last data update: 2011/10/21, 13:35

Website loading time

during the test: 0.93 s

cable connection (average): 1.2 s

DSL connection (average): 1.47 s

modem (average): 15.67 s

HTTP headers

Information about DNS servers

websec.wordpress.comCNAMElb.wordpress.comIN14400

Received from the first DNS server

Received from the second DNS server

Subdomains (the first 50)

Typos (misspells)

qebsec.wordpress.com
aebsec.wordpress.com
sebsec.wordpress.com
eebsec.wordpress.com
3ebsec.wordpress.com
2ebsec.wordpress.com
wwbsec.wordpress.com
wsbsec.wordpress.com
wdbsec.wordpress.com
wrbsec.wordpress.com
w4bsec.wordpress.com
w3bsec.wordpress.com
wevsec.wordpress.com
wensec.wordpress.com
wehsec.wordpress.com
wegsec.wordpress.com
webaec.wordpress.com
webzec.wordpress.com
webxec.wordpress.com
webdec.wordpress.com
webeec.wordpress.com
webwec.wordpress.com
webswc.wordpress.com
webssc.wordpress.com
websdc.wordpress.com
websrc.wordpress.com
webs4c.wordpress.com
webs3c.wordpress.com
websex.wordpress.com
websev.wordpress.com
websef.wordpress.com
websed.wordpress.com
ebsec.wordpress.com
wbsec.wordpress.com
wesec.wordpress.com
webec.wordpress.com
websc.wordpress.com
webse.wordpress.com
ewbsec.wordpress.com
wbesec.wordpress.com
wesbec.wordpress.com
webesc.wordpress.com
websce.wordpress.com
wwebsec.wordpress.com
weebsec.wordpress.com
webbsec.wordpress.com
webssec.wordpress.com
webseec.wordpress.com
websecc.wordpress.com

Location

IP: 74.200.243.251, 74.200.244.59, 76.74.254.120, 76.74.254.123, 72.233.2.58, 72.233.69.6

continent: NA, country: United States (USA), city: Plano

Website value

rank in the traffic statistics:

There is not enough data to estimate website value.

Basic information

website build using CSS

code weight: 103.15 KB

text per all code ratio: 54 %

title: Reiners’ Weblog

description:

keywords:

encoding: UTF-8

language: en

Website code analysis

one word phrases repeated minimum three times

two word phrases repeated minimum three times

three word phrases repeated minimum three times

B tags

automatically detected

language file

a

1

s

9

15

398720351149

Update:

U tags

I tags

If you don’t know what blind

extractvalue

Accept-Language

Accept-Language: es

language file

Accept-Language: foobar

Accept-Language: index.php

Accept-Language: ../index.php

?id=17

worker/funcs.php

messages/

a:1

{

s:9:”secretkey”

s:15:”p1r4t3s.k1lly0u”

}

worker/mysql.php

sql_db

__wakeup()

__destruct()

sql_close()

logs

sql_db()

createLog()

log_table

users

printGold()

images

file namealternative text
;)
:)
RIPS file graph
RIPS function graph
RIPS stats

headers

H1

Reiners’ Weblog

H2

hack.lu CTF 2011 challenge writeup – Secret Space Code

hack.lu CTF 2011 challenge writeup – AALabs (Part 1)

Project RIPS – Status

Blind SQLi techniques

SQLi filter evasion cheat sheet (MySQL)

Basic filter

Function filter

Keyword filter

hack.lu CTF challenge 21 writeup – PIGS

Blind SQL injection with load_file()

RIPS – A static source code analyser for vulnerabilities in PHP scripts

Exploiting hard filtered SQL Injections 3

Exploiting hard filtered SQL Injections 2 (conditional errors)

Archives

Categories

active

blogs

Meta

H3

hack.lu CTF 2011 challenge writeup – Secret Space Code

hack.lu CTF 2011 challenge writeup – AALabs (Part 1)

Project RIPS – Status

Blind SQLi techniques

SQLi filter evasion cheat sheet (MySQL)

Basic filter

Function filter

Keyword filter

hack.lu CTF challenge 21 writeup – PIGS

Blind SQL injection with load_file()

RIPS – A static source code analyser for vulnerabilities in PHP scripts

Exploiting hard filtered SQL Injections 3

Exploiting hard filtered SQL Injections 2 (conditional errors)

Archives

Categories

active

blogs

Meta

H4

H5

H6

internal links

addressanchor text
Reiners’ Weblog
Home
Talks
Papers
Tools
About
hack.lu CTF 2011 challenge writeup – Secret Space
1 Comment
CTF
Web Security
XSS
Permalink
hack.lu CTF 2011 challenge writeup – AALabs (Part
last years
Leave a Comment
CTF
PHP
Web Security
Permalink
Project RIPS –
RIPS
12 Comments
PHP
Projects
Web Security
PHP Analyser
PHP Scanner
RIPS
static analysis
Permalink
Blind SQLi
here
11 Comments
SQLi
Web Security
Permalink
SQLi filter evasion cheat sheet
29 Comments
SQLi
Web Security
SQL filter bypass
SQL filter evasion
SQL obfuscation
Permalink
hack.lu CTF challenge 21 writeup –
1 Comment
CTF
PHP
SQLi
Web Security
Permalink
Blind SQL injection with
5 Comments
SQLi
Web Security
Permalink
RIPS – A static source code analyser for vulnerabilities in PHP
PHP Scanner
23 Comments
PHP
Projects
Web Security
PHP Analyser
PHP Scanner
RIPS
Permalink
Exploiting hard filtered SQL Injections
Exploiting hard filtered SQL Injections
here
whitespace
first part
Part 1
Part2
SQLi filter evasion cheatsheet
15 Comments
SQLi
Web Security
SQL filter bypass
SQL filter evasion
SQL obfuscation
Permalink
Exploiting hard filtered SQL Injections 2 (conditional
Exploiting hard filtered SQL Injections
exploiting hard filtered SQL Injections
comparison of three operands
Part 1
Part 3
SQLi filter evasion cheatsheet
6 Comments
SQLi
Web Security
SQL filter bypass
SQL filter evasion
SQL obfuscation
Permalink
September 2011
June 2011
April 2011
December 2010
October 2010
June 2010
May 2010
March 2010
February 2010
November 2009
January 2009
December 2008
October 2008
September 2008
May 2008
November 2007
CTF
Other
PHP
Projects
SQLi
Web Security
XSS
Register
Log in
Follow

external links

addressanchor text
hack.lu 2011 conference CTF
we
organized
patched
scarybeast
blogpost
this paper
.mario
last year
FluxFingers
hack.lu conference CTF
participants
here
RIPS file graph
RIPS function graph
RIPS stats
here
changelog
sourceforge
this article
extracting data with bit shifting
extracting data with find_in_set
extracting data with find_in_set and regexp
extracting data through mysql errors
extracting data through mysql errors
here
PHPIDS
here
we
hack.lu
http://hacklu.fluxfingers.net/
Live HTTP Headers
__wakeup()
__destruct()
piwik exploit
here
official list
Month Of PHP Security
SourceForge
HTML
PDF
[download RIPS]
Campus Party
SecurityByDefault
SecurityByDefault
REGEXP
FluxFingers
sla.ckers
twitter
Bernardo Damele
christ1an
d0mber
Das Labor
Gareth Heyes
Gnarf
gnucitizen
hackademix
hackathology
Kishor
kuza55
pentestmonkey
PHPIDS
RSnake
sirdarckcat
thornmaker
Contempt
Vault9
Blog at WordPress.com
Powered by WordPress.com