Amazon XPeria

Search Flipkart

2010-05-28

Summer Intern'10....PART 2

So after my last post.....so many interesting things has been happened with us...one of them was the formation of our teams for the project, and a lot of drama was there for that. Before that I just remember one thing which I would have mentioned earlier  is the new names for some of my friends like AMISA for sankhla, RAGTI for raghu, ANDA for datta, KUKU for dilip.....and last but not the least raj.luniya for ANSHUL.

Hmm...so I was talking about formation of teams, actually the way of explanation of our project by RAGTI made some 6 week interns interest towards CLICKER ( OUR PROJECT ), actually we need only 11 people for h/w part and there were 13, so after a meeting with PATHAK sir, there were two people who were not allocated their task bcoz only one of them can come. So what we did, we tossed a coin n ROY(1 of the BALI KA BAKRA) called HEAD and it was HEAD , so he won the toss and finally he was there in the hardware team, and ANDA became the BALI KA BAKRA dramatically.

Also the thing which made us happy and sad both was that we have to complete our assigned tasks in 4 weeks, (this is the sad part...kyo k kam karne ki itni aadat nahi hai...MNIT valo ko..)..but if we will complete that within time duration then there will be a big surprise for us. So waiting for the 28th JUN......

Yeah...3 things made me happy in last 3 days.... First... the mausam was pleasant in last 2-3 days...that gives us a sign relief and also thank god that we are not in jaipur struggling with cooler in 48C temperature...Second....I have started writing my diary from last 2 days...and the Third....CANT SAY HERE ryt now....... I am uploading a video of our respected PROF. D.B.PATHAK SIR...he has a very good knowledge in technical field....


SEE THIS...
Zubaan Pe IT Dil Mein India - Dr. Deepak B. Phatak | Skoch Challenger Lifetime Achievement Award

2010-05-24

Summer Intern'10....PART 1

Well...as i have written in my last post that we reached Mumbai on 5th of May. Then from station we come to IITB by hiring an auto by paying a large amount.We were astounded by the security arrangement at the main gate of IITB, our luggage was checked thoroughly and they gave us a receipt of our laptop's registration.(That shows how tight the security arrangement was.) Then we came to HOSTEL-4 where we have to live for next 2 months. Within 30 mins. we got our rooms. Rooms are far-2 better then that of MNIT hostel rooms. The most important thing that made me happy was the JUICE CENTER near the hostel and the 24/7 hour water supply, which i missed a lot in MNIT.

One more thing that i would like to mention is the INTERNET facility. Here in every room, there are 2 LAN ACCESS POINTS, n the speed is very good (5MBPS with IDM) 24/7. Also they have made a DATABASE on LAN which is of around 32TB and it is my dream to implement the same in MNIT.

Now on 5th all of us have to do nothing except SANKHLA, who is struggling to get his recommendation letter. One of the best boys of MNIT i.e. MR. CHACHA is trying to get the letter for sankhla in MNIT. Finally he got it from placement department and sankhla got relief.

On next day i.e. 6th the PROF. came in the evening and gave us a brief introduction of the currently running projects. Most of us are interested for CLICKER which is a project to develop a device which u may have seen in KBC at the time of audience poll. One more thing i forget to mention is the FOOD. The quality of food and menu is extremely good. The management is also good. There are several special dishes like DOSA, IDLI, BHELPURI, one SWEET in evening plus one FRUIT also. The most special thing about the mess is that they are providing 2 times breakfast and lunch and dinner. Now coming to the rest of the part , we came to know that our timing for the lab are from 9:30 to 5:30, which threatened us bcoz in MNIT there is nothing xcpt to sleep after lunch, but here we know that we are going to miss that.

Now from the next day we went to lab and as we do in our other subjects labs, we opened up our gmail, facebook, and orkut account and started chatting with friends. the next 2 or 3 days were similar to the first day in lab. After that on 10th our mentors gave us a SMALL DATASHEET (244 Pages ONLY) :P to read and they told us to read the datasheet at least thrice coz it is quite difficult to understand.

So the next days are quite similar to the previous days, in those days we enjoyed a lot. We enjoyed so may things like the tea breaks between our lab session, THE TENSION OF GRADES GIVEN BY OUR TEACHERS(MNIT), cricket, football, movies and a lot of other things.

Ohh....I forget to mention about our new friends JOJU, RENJEET, ANSHUL and MRINMROY. All of them are our project partners and every one is a very good friend. Although ANSHUL thoda sir khata hai but its ok yar, koi to hona bhi chahiye na...:-) ...

Now on 19th, 6 WEEK interns came to IITB, and they brought a major task for us. The task was to give a presentation of our current project before them so that they can gey a brief overview of our project and can select one of them. As we had done almost nothing in last 14 days so it was a difficult task for us but 1 day time was more then enough for us to prepare ourselves. Finally Me, Raghu n Joju gave a presentation and it was good.

