Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

How to hacking Firefox users

Monday, March 9, 2009 Posted by Sanka Senevirathna 0 comments
How to hacking Firefox users.

I know Some of my friends are using remember password feature in firefox. This is the way hacking their passwords.
Remember don't save your passwords any more in Firefox, if you are sharing your owner computer.

  • This is the way to View anyone stored passwords in Firefox:
To view all the saved passward in Firefox.Go to
Tools -> Options -> Security -> Saved Passwords.
And there you have all the passwords that you ever asked Firefox to remember for you.


  • To Enable Or Disable Remember me Option from yours Firefox Go to

Tools -> Options -> Security

Check or Uncheck Remember passward for sites as per yours requirement , See below screenshot. for details.
  • You can also Control remember me passward feature by disable this feature for some website and enabling for some website , Check Exception Tab for more details


Lets consider how to get dotted passwords



if you have this kind of browser page you can easily view this passwords by pasting following script in address bar (insted of url) and hit Enter




A dialog box will prompt and your password is shown!






How to fast your Internet connection.


And there is another thing that I found from another site to improve you firefox effiency

1.Type “about:config” into the address bar and hit.

then scrol down and
Set “network.http.pipelining” to “true”

Set “network.http.proxy.pipelining” to “true”

Set “network.http.pipelining.maxrequests” to some number like 30(will make 30 requests at once).

Finally right-click anywhere and
select New-> Integer.
Name it “nglayout.initialpaint.delay” and set its value to “0″.
This value is the amount of time the browser waits before it acts on information it receives.
Now you’re broadband connection will load pages MUCH faster!



Labels:

Avoiding SQL Injection by sanka dilmadu

Wednesday, January 14, 2009 Posted by Sanka Senevirathna 1 comments

Avoiding SQL Injection


If you are a web developer this article is very important regarding Data security of your application. Actually to avoid hacking your database you have to learn how to hacking database. So sanka will teach you how to hacking database by SQL injection.


following is very interresting...check it..I think it is not more a hacking method,bcz all are know about htis by my articles.

’, ‘’); drop table MyTable;--


most of fu..ing web developers are doing following incorrect idiot type of coding..







string cmdStr =
"insert into Shippers (CompanyName, Phone) values ('" +
txtCompanyName.Text + "', '" + txtPhone.Text + "')";




So my friends do the following type of thing here



insert into Shippers (CompanyName, Phone) values ('', ''); drop table MyTable;--', '')


user name :


The first part of this statement adds a new row with blank values to the Shippers table. The second part, after the first semicolon (;), removes the MyTable table from the database. The rest of the statement, after the second semicolon, is commented out to prevent errors.

As you can see, attackers can do a lot of damage to your system or view information they aren’t supposed to see. Even worse, although it may not be totally obvious by this example, through SQL injection an attacker could potentially take over your entire system.



So this is the solution for that



string surname = this.surnameTb.Text.Replace("'", "''");
string cmdStr =
"insert into Shippers (CompanyName, Phone) values (" +
"@CompanyName, @Phone)";
using (SqlConnection conn = new SqlConnection(connStr))
using (SqlCommand cmd = new SqlCommand(cmdStr, conn))
{
// add parameters
cmd.Parameters.AddWithValue
("@CompanyName", txtCompanyName.Text);
cmd.Parameters.AddWithValue("@Phone", txtPhone.Text);
conn.Open();
cmd.ExecuteNonQuery();
}