Skip to content

Commit

Permalink
Adding chapter 32,33,34,35 and fixing and adjusting database backend …
Browse files Browse the repository at this point in the history
…for newer lessons along with main page corrections
  • Loading branch information
Audi-1 committed May 1, 2013
1 parent 16a8522 commit 779a155
Show file tree
Hide file tree
Showing 275 changed files with 537 additions and 10 deletions.
Empty file modified Less-1/index.php
100644 → 100755
Empty file.
Empty file modified Less-1/result.txt
100644 → 100755
Empty file.
Empty file modified Less-10/index.php
100644 → 100755
Empty file.
Empty file modified Less-11/index.php
100644 → 100755
Empty file.
Empty file modified Less-12/index.php
100644 → 100755
Empty file.
Empty file modified Less-13/index.php
100644 → 100755
Empty file.
Empty file modified Less-14/index.php
100644 → 100755
Empty file.
Empty file modified Less-15/index.php
100644 → 100755
Empty file.
Empty file modified Less-16/index.php
100644 → 100755
Empty file.
Empty file modified Less-17/index.php
100644 → 100755
Empty file.
Empty file modified Less-18/index.php
100644 → 100755
Empty file.
Empty file modified Less-19/index.php
100644 → 100755
Empty file.
Empty file modified Less-2/index.php
100644 → 100755
Empty file.
Empty file modified Less-2/result.txt
100644 → 100755
Empty file.
Empty file modified Less-21/result.txt
100644 → 100755
Empty file.
Empty file modified Less-22/result.txt
100644 → 100755
Empty file.
Empty file modified Less-23/index.php
100644 → 100755
Empty file.
Empty file modified Less-24/Logged-in.php
100644 → 100755
Empty file.
Empty file modified Less-24/failed.php
100644 → 100755
Empty file.
Empty file modified Less-24/forgot_password.php
100644 → 100755
Empty file.
Empty file modified Less-24/index.php
100644 → 100755
Empty file.
Empty file modified Less-24/logged-in.php
100644 → 100755
Empty file.
Empty file modified Less-24/login.php
100644 → 100755
Empty file.
Empty file modified Less-24/login_create.php
100644 → 100755
Empty file.
Empty file modified Less-24/new_user.php
100644 → 100755
Empty file.
Empty file modified Less-24/pass_change.php
100644 → 100755
Empty file.
Empty file modified Less-25/index.php
100644 → 100755
Empty file.
Empty file modified Less-25a/index.php
100644 → 100755
Empty file.
Empty file modified Less-25a/result.txt
100644 → 100755
Empty file.
Empty file modified Less-26/index.php
100644 → 100755
Empty file.
Empty file modified Less-26/result.txt
100644 → 100755
Empty file.
Empty file modified Less-26a/index.php
100644 → 100755
Empty file.
Empty file modified Less-27/index.php
100644 → 100755
Empty file.
Empty file modified Less-27/result.txt
100644 → 100755
Empty file.
Empty file modified Less-27a/index.php
100644 → 100755
Empty file.
Empty file modified Less-28/index.php
100644 → 100755
Empty file.
Empty file modified Less-28a/index.php
100644 → 100755
Empty file.
Empty file modified Less-29/hacked.php
100644 → 100755
Empty file.
Empty file modified Less-29/index.php
100644 → 100755
Empty file.
Empty file modified Less-29/login.php
100644 → 100755
Empty file.
Empty file modified Less-3/index.php
100644 → 100755
Empty file.
Empty file modified Less-30/hacked.php
100644 → 100755
Empty file.
Empty file modified Less-30/index.php
100644 → 100755
Empty file.
Empty file modified Less-30/login.php
100644 → 100755
Empty file.
Empty file modified Less-31/hacked.php
100644 → 100755
Empty file.
Empty file modified Less-31/index.php
100644 → 100755
Empty file.
Empty file modified Less-31/login.php
100644 → 100755
Empty file.
85 changes: 85 additions & 0 deletions Less-32/index.php
Original file line number Diff line number Diff line change
@@ -0,0 +1,85 @@
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<title>Less-32 **Bypass addslashes()**</title>
</head>

<body bgcolor="#000000">
<div style=" margin-top:70px;color:#FFF; font-size:23px; text-align:center">Welcome&nbsp;&nbsp;&nbsp;<font color="#FF0000"> Dhakkan </font><br>
<font size="5" color="#00FF00">


