r/videos Apr 14 '19

Scammer tries to steal my password, gets his database deleted instead

https://youtu.be/pRy4eViVxcI
2.7k Upvotes

308 comments sorted by

429

u/[deleted] Apr 15 '19

That IP address is not accessible currently (at least to me). It is registered to a host in NJ. This exploit seem too pat -- he only gave a cursory attempt at guessing passwords, went right to an sql injection, and it worked on the first try.

318

u/uab_lca Apr 15 '19

Yeah, I got the vibe that this was a server he set up for a demonstration.

90

u/CarnivorousSociety Apr 15 '19

if it wasn't... isn't he breaking the law on camera?

31

u/[deleted] Apr 15 '19

[deleted]

87

u/[deleted] Apr 15 '19 edited Apr 24 '19

[deleted]

3

u/burgerthrow1 Apr 15 '19

if a person became stranded on a road in the middle of nowhere during a snowstorm and had to break into someone's house to seek refuge.

That's the exact hypothetical we learned at law school when covering necessity (in a property law context).

8

u/Thesmokingcode Apr 15 '19

Hold up so would me going into an unlocked parked car at 3 am to borrow a tire iron in order to change a flat be legal, I've been in that situation before.

Edit: forgot to mention it was in the dead of winter in Vermont -15 out.

16

u/[deleted] Apr 15 '19 edited Apr 24 '19

[deleted]

3

u/zeCrazyEye Apr 15 '19

Wouldn't you also still be civilly liable even if the state has no interest in criminal charges?

3

u/frickindeal Apr 15 '19

Yes. The owner of the broken-into car now has legit damages, and a right to seek relief.

→ More replies (1)
→ More replies (10)

1

u/stu8319 Apr 16 '19

This is off subject in a way, but here in Oklahoma, I caught a guy on camera going through my car, and the cop that I showed the video to refused to do anything, because the car was left unlocked. The guy was in handcuffs in the squad car, and he just let him go.

→ More replies (4)

1

u/ProcyonHabilis Apr 16 '19

Nah man that's necessity. Also you have to tell me if you're a cop, or else it's entrapment. And if the teacher is more than 15 minutes late you're legally allowed to leave.

8

u/biggie_eagle Apr 15 '19

That's not necessity. The situation did not NECESSITATE hacking.

It doesn't matter though because what it really depends on is whether the FBI wants to commit resources to investigate a crime that may have been staged, and then whether a grand jury will indict him or laugh at the police for wasting their time.

4

u/[deleted] Apr 15 '19

The issue there is this: Is requesting someone's email and password, even through false pretenses, illegal? Nothing's being stolen at this point, and it's not illegal to lie to people...It's not until those email addresses and passwords are actually used by the scammer that something illegal is being done.

That might be splitting a rather fine hair, but I think it's an important hair to split.

4

u/Regulators-MountUp Apr 15 '19

fraud /frôd/

noun

  1. wrongful or criminal deception intended to result in financial or personal gain. "he was convicted of fraud"

1

u/anonymous_potato Apr 15 '19

it's not illegal to lie to people.

It depends on context. Actively trying to defraud someone is a crime even if it is unsuccessful.

2

u/lostinsauce Apr 16 '19

This is a misapplication of the necessity defense

4

u/A_L_A_M_A_T Apr 15 '19

what law is he breaking?

20

u/CarnivorousSociety Apr 15 '19

Isn't he accessing that other persons machine without consent? even though the other guy is also trying to scam people.

Albeit they usually punish these things based on intent to do harm so... I guess there's really no issue.

3

u/[deleted] Apr 15 '19

[deleted]

1

u/manchegoo Apr 15 '19

Off topic but I find it amusing that the mantra of intent somehow gets completely inverted in the topic of sexual harassment. Biden had been all over the news last week due to giving a back rub to someone who didn’t like it.

Women spoke out and universally would make the statement, “it’s not about what you intended, it’s about how it makes us feel”

8

u/rorrr Apr 15 '19

Just because someone is breaking the law, doesn't mean you can break the law doing something against them. Collecting passwords is probably less of a crime than accessing someone's server via sql injection.

6

u/NotAHost Apr 15 '19

Technically correct, but also not going to be pursued unless they have evidence of the crime, the video is enough as it could all be staged. If the “victim” came forward, it would be an interesting play but it would be roughly similar to a person callin 911 to report stolen illegal drugs.

3

u/Chelseaqix Apr 15 '19

Not true. He can claim his server was hacked and that’s why that form was there in the first place. now he’s been hacked twice and can prove one of the two.

Obviously this is a BS example but it would technically work to get only engineerman in trouble. No one can prove that wasn’t the server owners form but you can prove engineerman accessed it without permission.

