<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Hack a Day &#187; sql</title>
	<atom:link href="http://hackaday.com/tag/sql/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Fri, 10 Feb 2012 06:18:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='hackaday.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/5560f98f805877b0e332f191cb9e0af3?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Hack a Day &#187; sql</title>
		<link>http://hackaday.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://hackaday.com/osd.xml" title="Hack a Day" />
	<atom:link rel='hub' href='http://hackaday.com/?pushpress=hub'/>
		<item>
		<title>Use Droid Bionic as a mobile hotspot without paying extra</title>
		<link>http://hackaday.com/2011/09/13/use-droid-bionic-as-a-mobile-hotspot-without-paying-extra/</link>
		<comments>http://hackaday.com/2011/09/13/use-droid-bionic-as-a-mobile-hotspot-without-paying-extra/#comments</comments>
		<pubDate>Tue, 13 Sep 2011 17:04:58 +0000</pubDate>
		<dc:creator>Mike Szczys</dc:creator>
				<category><![CDATA[cellphones hacks]]></category>
		<category><![CDATA[hotspot]]></category>
		<category><![CDATA[root]]></category>
		<category><![CDATA[sql]]></category>
		<category><![CDATA[Tether]]></category>
		<category><![CDATA[verizon]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=55502</guid>
		<description><![CDATA[Apparently Verizon customers are expected to pay for a second data plan if they want to be allowed to use a cellphone as a mobile hotspot. This means one data plan for the phone, and a second for the tethering. [DroidBionicRoot] thinks this is a little silly since there is already a data cap on [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=55502&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-55503" title="droid-bionic-hotspot" src="http://hackadaycom.files.wordpress.com/2011/09/droid-bionic-hotspot.jpg" alt="" width="470" height="353" /></p>
<p>Apparently Verizon customers are expected to pay for a second data plan if they want to be allowed to use a cellphone as a mobile hotspot. This means one data plan for the phone, and a second for the tethering. [DroidBionicRoot] thinks this is a little silly since there is already a data cap on the phone&#8217;s plan. But he&#8217;s found a way around it if you don&#8217;t mind <a href="http://droidbionicroot.com/droid-bionic-tether/how-to-get-free-wifi-tether-mobile-hotspot-on-your-droid-bionic/">rooting the phone to enable free tethering</a>.</p>
<p>Not surprisingly it&#8217;s a very simple alteration. The phone is already capable of tethering, to enable the feature without Verizon&#8217;s permission just edit one database value. In the video after the break, [DroidBionicRoot] starts the process with a rooted Droid Bionic handset. He purchases an app for $2.99 which allows him to edit SQL databases on the handset. From there he navigates to the &#8216;Settings Storage&#8217; database and changes the &#8216;entitlement_check&#8217; key value to 0. Reboot the phone and tethering is now unlocked.</p>
<p><span id="more-55502"></span><span style="text-align:center; display: block;"><a href="http://hackaday.com/2011/09/13/use-droid-bionic-as-a-mobile-hotspot-without-paying-extra/"><img src="http://img.youtube.com/vi/vuSHY7ed0oU/2.jpg" alt="" /></a></span></p>
<p>[Thanks Max]</p>
<br />Filed under: <a href='http://hackaday.com/category/cellphones-hacks/'>cellphones hacks</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/55502/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/55502/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/55502/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/55502/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/55502/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/55502/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/55502/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/55502/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/55502/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/55502/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/55502/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/55502/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/55502/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/55502/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=55502&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2011/09/13/use-droid-bionic-as-a-mobile-hotspot-without-paying-extra/feed/</wfw:commentRss>
		<slash:comments>45</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike Szczys</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2011/09/droid-bionic-hotspot.jpg" medium="image">
			<media:title type="html">droid-bionic-hotspot</media:title>
		</media:content>
	</item>
		<item>
		<title>Barcode Infiltrator</title>
		<link>http://hackaday.com/2010/09/02/barcode-infiltrator/</link>
		<comments>http://hackaday.com/2010/09/02/barcode-infiltrator/#comments</comments>
		<pubDate>Thu, 02 Sep 2010 15:12:01 +0000</pubDate>
		<dc:creator>James Munns</dc:creator>
				<category><![CDATA[classic hacks]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[barcode]]></category>
		<category><![CDATA[database]]></category>
		<category><![CDATA[injection]]></category>
		<category><![CDATA[led]]></category>
		<category><![CDATA[scripting]]></category>
		<category><![CDATA[sql]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=27893</guid>
		<description><![CDATA[Whenever someone manages to expose vulnerabilities in everyday devices, we love to root for them. [Adrian] over at Irongeek has been inspired to exploit barcodes as a means to attack a POS database. Based on an idea from a Pauldotcom episode, he set out to make a rapid attack device, using an LED to spoof [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=27893&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-27894" title="image" src="http://hackadaycom.files.wordpress.com/2010/09/image.jpg" alt="" width="470" height="275" /></p>
<p>Whenever someone manages to expose vulnerabilities in everyday devices, we love to root for them. [Adrian] over at Irongeek has been inspired to <a href="http://www.irongeek.com/i.php?page=security/barcode-flashing-led-fuzzer-bruteforcer-injector">exploit barcodes</a> as a means to attack a POS database. Based on an idea from a <a href="http://pauldotcom.com/2010/01/pauldotcom-security-weekly---e-56.html">Pauldotcom</a> episode, he set out to make a rapid attack device, using an LED to spoof the signals that would be received by scanning a barcode. By exposing the POS to a set of generic database attacks, including <a href="http://en.wikipedia.org/wiki/Cross-site_scripting">XSS</a>, <a href="http://en.wikipedia.org/wiki/SQL_injection">SQL Injection</a>, and other errors easily solved by input sanitation, he has created the first version of an automated system penetration device. In this case the hardware is simple, but the concept is impressive.</p>
