4 ms·
That is really a good way to make them drop all the target. but rather if I were to do it I will do it with set of different signature snuffling randomly to ma
by jitendrac 6y ago
That is really a good way to make them drop all the target.
but rather if I were to do it I will do it with set of different signature snuffling randomly to make them un-filterable and limit the rate of submission such that they dont immediately notice me and I can make their database full of dummy data which makes it useless for them. Many times you can also get to execute arbitrary sql-injection and can delete the database.
In fact, in past when in collage I was trying to learn some hacking basics to find vulnerable servers. And as on the googled article like most scripting kiddies, I searched and found a vulnerable site which was already hacked and had installed shell.php on it.
What that vulnerability did was, it found a way to inject the browser navigator name into php script using /proc/self/environ. after studying attack what I did was, remove the shell and patched the vulnerable file with some obfuscation. I was so naive(what would have happened if my IP was tracked and I became suspected criminal),now seeing past luckily I never got my self involved in legal things.