630'/><link rel='alternate' type='text/html' href='http://sqlinject.blogspot.com/2007/07/hackbar-111-firefox-eklentisi.html' title='HackBar 1.1.1 Firefox eklentisi'/><author><name>sql injection</name><uri>http://www.blogger.com/profile/04352566823640857875</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1539550101889367295.post-8757866325007754608</id><published>2007-07-15T04:52:00.001-07:00</published><updated>2007-07-15T05:18:02.436-07:00</updated><title type='text'></title><content type='html'>&lt;span style="font-weight: bold;font-size:130%;" &gt;http://www.alisverissiteleri.net/&lt;br /&gt;alisveris.asp?sid=&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1539550101889367295-8757866325007754608?l=sqlinject.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sqlinject.blogspot.com/feeds/8757866325007754608/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1539550101889367295&amp;postID=8757866325007754608' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/8757866325007754608'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/8757866325007754608'/><link rel='alternate' type='text/html' href='http://sqlinject.blogspot.com/2007/07/httpwww_15.html' title=''/><author><name>sql injection</name><uri>http://www.blogger.com/profile/04352566823640857875</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1539550101889367295.post-524709986978421962</id><published>2007-07-15T04:36:00.000-07:00</published><updated>2007-07-19T09:48:43.212-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='eklenti'/><category scheme='http://www.blogger.com/atom/ns#' term='firefox'/><category scheme='http://www.blogger.com/atom/ns#' term='add-on'/><title type='text'>Web developer extension</title><content type='html'>Bu firefox eklentisi çok işe yarıyor: Cookie silmek, düzenlemek, javascripti, meta redirecti engellemek, form detayları, gizli öğeler...&lt;br /&gt;Sayfanın içini dışını gösteriyor düğmeleriyle size.&lt;br /&gt;Ben  &lt;a href="http://ferruh.mavituna.com/makale/firefox-eklentileri/"&gt;http://ferruh.mavituna.com/makale/firefox-eklentileri/&lt;/a&gt; Ferruh Mavituna'nın günlüğünde görmüştüm. Kullandım işe yarıyor.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1539550101889367295-524709986978421962?l=sqlinject.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sqlinject.blogspot.com/feeds/524709986978421962/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1539550101889367295&amp;postID=524709986978421962' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/524709986978421962'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/524709986978421962'/><link rel='alternate' type='text/html' href='http://sqlinject.blogspot.com/2007/07/web-developer-extension.html' title='Web developer extension'/><author><name>sql injection</name><uri>http://www.blogger.com/profile/04352566823640857875</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1539550101889367295.post-7722395477613266323</id><published>2007-07-15T04:22:00.000-07:00</published><updated>2007-07-15T05:18:42.277-07:00</updated><title type='text'>Aman ha, siteyle ilgim yok. Sadece internette ararken buldum.</title><content type='html'>&lt;span style="font-weight: bold;"&gt;"http://www.sicakhikaye.com/&lt;br /&gt;kategori.asp?id="&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Site bir "porno hikaye" sitesi. En baştan söyleyeim işim olmaz nu sitelerle. Fakat asp kullanmış. Açığı belli artık nasıl oynarsanız. id= yerine yaza yaza sızacaksınız artık...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1539550101889367295-7722395477613266323?l=sqlinject.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sqlinject.blogspot.com/feeds/7722395477613266323/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1539550101889367295&amp;postID=7722395477613266323' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/7722395477613266323'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/7722395477613266323'/><link rel='alternate' type='text/html' href='http://sqlinject.blogspot.com/2007/07/aman-ha-siteyle-ilgim-yok-sadece.html' title='Aman ha, siteyle ilgim yok. Sadece internette ararken buldum.'/><author><name>sql injection</name><uri>http://www.blogger.com/profile/04352566823640857875</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1539550101889367295.post-8624989090759787997</id><published>2007-07-15T04:16:00.000-07:00</published><updated>2007-07-15T04:21:37.725-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql sızma'/><category scheme='http://www.blogger.com/atom/ns#' term='sql'/><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sql test'/><category scheme='http://www.blogger.com/atom/ns#' term='test lab'/><title type='text'>Sql injection</title><content type='html'>Sql ile uğraşırken google'da arama yapıp, açığı olan siteleri yayınlıyorum. Gerçek hayatta sitelerde hala açıklar var. Bir çeşit canlı deneme ortamı oluşturuyoeum. Siz de bu günlükten yaralanıp, sitelerde kendinizi sınayabilirsiniz sql ile sızma konusunda.&lt;br /&gt;&lt;br /&gt;En baştan söyleyeyim bu siteleri test amaçlı bulup yazıyorum. Oyun parkı gibi bir şey yani...&lt;br /&gt;&lt;br /&gt;Siteler üstünde dilediğinizi yapmakta serbestsiniz. Sonuçların tüm sorumluluğu, sitelere sızma girişiminde bulunan arkadaşlarındır. Bu siteleri yayınlayan ben de değil.&lt;br /&gt;&lt;br /&gt;Hadi Eyvallah,&lt;br /&gt;Kolay gelsin.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1539550101889367295-8624989090759787997?l=sqlinject.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sqlinject.blogspot.com/feeds/8624989090759787997/comments/default' title='Kayıt Yorumları'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1539550101889367295&amp;postID=8624989090759787997' title='0 Yorum'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/8624989090759787997'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1539550101889367295/posts/default/8624989090759787997'/><link rel='alternate' type='text/html' href='http://sqlinject.blogspot.com/2007/07/sql-injection.html' title='Sql injection'/><author><name>sql injection</name><uri>http://www.blogger.com/profile/04352566823640857875</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
