29.09.2015 Views

Legal Disclaimer

Hacking-For-Beginners-a-beginners-guide-for-learning-ethical-hacking

Hacking-For-Beginners-a-beginners-guide-for-learning-ethical-hacking

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Hacking For Beginners – Manthan Desai 2010<br />

Now this will step up one directory (to directory E ) and look for 'etc' but again it will return nothing Now type<br />

http://www.chitkara.edu.in/chitkara/chitkarauniversity.php?page=../../etc/passwd<br />

Now this will step up two directories (to directory D) and look for 'etc' but again it will return nothing.<br />

So by proceeding like this, we go for this URL<br />

http://www.chitkara.edu.in/chitkara/chitkarauniversity.php?page=../../../../../etc/passwd<br />

It takes us 5 directories up to the main drive and then to 'etc' directory and show us contents of 'passwd' file.<br />

To understand the contents of 'passwd' file, visit<br />

http://www.cyberciti.biz/faq/understanding-etcpasswd-file-format/<br />

You can also view etc/profile; etc/services and many others files like backup files which may contain sensitive data. Some<br />

files like etc/shadow may not be accessible because they are accessible only by privileged users.<br />

If proc/self/environ would be accessible; you might upload a shell on server which is called as Local File Inclusion.<br />

Database Servers<br />

• The Database server is a key component in a client/server environment. Specially the Websites which have a User Login<br />

Architecture.<br />

• Database Server holds the Database Management System (DBMS) and the Data Records. Upon requests from the client<br />

machines, it searches the database for selected records and passes them back over the network.<br />

• Software to setup a Database Server:<br />

– Oracle<br />

– SQL Server<br />

– MySql<br />

w w w . h a c k i n g t e c h . c o . t v Page 57

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!