<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Sql Injection in CCBill.com</title>
	<atom:link href="http://blog.rstcenter.com/2009/03/13/sql-injection-in-ccbillcom/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.rstcenter.com/2009/03/13/sql-injection-in-ccbillcom/</link>
	<description></description>
	<lastBuildDate>Sat, 17 Sep 2011 10:00:04 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: [P]hoenix</title>
		<link>http://blog.rstcenter.com/2009/03/13/sql-injection-in-ccbillcom/comment-page-1/#comment-1923</link>
		<dc:creator>[P]hoenix</dc:creator>
		<pubDate>Mon, 27 Apr 2009 02:44:43 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rstcenter.com/?p=1559#comment-1923</guid>
		<description>Impressive hack!</description>
		<content:encoded><![CDATA[<p>Impressive hack!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: maximilian</title>
		<link>http://blog.rstcenter.com/2009/03/13/sql-injection-in-ccbillcom/comment-page-1/#comment-1887</link>
		<dc:creator>maximilian</dc:creator>
		<pubDate>Wed, 01 Apr 2009 23:27:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rstcenter.com/?p=1559#comment-1887</guid>
		<description>ma stii care e chestia ca am vazut si eu blogul si stiu ca ar suna tampit sa intreb daca ar vrea cineva sa ma initieze si pe mine pe mysql dar daca a-ti putea sa ma ajutati va astept ajutorul diabolik_lover mess si tot aia mail pe yahoo</description>
		<content:encoded><![CDATA[<p>ma stii care e chestia ca am vazut si eu blogul si stiu ca ar suna tampit sa intreb daca ar vrea cineva sa ma initieze si pe mine pe mysql dar daca a-ti putea sa ma ajutati va astept ajutorul diabolik_lover mess si tot aia mail pe yahoo</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: XuanHung_Cntt</title>
		<link>http://blog.rstcenter.com/2009/03/13/sql-injection-in-ccbillcom/comment-page-1/#comment-1625</link>
		<dc:creator>XuanHung_Cntt</dc:creator>
		<pubDate>Sun, 22 Mar 2009 13:41:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rstcenter.com/?p=1559#comment-1625</guid>
		<description>I Want to become a hacker! who can help me?</description>
		<content:encoded><![CDATA[<p>I Want to become a hacker! who can help me?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anonuser</title>
		<link>http://blog.rstcenter.com/2009/03/13/sql-injection-in-ccbillcom/comment-page-1/#comment-1580</link>
		<dc:creator>anonuser</dc:creator>
		<pubDate>Sun, 15 Mar 2009 12:53:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rstcenter.com/?p=1559#comment-1580</guid>
		<description>chestia e ca am incercat si eu sa introduc o comanda in linkul de la ccbill consumer base dar nu am avut nici un rezultat</description>
		<content:encoded><![CDATA[<p>chestia e ca am incercat si eu sa introduc o comanda in linkul de la ccbill consumer base dar nu am avut nici un rezultat</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anonuser</title>
		<link>http://blog.rstcenter.com/2009/03/13/sql-injection-in-ccbillcom/comment-page-1/#comment-1579</link>
		<dc:creator>anonuser</dc:creator>
		<pubDate>Sun, 15 Mar 2009 12:52:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rstcenter.com/?p=1559#comment-1579</guid>
		<description>multumesc pt raspunsuri, eu credeam ca e de ajuns sa rescrii linkurile cu mod_rewrite ca sa tii sql injecturile departe de site-ul tau</description>
		<content:encoded><![CDATA[<p>multumesc pt raspunsuri, eu credeam ca e de ajuns sa rescrii linkurile cu mod_rewrite ca sa tii sql injecturile departe de site-ul tau</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: whatever</title>
		<link>http://blog.rstcenter.com/2009/03/13/sql-injection-in-ccbillcom/comment-page-1/#comment-1559</link>
		<dc:creator>whatever</dc:creator>
