<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Gardianul.ro, full access din cauza unui SQL Injection</title>
	<atom:link href="http://blog.rstcenter.com/2008/10/30/gardianulro-full-access-din-cauza-unui-sql-injection/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.rstcenter.com/2008/10/30/gardianulro-full-access-din-cauza-unui-sql-injection/</link>
	<description></description>
	<lastBuildDate>Sat, 17 Sep 2011 10:00:04 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: bb</title>
		<link>http://blog.rstcenter.com/2008/10/30/gardianulro-full-access-din-cauza-unui-sql-injection/comment-page-1/#comment-3099</link>
		<dc:creator>bb</dc:creator>
		<pubDate>Fri, 24 Jul 2009 00:53:36 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=113#comment-3099</guid>
		<description>cacatul ala de site foloseste rainbow tables :).
md5 nu poate fi decryptat.</description>
		<content:encoded><![CDATA[<p>cacatul ala de site foloseste rainbow tables <img src='http://blog.rstcenter.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> .<br />
md5 nu poate fi decryptat.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: catalin</title>
		<link>http://blog.rstcenter.com/2008/10/30/gardianulro-full-access-din-cauza-unui-sql-injection/comment-page-1/#comment-1925</link>
		<dc:creator>catalin</dc:creator>
		<pubDate>Mon, 27 Apr 2009 06:10:25 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=113#comment-1925</guid>
		<description>Atata timp cat unele parole md5 pot fi decriptate prin brute force attack, aia nu e o solutie !! Vezi site-ul urmator: http://tools.benramsey.com/md5/ 

Cea mai puternica metoda de criptare ramane implementarea unui algoritm de criptare cu cheie publica; recomandat 3DES pt ca foloseste o cheie de criptare pe 24 de biti care o imparte in 3 chei de 8 biti. Mai recomand: DES, AES, Blowfish ca si algoritmi de criptare.</description>
		<content:encoded><![CDATA[<p>Atata timp cat unele parole md5 pot fi decriptate prin brute force attack, aia nu e o solutie !! Vezi site-ul urmator: <a href="http://tools.benramsey.com/md5/" rel="nofollow">http://tools.benramsey.com/md5/</a> </p>
<p>Cea mai puternica metoda de criptare ramane implementarea unui algoritm de criptare cu cheie publica; recomandat 3DES pt ca foloseste o cheie de criptare pe 24 de biti care o imparte in 3 chei de 8 biti. Mai recomand: DES, AES, Blowfish ca si algoritmi de criptare.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: crs12decoder</title>
		<link>http://blog.rstcenter.com/2008/10/30/gardianulro-full-access-din-cauza-unui-sql-injection/comment-page-1/#comment-26</link>
		<dc:creator>crs12decoder</dc:creator>
		<pubDate>Sun, 02 Nov 2008 20:25:16 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=113#comment-26</guid>
		<description>lol... din cate am observat din ultima poza facuta in phpmyadmin imi dau seama dupa length ca parolele nici macar nu&#039;s criptate in md5... wtf.... gardianul.ro nu are nici macar criptare in md5?... site-u asta a fost facut de copii de 10 ani?</description>
		<content:encoded><![CDATA[<p>lol&#8230; din cate am observat din ultima poza facuta in phpmyadmin imi dau seama dupa length ca parolele nici macar nu&#8217;s criptate in md5&#8230; wtf&#8230;. gardianul.ro nu are nici macar criptare in md5?&#8230; site-u asta a fost facut de copii de 10 ani?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bogdan S</title>
		<link>http://blog.rstcenter.com/2008/10/30/gardianulro-full-access-din-cauza-unui-sql-injection/comment-page-1/#comment-23</link>
		<dc:creator>Bogdan S</dc:creator>
		<pubDate>Fri, 31 Oct 2008 19:54:56 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=113#comment-23</guid>
		<description>sunteti o foarte buna unealta de testing :)) tot respectu&#039;</description>
		<content:encoded><![CDATA[<p>sunteti o foarte buna unealta de testing <img src='http://blog.rstcenter.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> ) tot respectu&#8217;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tinu Coman</title>
		<link>http://blog.rstcenter.com/2008/10/30/gardianulro-full-access-din-cauza-unui-sql-injection/comment-page-1/#comment-21</link>
		<dc:creator>Tinu Coman</dc:creator>
		<pubDate>Fri, 31 Oct 2008 16:11:15 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=113#comment-21</guid>
		<description>@darkyndy &amp; @Tocsixu Aveti dreptate. Nu ar fi trebuit sa ma bazez pe acele setari mai ales cum incepand cu php6 e deprecated, dar s-a intamplat ca pe serverul initial sa fie on si nu am mai adaugat mysql_real_escape_string(stripslashes(&#039;valori&#039;)) pentru a nu face acelasi proces de mai multe ori. Multumesc pentru mailul de warning cu cateva zile inainte de postarea informatiei pt a avea timp sa rezolvam.

