hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Full Version: Sql Exec 3
The Storm
Hi I`m postiung here "SQLEXEC for Nethacker III" it sometimes can bypass the SQL_ERROR u get on the normal SQLEXEC with the green apple hop it help`s.
pdf
tnx m8 I'll check it

is there a new features?

edit:

I noticed some basic bugs before i try to hack with it

SQL>Connecting 127.0.0.1.
SQL>Disconnected.
SQL>Disconnected.

how's that? disconnect twice? blink.gif (sometimes it's 3 times)

edit 2:

I noticed also that you program have some overflows smile.gif
The Storm
what du u mean? I don`t know ur problem!
pdf
read edit 2
The Storm
what du u think about when u say overflows? on my PC it works fine but i only use it if i have the SQL_ERROR on the one with the green apple. If u tell me exactly hat errors u have i can help u evt.!
pdf
it works fine but there are some errors when u input too many parameters on some textboxs (such as 'ip box' , 'user box' , 'pass box' , 'cmd box' and the 'registering box' )

try it u will get error and the app will be crashed!
DumpZ
Looks nice but im gonna stick with 2.0 because in that one i can echo quote signs and in this version i can't.

But Thanks for sharing!
vnet576
Nice version, but can u add support for direct injection of other sql commands. For example right now u use the format xp_cmdshell %s (s is command)...can u make the xp_cmdshell parameter optional so that I could add other sp commands for example sp_password.
Hellraiseruk
gonna dl this m8..thx for the update biggrin.gif
drizzlah
nice go to try this appz !!!
The Storm
I havn`t coded this one and above i told that i use this one only if i get SQL_ERROR but i can`t alway bypass it judt try it!
sylver
i use this sqlexec for some time now, but it never bypass the sql_error!
shii
great job if it bypass the SQL error, i no longer use the 1443 port fora long time !!

thanx mate
The Storm
It's not always able to bypass the SQL_ERROR but sometimes i don`t know what it does to do this if somebody know pls tell it!
ellitio
this one is better than the one with the apple tongue.gif
ThankS!! smile.gif
The Storm
I don't think so i think the one with the green apple is better but if u thi9nk so I`m happy cause i could help u *g*
Killaloop
QUOTE (The Storm @ Mar 24 2004, 08:10 PM)
It's not always able to bypass the SQL_ERROR but sometimes i don`t know what it does to do this if somebody know pls tell it!

it uses some tricks to identify you as a "trusted connection" so you have execute permissions. thats also the reason why you cannot use " since it doesn't support it in the way the procedur is used in that program.
for all who wanna get a little more professional or for those of you who know what they are doing I can recommend MsSQLMs.
Its a gui SQL Server manager.
but only use it if you know what you are doing because you will see the whole database and could delete and create everything within the SA role.
this one also would be able to do what vnet576 asked for but its of course query based smile.gif
marteltor
the file i downloaded is 0 kb?!
The Storm
evt. u have a firewall that blocks the dl!
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.