Hmm...so many things happened till now in IITB...and I am writing the end of this post just after coming from NARIMAN POINT, a very good place to enjoy for couples(However singles can also enjoy by seeing the couples and other girls..:-)) NARIMAN POINT is really a nice place on the edge of sea....sitting on mountains while the waves striking them gives a lot of relief  to your heart...SO THATS ALL....THIS IS THE END OF PART-1...will meet you soon...

2010-05-08

Journey to IITB

Hmm....so i am going to write my first post related to my life...and this is about the starting of my internship at IITB. I was very happy when i got a mail from Prof. D.B.Pathak saying that i have got selected for the summer internship'2010 and i have to send my travel plan. But i was not quite sure about the intern at IITB till 3rd of MAY due to some reason. Then i talked to ROOPESH BOSS and he suggested me to go to IITB for my summer intern. Finally i decided to do my intern at IITB.

So, our start of journey to IITB on May 4th, was quite dramatic as AMIT SANKHLA did not get his permission letter. But at last he decided to come to IITB without that letter. After all that drama we started our journey from Jaipur to Mumbai by GARIB RATH. We were 7 people including Arpan, Piyush, Raghu, Dilip, Ankur, Amit and me. We met one of our pass out seniors(oh..i forget the name...)...who was very much talkative. At ABU ROAD station we got tasty GHAR KA KHANA....given by AUNTY(ARPAN's MUMMA). Then we spent the whole night adjusting ourselves on the birth's of train(as we were 7 people on 5 birth's)...and finally we reached Mumbai around 8'o clock on 5th of May.

2009-10-21

SQL Injection

One of the major problems with SQL is its poor security issues surrounding is the login and url strings.

First SEARCH the following Keywords in Google or any Search Engine:

admin\login.asp
login.asp

with these two search string you will have plenty of targets to chose from…choose one that is Vulnerable

INJECTION STRINGS: How to use it?

This is the easiest part…very simple

On the login page just enter something like

user:admin (you dont even have to put this.)
pass:’ or 1=1–

or

user:’ or 1=1–
admin:’ or 1=1–

Some sites will have just a password so

password:’ or 1=1–

There are many other strings involving for instance UNION table access via reading the error pages table structure thus an attack with this method will reveal eventually admin U\P paths.

The one I am interested in are quick access to targets


combo example:

admin:’ or a=a–
admin:’ or 1=1–

And so on. You don’t have to be admin and still can do anything you want. The most important part is example:’ or 1=1– this is our basic injection string

Now the only trudge part is finding targets to exploit. So I tend to search say google for login.asp or whatever

inurl:login.asp
index of:/admin/login.asp

like this: index of login.asp

result:

http://www3.google.com/search?hl=en&ie=ISO…G=Google+Search

17,000 possible targets trying various searches spews out plent more

After an hour or so you have a list of sites of potential targets like so

http://www.somesite.com/login.asp
http://www.another.com/admin/login.asp

and so on. In a couple of hours you can build up quite a list because I don’t select all results or spider for log in pages.

Sit back and wait. Any target vulnerable will show up in the hits box. Now when it finds a target it will spew all the strings on that site as vulnerable. You have to go through each one on the site by cutting and pasting the string till you find the right one. But the thing is you know you CAN access the site. Really I need a program that will return the hit with a click on url and ignore false outputs. I am still looking for it. This will saves quite a bit of time going to each site and each string to find its not exploitable.

There you go you should have access to your vulnerable target by now

Another thing you can use the strings in the urls were user=? edit the url to the = part and paste ‘ or 1=1– so it becomes

user=’ or 1=1– just as quick as login process

Combo List

There are lot of other variations of the Injection String which I cannot put on my blog because that is Illegal. If you are interested I can send it to you through Email. Just write in your email address in comment and I will send it to you as early as possible but you need to remain patient it may take 1 or 2 days.

Happy Hunting



2009-10-20

How to Block Any Website

How to Block Any Website

Hi friends.....this trick will be very helpful for you in case if you want to block a particular website on your PC.....Let's see how............

Steps:

  • Open Run Menu & Paste %Windir%\System32\Drivers\Etc
  • Find The File Named "Hosts"
  • Open It In Notepad
  • Under "127.0.0.1 Localhost" Add 127.0.0.2 www.Google.com , And That Site Will No Longer Be Accessable.
  • Done!


-For Example-

127.0.0.1 Localhost
127.0.0.2 www.Google.com



-For More Than One Site To Block-

127.0.0.1 Localhost
127.0.0.2 www.Google.com
127.0.0.3 www.Google.co.in
127.0.0.4 Google.com
127.0.0.5 www.Yahoo.com
127.0.0.6 Yahoo.com
127.0.0.7 www.Orkut.com
127.0.0.8 Orkut.com
127.0.0.9 www.Youtube.com

Welcome!!

What is especially uncanny about this blog is that everything that I think is important is blogged about here, in language that seems to precisely reflect my own thinking. It’s like I am reading my own mind every time I compose a post. If you are me, I’m sure you will feel the same way. In the unlikely event that you are not me, there is still a chance that you will enjoy my blog. Who knows? (And Who isn’t telling, so you’d better check it out yourself.)”