Solved How hackers will try and hack your website!

Neverhavemoney

Registered Nurse
Hello everyone,

This is for educational purposes only. I hope no one on this site would abuse the information i am about to provide.


Remote File Inclusion (RFI):
A method of uploading a shell by an off-site link.

Local File Inclusion (LFI) AKA Directory traversal attack:
A method of pulling usernames and passwords off a website vulnerable to the exploit of insufficient security validation / sanitization of user-supplied input file names.

Blind Structured Query Language Injection: (blind SQLI):
Method of once again insufficient security validation and sanitization of user-input.

Basic SQLi:
This is the easiest method of SQLi. This method allows you to enter codes such as ' or '1'='1 into the username and password fields to gain access.

Cross Site Scripting (XSS):
A method of injection html/javascript into a website. The can be both persistent attacks, and non-persistent.

Cross site request forgery (CSRF):
An attack that is commonly sent by e-mail or other means and often tricks a user. Links given to a target may include HTML.This will be activated through the slave's browser and the site will think it was a valid and intentional move.

Public Exploits:
Public exploits are just scripts that people have released for others to use. Such as
this exploit which exploits a web-server running this program on one of its open ports.

DNS hijacking:
This is the method or redirecting the domain name to a rouge domain name. This method is used particularly in phishing attacks.
Another attempt that can be used to hijack the domain name is called DNS cache poisoning.

Brute-forcing:
This method is the practice of running a program to keep guessing the password and username of a site. This method is vastly going out of fashion as the max login attempts are added and even without this obstacle, it can take weeks to gain the correct password.

Password Guessing:
Yes, just as it sounds. This is the method of just guessing common passwords.

Packet Sniffing:
If a site with FTP access is found, there is software they can use to sniff the password and username when the login.

RCE (Remote Command Execution):
This is the method of making the server read command that you have entered for it to.

Social Engineering:
A common method used to gain information. This can be a long process, but an effective one.

Cookie poisoning:
This is a method of editing cookies you have already gained, to gain extra privileges. Not a very common method now as of cookies being encrypted, and having to be signed.

Parameter tampering:
An attack usual done by modifying values in the url. E.g. changing a value to decrease the amount you have to pay on something.

****** ****:
A Firefox add-on which is used to modify http/https headers and post parameters.

Admin Auth bypass:
This exploit when a server/application allows you to edit by having the valid URL, instead of by cookies. Another method of admin auth bypass is editing the html to proceed even if the password is wrong.
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Clevo W870CU
OS
Windows 7 Ultimate Professional x64
CPU
Intel Core i7-740QM @ 1.73GHz 4Core
Motherboard
Intel PM55
Memory
2 X 4GB DDR3-SDRAM 667MHz
Graphics Card(s)
ATI Mobility Radeon HD 5870 1GB SDRAM
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
AUO149D 17.1" HD+/FHD @600Hz
Screen Resolution
1920X1080
Hard Drives
Seagate A0D-10F4 - 500 GB @7200RPM
PSU
43290mWh Intel Lithium-Ion Battery
Case
Cleveo W870CU
Cooling
2 Fans
Keyboard
Microsoft eHome MCIR 109
Mouse
Finger Sensing HID-Compliant Mouse Pad
Internet Speed
100 MB/s
Antivirus
avast! Antivirus
Browser
Google Chrome
Other Info
Biometric Enabled
2.0MP Cam
****** ****:
A Firefox add-on which is used to modify http/https headers and post parameters.

LOL
 

My Computer

OS
Windows 7 Ultimate 64-bit
CPU
AMD Phenom II X6 1090T 3.2GHZ
Motherboard
MSI 890FXA-GD70
Memory
G.SKILL RipJaw 3x2GB DDR3-1066
Graphics Card(s)
2x HIS Radeon HD 6850 1 GB
Sound Card
VIA 8-channel
Monitor(s) Displays
2x 20 inch Acer LCDs, 1x 32" Sony LCD TV
Screen Resolution
4480x900
Hard Drives
1x Crucial 64GB SSD
3x 1TB HDDs (WD, Seagate, Hitatchi)
1x 500GB Seagate External
PSU
Kingwin 1000W Modular
Case
Coolermaster HAF 932
Cooling
1x 120mm, 3x 200mm, CoolerMaster Hyper 212+
Keyboard
Microsoft Wireless Keyboard 1000
Mouse
Microsoft Wiresless Mouse 5000
Internet Speed
20mbps
Other Info
Samsung BD-ROM/DVD-RW

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Clevo W870CU
OS
Windows 7 Ultimate Professional x64
CPU
Intel Core i7-740QM @ 1.73GHz 4Core
Motherboard
Intel PM55
Memory
2 X 4GB DDR3-SDRAM 667MHz
Graphics Card(s)
ATI Mobility Radeon HD 5870 1GB SDRAM
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
AUO149D 17.1" HD+/FHD @600Hz
Screen Resolution
1920X1080
Hard Drives
Seagate A0D-10F4 - 500 GB @7200RPM
PSU
43290mWh Intel Lithium-Ion Battery
Case
Cleveo W870CU
Cooling
2 Fans
Keyboard
Microsoft eHome MCIR 109
Mouse
Finger Sensing HID-Compliant Mouse Pad
Internet Speed
100 MB/s
Antivirus
avast! Antivirus
Browser
Google Chrome
Other Info
Biometric Enabled
2.0MP Cam
Back
Top