<p>With the hardware explained and the source code provided, as well as a basic un-sanitized input <a href="http://www.irongeek.com/xss-sql-injection-fuzzing-barcode-generator.php">cheat sheet</a>, the would-be barcode hackers have a great place to start if they feel compelled to provide a revision two.</p>
<p>[Thanks Robert W.]</p>
<br />Filed under: <a href='http://hackaday.com/category/classic-hacks/'>classic hacks</a>, <a href='http://hackaday.com/category/security-hacks/'>security hacks</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/27893/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/27893/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/27893/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/27893/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/27893/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/27893/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/27893/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/27893/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/27893/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/27893/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/27893/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/27893/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/27893/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/27893/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=27893&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2010/09/02/barcode-infiltrator/feed/</wfw:commentRss>
		<slash:comments>25</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">jahmez</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2010/09/image.jpg" medium="image">
			<media:title type="html">image</media:title>
		</media:content>
	</item>
		<item>
		<title>Real time gas monitoring</title>
		<link>http://hackaday.com/2008/09/21/real-time-gas-monitoring/</link>
		<comments>http://hackaday.com/2008/09/21/real-time-gas-monitoring/#comments</comments>
		<pubDate>Mon, 22 Sep 2008 02:41:22 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[cellphones hacks]]></category>
		<category><![CDATA[classic hacks]]></category>
		<category><![CDATA[home hacks]]></category>
		<category><![CDATA[energy]]></category>
		<category><![CDATA[energy monitor]]></category>
		<category><![CDATA[gas]]></category>
		<category><![CDATA[gas heating]]></category>
		<category><![CDATA[pys60]]></category>
		<category><![CDATA[python]]></category>
		<category><![CDATA[sql]]></category>
		<category><![CDATA[symbian]]></category>

		<guid isPermaLink="false">http://hackadaycom.wordpress.com/?p=3527</guid>
		<description><![CDATA[With the weather getting colder, [Daniel] decided it would be a good idea to monitor how much energy his gas heating was using in real time. He used a Nokia 6680 cameraphone to monitor the heater&#8217;s flame through the sight glass. PyS60, a Symbian implementation of Python, checks the image sent by the camera and [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=3527&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-3528" title="gas_meter" src="http://hackadaycom.files.wordpress.com/2008/09/gas_meter.jpg" alt="" width="450" height="325" /></p>
<p>With the weather getting colder, [Daniel] decided it would be a good idea to <a href="http://blog.danielwinter.de/archives/13">monitor how much energy his gas heating was using</a> in real time. He used a Nokia 6680 cameraphone to monitor the heater&#8217;s flame through the sight glass. <a href="http://wiki.opensource.nokia.com/projects/PyS60">PyS60</a>, a Symbian implementation of Python, checks the image sent by the camera and measures how much blue flame is visible. These values are stored in a SQL DB on the phone that can be polled over Bluetooth. At the end of the billing cycle,  he&#8217;ll be able to correlate the amount of gas used with what the phone reported.</p>
<p>[Thanks,  florent bayle]</p>
<br />Posted in cellphones hacks, classic hacks, home hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/3527/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/3527/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/3527/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/3527/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/3527/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/3527/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/3527/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/3527/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/3527/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/3527/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/3527/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/3527/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/3527/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/3527/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=3527&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/09/21/real-time-gas-monitoring/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/09/gas_meter.jpg" medium="image">
			<media:title type="html">gas_meter</media:title>
		</media:content>
	</item>
		<item>
		<title>Crawling + SQL injection with Scrawlr</title>
		<link>http://hackaday.com/2008/06/24/crawling-sql-injection-with-scrawlr/</link>
		<comments>http://hackaday.com/2008/06/24/crawling-sql-injection-with-scrawlr/#comments</comments>
		<pubDate>Wed, 25 Jun 2008 04:15:00 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[security hacks]]></category>
		<category><![CDATA[crawler]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[scrawlr]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sql]]></category>
		<category><![CDATA[sqlinjection]]></category>
		<category><![CDATA[tool]]></category>
		<category><![CDATA[verboseinjection]]></category>
		<category><![CDATA[webcrawler]]></category>

		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/06/24/crawling-sql-injection-with-scrawlr/</guid>
		<description><![CDATA[Scrawlr is the latest tool to come out of HP&#8217;s Web Security Research Group. It was built in response to the massive number of SQL injection attacks happening on the web this year. Most of these vulnerable sites are found through googling, so Scrawlr works the same way. Point it at your web server and [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2103&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div align="center"><img width="400" vspace="4" hspace="4" height="308" border="0" src="http://hackadaycom.files.wordpress.com/2008/06/had_scrawlr.jpg?w=400&#038;h=308"  alt="" /></div>