<?php
//including the Mysql connect parameters.
include("../sql-connections/sql-connect.php");

function check_addslashes($string)
{
$string = preg_replace('/'. preg_quote('\\') .'/', "\\\\\\", $string); //escape any backslash
$string = preg_replace('/\'/i', '\\\'', $string); //escape single quote with a backslash
$string = preg_replace('/\"/', "\\\"", $string); //escape double quote with a backslash


return $string;
}

// take the variables
if(isset($_GET['id']))
{
$id=check_addslashes($_GET['id']);
//echo "The filtered request is :" .$id . "<br>";

//logging the connection parameters to a file for analysis.
$fp=fopen('result.txt','a');
fwrite($fp,'ID:'.$id."\n");
fclose($fp);

// connectivity


$sql="SELECT * FROM users WHERE id='$id' LIMIT 0,1";
$result=mysql_query($sql);
$row = mysql_fetch_array($result);

if($row)
{
echo '<font color= "#00FF00">';
echo 'Your Login name:'. $row['username'];
echo "<br>";
echo 'Your Password:' .$row['password'];
echo "</font>";
}
else
{
echo '<font color= "#FFFF00">';
print_r(mysql_error());
echo "</font>";
}
}
else { echo "Please input the ID as parameter with numeric value";}



?>
</font> </div></br></br></br><center>
<img src="../images/Less-32.jpg" />
</br>
</br>
</br>
</br>
</br>
<font size='4' color= "#33FFFF">
<?php
echo "Hint: The Query String you input is escaped as : ".$id;
?>
</center>
</font>
</body>
</html>






81 changes: 81 additions & 0 deletions Less-33/index.php
Original file line number Diff line number Diff line change
@@ -0,0 +1,81 @@
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<title>Less-32 **Bypass addslashes()**</title>
</head>

<body bgcolor="#000000">
<div style=" margin-top:70px;color:#FFF; font-size:23px; text-align:center">Welcome&nbsp;&nbsp;&nbsp;<font color="#FF0000"> Dhakkan </font><br>
<font size="5" color="#00FF00">


<?php
//including the Mysql connect parameters.
include("../sql-connections/sql-connect.php");

function check_addslashes($string)
{
$string= addslashes($string);
return $string;
}

// take the variables
if(isset($_GET['id']))
{
$id=check_addslashes($_GET['id']);
//echo "The filtered request is :" .$id . "<br>";

//logging the connection parameters to a file for analysis.
$fp=fopen('result.txt','a');
fwrite($fp,'ID:'.$id."\n");
fclose($fp);

// connectivity


$sql="SELECT * FROM users WHERE id='$id' LIMIT 0,1";
$result=mysql_query($sql);
$row = mysql_fetch_array($result);

if($row)
{
echo '<font color= "#00FF00">';
echo 'Your Login name:'. $row['username'];
echo "<br>";
echo 'Your Password:' .$row['password'];
echo "</font>";
}
else
{
echo '<font color= "#FFFF00">';
print_r(mysql_error());
echo "</font>";
}
}
else { echo "Please input the ID as parameter with numeric value";}



?>
</font> </div></br></br></br><center>
<img src="../images/Less-33.jpg" />
</br>
</br>
</br>
</br>
</br>
<font size='4' color= "#33FFFF">
<?php
echo "Hint: The Query String you input is escaped as : ".$id;
?>
</center>
</font>
</body>
</html>






119 changes: 119 additions & 0 deletions Less-34/index.php
Original file line number Diff line number Diff line change
@@ -0,0 +1,119 @@
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<title>Less-34- Bypass Add SLASHES</title>
</head>

<body bgcolor="#000000">
<div style=" margin-top:20px;color:#FFF; font-size:24px; text-align:center"> Welcome&nbsp;&nbsp;<font color="#FF0000"> Dhakkan </font><br></div>

<div align="center" style="margin:40px 0px 0px 520px;border:20px; background-color:#0CF; text-align:center; width:400px; height:150px;">

<div style="padding-top:10px; font-size:15px;">


<!--Form to post the data for sql injections Error based SQL Injection-->
<form action="" name="form1" method="post">
<div style="margin-top:15px; height:30px;">Username : &nbsp;&nbsp;&nbsp;
<input type="text" name="uname" value=""/>
</div>
<div> Password : &nbsp;&nbsp;&nbsp;
<input type="text" name="passwd" value=""/>
</div></br>
<div style=" margin-top:9px;margin-left:90px;">
<input type="submit" name="submit" value="Submit" />
</div>
</form>