		<pubDate>Fri, 13 Mar 2009 22:36:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rstcenter.com/?p=1559#comment-1559</guid>
		<description>Felicitari baieti! ccbill e treaba serioasa, cred ca au milioane de carti de credit in bazele lor de date. Nu ma gandeam ca un site asa important are probleme de genul asta. Eh, omul cat traieste invata.</description>
		<content:encoded><![CDATA[<p>Felicitari baieti! ccbill e treaba serioasa, cred ca au milioane de carti de credit in bazele lor de date. Nu ma gandeam ca un site asa important are probleme de genul asta. Eh, omul cat traieste invata.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tipul07</title>
		<link>http://blog.rstcenter.com/2009/03/13/sql-injection-in-ccbillcom/comment-page-1/#comment-1538</link>
		<dc:creator>Tipul07</dc:creator>
		<pubDate>Fri, 13 Mar 2009 16:16:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rstcenter.com/?p=1559#comment-1538</guid>
		<description>sau bagi (.*) pentru cimpurile care nu le folosesti... (Doar pentru SEO)</description>
		<content:encoded><![CDATA[<p>sau bagi (.*) pentru cimpurile care nu le folosesti&#8230; (Doar pentru SEO)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: wish</title>
		<link>http://blog.rstcenter.com/2009/03/13/sql-injection-in-ccbillcom/comment-page-1/#comment-1537</link>
		<dc:creator>wish</dc:creator>
		<pubDate>Fri, 13 Mar 2009 15:23:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rstcenter.com/?p=1559#comment-1537</guid>
		<description>Exact..
@anonuser: pe de alta parte,nu este intotdeauna obligatoriu ca in url sa existe un parametru de tip numeric.
O adresa vulnerabila poate foarte bine sa arate in felul urmator:

www.site.com/paginadeprezentare.html

Unii coderi obisnuiesc sa foloseasca un camp aditional cu adresa seo a unei pagini dinamice, pe care sa il bage mod_rewrite. O idee buna de altfel, dar nu atunci cand rewrite-ul este facut cu (.*).
Daca magic_quotes_gpc e Off, that&#039;s it...</description>
		<content:encoded><![CDATA[<p>Exact..<br />
@anonuser: pe de alta parte,nu este intotdeauna obligatoriu ca in url sa existe un parametru de tip numeric.<br />
O adresa vulnerabila poate foarte bine sa arate in felul urmator:</p>
<p><a href="http://www.site.com/paginadeprezentare.html" rel="nofollow">http://www.site.com/paginadeprezentare.html</a></p>
<p>Unii coderi obisnuiesc sa foloseasca un camp aditional cu adresa seo a unei pagini dinamice, pe care sa il bage mod_rewrite. O idee buna de altfel, dar nu atunci cand rewrite-ul este facut cu (.*).<br />
Daca magic_quotes_gpc e Off, that&#8217;s it&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tipul07</title>
		<link>http://blog.rstcenter.com/2009/03/13/sql-injection-in-ccbillcom/comment-page-1/#comment-1535</link>
		<dc:creator>Tipul07</dc:creator>
		<pubDate>Fri, 13 Mar 2009 15:05:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rstcenter.com/?p=1559#comment-1535</guid>
		<description>Bravo domnu! Felicitari! Asa le trebe daca nu fac in-house.</description>
		<content:encoded><![CDATA[<p>Bravo domnu! Felicitari! Asa le trebe daca nu fac in-house.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shocker</title>
		<link>http://blog.rstcenter.com/2009/03/13/sql-injection-in-ccbillcom/comment-page-1/#comment-1534</link>
		<dc:creator>Shocker</dc:creator>
		<pubDate>Fri, 13 Mar 2009 14:57:36 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rstcenter.com/?p=1559#comment-1534</guid>
		<description>Tocmai asta e una din scaparile multor coderi, uita de filtrare cand folosesc mod_rewrite</description>
		<content:encoded><![CDATA[<p>Tocmai asta e una din scaparile multor coderi, uita de filtrare cand folosesc mod_rewrite</p>
]]></content:encoded>
	</item>
</channel>
</rss>

