<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="FeedCreator 1.7.3" -->
<rss version="2.0">
	<channel>
		<title>SQL Injection Vol.2</title>
		<description>Discuss SQL Injection Vol.2</description>
		<link>http://www.neoteker.or.id/info-security/58-sql-injection-vol2.html</link>
		<lastBuildDate>Fri, 10 Sep 2010 12:23:39 +0100</lastBuildDate>
        <generator>FeedCreator 1.7.3</generator>
		<item>
			<title>hkn89 says:</title>
			<link>http://www.neoteker.or.id/info-security/58-sql-injection-vol2.html#comment-83</link>
			<description>Users where UserName =='&quot;+login+&quot; ' and Password='&quot;+ pass&quot;'&quot;; nah kalau begitu kita masukin syntax sql union untuk melihat username : ' union select min(UserName) ,1,1,1 from Users where username &gt; 'a'-- jadi hasilnya : select * from Users where UserName ==' union select min(UserName) ,1,1,1 from Users where username &gt; 'a'--and Password='&quot;+ pass&quot;'&quot;; gitu kiranya, jadi nanti akan muncul error messages lagi yang akan menampilkan sebuah username lebih dari huruf a ,contoh: disini ane blom paham tu maksudnya kita login dengan username = +login+ pasword = + pass mohon pencerahannya gan</description>
			<author>hkn89</author>
			<pubDate>Tue, 19 Jan 2010 07:57:13 +0100</pubDate>
		</item>
	</channel>
</rss>