</div>
</div>
<div style=" margin-top:10px;color:#FFF; font-size:23px; text-align:center">
<font size="3" color="#FFFF00">
<center>
<br>
<br>
<br>
<img src="../images/Less-34.jpg" />
</center>

<?php
//including the Mysql connect parameters.
include("../sql-connections/sql-connect.php");


// take the variables
if(isset($_POST['uname']) && isset($_POST['passwd']))
{
$uname1=$_POST['uname'];
$passwd1=$_POST['passwd'];

//echo "username before addslashes is :".$uname1 ."<br>";
//echo "Input password before addslashes is : ".$passwd1. "<br>";

//logging the connection parameters to a file for analysis.
$fp=fopen('result.txt','a');
fwrite($fp,'User Name:'.$uname1);
fwrite($fp,'Password:'.$passwd1."\n");
fclose($fp);

$uname = addslashes($uname1);
$passwd= addslashes($passwd1);

//echo "username after addslashes is :".$uname ."<br>";
//echo "Input password after addslashes is : ".$passwd;

// connectivity
@$sql="SELECT username, password FROM users WHERE username='$uname' and password='$passwd' LIMIT 0,1";
$result=mysql_query($sql);
$row = mysql_fetch_array($result);

if($row)
{
//echo '<font color= "#0000ff">';

echo "<br>";
echo '<font color= "#FFFF00" font size = 4>';
//echo " You Have successfully logged in\n\n " ;
echo '<font size="3" color="#0000ff">';
echo "<br>";
echo 'Your Login name:'. $row['username'];
echo "<br>";
echo 'Your Password:' .$row['password'];
echo "<br>";
echo "</font>";
echo "<br>";
echo "<br>";
echo '<img src="../images/flag.jpg" />';

echo "</font>";
}
else
{
echo '<font color= "#0000ff" font size="3">';
//echo "Try again looser";
print_r(mysql_error());
echo "</br>";
echo "</br>";
echo "</br>";
echo '<img src="../images/slap.jpg" />';
echo "</font>";
}
}

?>

</br>
</br>
</br>
<font size='4' color= "#33FFFF">
<?php

echo "Hint: The Username you input is escaped as : ".$uname ."<br>";
echo "Hint: The Password you input is escaped as : ".$passwd ."<br>";
?>

</font>
</div>
</body>
</html>
81 changes: 81 additions & 0 deletions Less-35/index.php
Original file line number Diff line number Diff line change
@@ -0,0 +1,81 @@
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<title>Less-35 **why care for addslashes()**</title>
</head>

<body bgcolor="#000000">
<div style=" margin-top:70px;color:#FFF; font-size:23px; text-align:center">Welcome&nbsp;&nbsp;&nbsp;<font color="#FF0000"> Dhakkan </font><br>
<font size="5" color="#00FF00">


<?php
//including the Mysql connect parameters.
include("../sql-connections/sql-connect.php");

function check_addslashes($string)
{
$string = addslashes($string);
return $string;
}

// take the variables
if(isset($_GET['id']))
{
$id=check_addslashes($_GET['id']);
//echo "The filtered request is :" .$id . "<br>";

//logging the connection parameters to a file for analysis.
$fp=fopen('result.txt','a');
fwrite($fp,'ID:'.$id."\n");
fclose($fp);

// connectivity


$sql="SELECT * FROM users WHERE id=$id LIMIT 0,1";
$result=mysql_query($sql);
$row = mysql_fetch_array($result);

if($row)
{
echo '<font color= "#00FF00">';
echo 'Your Login name:'. $row['username'];
echo "<br>";
echo 'Your Password:' .$row['password'];
echo "</font>";
}
else
{
echo '<font color= "#FFFF00">';
print_r(mysql_error());
echo "</font>";
}
}
else { echo "Please input the ID as parameter with numeric value";}



?>
</font> </div></br></br></br><center>
<img src="../images/Less-35.jpg" />
</br>
</br>
</br>
</br>
</br>
<font size='4' color= "#33FFFF">
<?php
echo "Hint: The Query String you input is escaped as : ".$id;
?>
</center>
</font>
</body>
</html>






Empty file modified Less-4/index.php
100644 → 100755
Empty file.
Empty file modified Less-5/index.php
100644 → 100755
Empty file.
Empty file modified Less-6/index.php
100644 → 100755
Empty file.
Empty file modified Less-7/index.php
100644 → 100755
Empty file.
Empty file modified Less-8/index.php
100644 → 100755
Empty file.
Empty file modified Less-9/index.php
100644 → 100755
Empty file.
Loading

0 comments on commit 779a155

Please sign in to comment.