@crow.ro - nu a fost o zi atat de nefericita. Intr-o juma de ora a fost rezolvata problema :)</description>
		<content:encoded><![CDATA[<p>@darkyndy &amp; @Tocsixu Aveti dreptate. Nu ar fi trebuit sa ma bazez pe acele setari mai ales cum incepand cu php6 e deprecated, dar s-a intamplat ca pe serverul initial sa fie on si nu am mai adaugat mysql_real_escape_string(stripslashes(&#8216;valori&#8217;)) pentru a nu face acelasi proces de mai multe ori. Multumesc pentru mailul de warning cu cateva zile inainte de postarea informatiei pt a avea timp sa rezolvam.</p>
<p>@crow.ro &#8211; nu a fost o zi atat de nefericita. Intr-o juma de ora a fost rezolvata problema <img src='http://blog.rstcenter.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shocker</title>
		<link>http://blog.rstcenter.com/2008/10/30/gardianulro-full-access-din-cauza-unui-sql-injection/comment-page-1/#comment-20</link>
		<dc:creator>Shocker</dc:creator>
		<pubDate>Fri, 31 Oct 2008 15:26:07 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=113#comment-20</guid>
		<description>Vlad, realizarea e de vina. Nu te poti baza pe faptul ca o sa iti faca modulele de apache toata treaba cu securitatea.</description>
		<content:encoded><![CDATA[<p>Vlad, realizarea e de vina. Nu te poti baza pe faptul ca o sa iti faca modulele de apache toata treaba cu securitatea.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: darkyndy</title>
		<link>http://blog.rstcenter.com/2008/10/30/gardianulro-full-access-din-cauza-unui-sql-injection/comment-page-1/#comment-19</link>
		<dc:creator>darkyndy</dc:creator>
		<pubDate>Fri, 31 Oct 2008 15:01:24 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=113#comment-19</guid>
		<description>@Vlad si tu ca firma lasi acest risc la o setare de apache, sau te asiguri ca orice setare vei avea nu vei avea astfel de probleme?! (intrebare retorica)</description>
		<content:encoded><![CDATA[<p>@Vlad si tu ca firma lasi acest risc la o setare de apache, sau te asiguri ca orice setare vei avea nu vei avea astfel de probleme?! (intrebare retorica)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vlad</title>
		<link>http://blog.rstcenter.com/2008/10/30/gardianulro-full-access-din-cauza-unui-sql-injection/comment-page-1/#comment-18</link>
		<dc:creator>Vlad</dc:creator>
		<pubDate>Fri, 31 Oct 2008 14:36:56 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=113#comment-18</guid>
		<description>Nu realizarea a fost de vina ci simplul motiv ca la schimbarea site-ului pe un nou server, nu a fost activat in php.ini &quot;magic quotes&quot;, asta ducand la vulnerabilitatile descoperite de voi.</description>
		<content:encoded><![CDATA[<p>Nu realizarea a fost de vina ci simplul motiv ca la schimbarea site-ului pe un nou server, nu a fost activat in php.ini &#8220;magic quotes&#8221;, asta ducand la vulnerabilitatile descoperite de voi.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Update la zi</title>
		<link>http://blog.rstcenter.com/2008/10/30/gardianulro-full-access-din-cauza-unui-sql-injection/comment-page-1/#comment-16</link>
		<dc:creator>Update la zi</dc:creator>
		<pubDate>Fri, 31 Oct 2008 08:46:58 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=113#comment-16</guid>
		<description>[...] Arhi ne povesteşte despre: Perverşii din autobuze. Gardianul.ro, full access din cauza unui SQL Injection [...]</description>
		<content:encoded><![CDATA[<p>[...] Arhi ne povesteşte despre: Perverşii din autobuze. Gardianul.ro, full access din cauza unui SQL Injection [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dAImon</title>
		<link>http://blog.rstcenter.com/2008/10/30/gardianulro-full-access-din-cauza-unui-sql-injection/comment-page-1/#comment-14</link>
		<dc:creator>dAImon</dc:creator>
		<pubDate>Fri, 31 Oct 2008 07:33:25 +0000</pubDate>
		<guid isPermaLink="false">http://hackersblog.org/?p=113#comment-14</guid>
		<description>sec.
asta se intampla cand bagi banii dar nu faci si un audit de securitate dupa.</description>
		<content:encoded><![CDATA[<p>sec.<br />
asta se intampla cand bagi banii dar nu faci si un audit de securitate dupa.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