<p><a href="https://download.spidynamics.com/Products/scrawlr/">Scrawlr</a> is the latest tool to come out of HP&#8217;s Web Security Research Group. It was built in response to the <a href="http://www.microsoft.com/technet/security/advisory/954462.mspx">massive number of SQL injection attacks</a> happening on the web this year. Most of these vulnerable sites are found through googling, so Scrawlr works the same way. Point it at your web server and it will <a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2008/06/23/finding-sql-injection-with-scrawlr.aspx">crawl all of the pages and evaluate the URL parameters</a> to see if they&#8217;re vulnerable to verbose injection. It reports the SQL server and table names if it comes across anything.</p>
<p>It only supports 1500 pages right now and can&#8217;t do authentication or blind injection. It&#8217;s still a free tool and a great way to identify if your site is vulnerable to automated tools finding you website via search engines.</p>
<p>[via <a href="http://www.memestreams.net/users/acidus/blogid10328589/">Acidus</a>]</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackadaycom.wordpress.com/2103/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackadaycom.wordpress.com/2103/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/2103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/2103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/2103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/2103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/2103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/2103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/2103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/2103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/2103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/2103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/2103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/2103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/2103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/2103/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2103&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/06/24/crawling-sql-injection-with-scrawlr/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/06/had_scrawlr.jpg" medium="image" />
	</item>
		<item>
		<title>Exploit-Me Firefox XSS and SQL scanning addon</title>
		<link>http://hackaday.com/2008/06/14/exploit-me-firefox-xss-and-sql-scanning-addon/</link>
		<comments>http://hackaday.com/2008/06/14/exploit-me-firefox-xss-and-sql-scanning-addon/#comments</comments>
		<pubDate>Sat, 14 Jun 2008 09:40:00 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[cons]]></category>
		<category><![CDATA[firefox hacks]]></category>
		<category><![CDATA[addon]]></category>
		<category><![CDATA[crosssitescripting]]></category>
		<category><![CDATA[dansinclair]]></category>
		<category><![CDATA[extension]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[layerone]]></category>
		<category><![CDATA[layerone2008]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[securitycompass]]></category>
		<category><![CDATA[sql]]></category>
		<category><![CDATA[sqlinjection]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/06/14/exploit-me-firefox-xss-and-sql-scanning-addon/</guid>
		<description><![CDATA[One of the best tools we saw at LayerOne was the Exploit-Me series presented by [Dan Sinclair]. Security Compass created these tools to help developers easily identify cross site scripting (XSS) and SQL injection vulnerabilities. XSS-Me is a Firefox add-on that loads in the sidebar. It identifies all the input fields on a page and [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=1998&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span style="text-align:center; display: block;"><a href="http://hackaday.com/2008/06/14/exploit-me-firefox-xss-and-sql-scanning-addon/"><img src="http://img.youtube.com/vi/RbL2ptbjoSA/2.jpg" alt="" /></a></span><br />One of the best tools we saw at <a href="http://layerone.info/">LayerOne</a> was the <a href="http://www.securitycompass.com/exploitme.shtml">Exploit-Me series</a> presented by [Dan Sinclair]. Security Compass created these tools to help developers easily identify cross site scripting (XSS) and SQL injection vulnerabilities.</p>
<p><span id="more-1998"></span></p>
<p>XSS-Me is a Firefox add-on that loads in the sidebar. It identifies all the input fields on a page and iterates through a user provided <a href="http://ha.ckers.org/xss.html">list of XSS strings</a>: opening new tabs and checking the results. When this process completes you get a report of what attacks got through, what didn&#8217;t, and what might have. The upcoming 0.3 version will use heuristics to determine what characters can be used and automatically skip attack strings that won&#8217;t get through.</p>
<p>The SQL Inject-Me works almost exactly the same way. It does require a little planning though: you need to tell it what you expect the results page to look like when an attack gets through.</p>
<p>The newest tool, Access-Me, surfs along with you while you&#8217;re authenticated to a website and checks whether you can see the same page unauthenticated.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackadaycom.wordpress.com/1998/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackadaycom.wordpress.com/1998/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/1998/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/1998/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/1998/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/1998/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/1998/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/1998/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/1998/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/1998/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/1998/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/1998/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/1998/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/1998/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/1998/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/1998/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=1998&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/06/14/exploit-me-firefox-xss-and-sql-scanning-addon/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>
	</item>
	</channel>
</rss>