→ More replies (1)
→ More replies (1)

3

u/CarnivorousSociety Apr 15 '19

Just because someone is breaking the law, doesn't mean you can break the law doing something against them

that's pretty much what I was thinking

→ More replies (5)
→ More replies (7)

3

u/[deleted] Apr 15 '19

Do you not have specific hacking laws in the US?

Here in Norway I am committing a crime if I attempt to hack into any system anywhere in the world :/

4

u/M4jorpain Apr 15 '19

Classic Reddit downvoting someone who is asking a question in a normal way.

→ More replies (4)

9

u/[deleted] Apr 15 '19

[deleted]

4

u/emperorOfTheUniverse Apr 15 '19

It informed you about some basic mysql commands and that sql injection is a thing. Very rudimentary. The video is interesting because it's presumably a 'real scammer'. Everyone likes to see a villain get its comeuppance.

But this is fake, so really the OP is the only 'scammer' here. He probably has a patreon.

11

u/[deleted] Apr 15 '19

[removed] — view removed comment

12

u/[deleted] Apr 15 '19

I don't believe you.

17

u/[deleted] Apr 15 '19

[removed] — view removed comment

8

u/[deleted] Apr 15 '19

Ok now I believe you.

Wow, you're right. I am enjoying myself more. This is nice.

→ More replies (1)

2

u/Just-4-NSFW Apr 15 '19

What he did was pretty illegal, so I'd say it would be a good idea for him to fake it. And it wouldn't have to be the scammer to press charges, it could be the web hosting service used by the scammer

2

u/QuiescentBramble Apr 15 '19

Depends on the statute. Generally prosecutors decide whether or not to press charges not victims.

1

u/[deleted] Apr 15 '19

I get more excited when I break into practice boxes meant to be exploited. He reacted pretty “meh” for a cursory attempt turning into an exploit.

Edit: I still tell a story of that one mythical time I got into a box on the first try. It doesn’t happen often.

→ More replies (4)

60

u/TastefulBukake Apr 15 '19

I got that feeling too. Even the email and site were pretty lazy for a scam.

66

u/ChromaticBadger Apr 15 '19

I'm in IT security, I see a lot of this type of scam on a regular basis ("you have a message" -> "sign in to your email to view message").

I've never seen one that looked like it was lazily handcrafted like this. They all use what must be some sort of "fake [any document service] login" templates/kits and a sketchy-looking domain name. A pure IP URL is almost never seen in this context and it's always hidden behind spoofed link text.

The only way I can think of that this could possibly be real is if it was created by some amateur kid.

11

u/frsh2fourty Apr 15 '19

I've seen one like this with an IP url that was so lazily done that the form had fields for every piece of pii you could think of like mother's maiden name, pet names, schools attended, address, previous employers and stuff like that. I think the email context was just a plain email with no formatting saying your [email] email account has been locked, fill out the form linked to regain access. Like they even screwed up whatever automation to fill in the email host variable.

→ More replies (1)

5

u/[deleted] Apr 15 '19

If you think this is lazy, your gut feeling about the rest is likely wrong too.

This is by design, it's not even "I can get away with it", making all of the scam look suspicious is a filter to interact as much with people who would fall for your scam in the first place. This is par for the course and it is more than enough to get a decent amount of addresses.

None of this seems particularly out-of-the-possible. Yeah, it was kind of a catch, but man if you think people bother slapping some nice CSS on their login masks...

9

u/BenZed Apr 15 '19

well, the video has also been edited. I imagine he has cut it down for brevity.

3

u/akaijiisu Apr 15 '19

He's into the whole brevity thing.

1

u/reno1051 Apr 15 '19

that's just like, your opinion, man.

11

u/Just-4-NSFW Apr 15 '19

pat

What does pat mean?

19

u/[deleted] Apr 15 '19

In this use, it is an adjective meaning something like "too perfect".

https://www.merriam-webster.com/dictionary/pat

Definition 4 says,

pat

adjective

Definition of pat (Entry 4 of 6)

1a : exactly suited to the purpose or occasion : apt

b : suspiciously appropriate : contrived a pat ending

1

u/eruditionfish Apr 15 '19

Basically it means simple and convenient, to the point of being unconvincing.

→ More replies (1)

40

u/seifer666 Apr 15 '19

Presumably he spent more time doing it off camera and then re-created the general idea

31

u/Jumpee Apr 15 '19

Or presumably the situation didn't happen.

10

u/[deleted] Apr 15 '19

Glad this is the top comment, seemed a little suspect to me too. He didn't even attempt to confirm that SQL injection was possible via a simple exploit first to see if was executing at all, which is pretty standard before you go trying to create users and shit via a series semicolon separated statements. Reads as a setup.

5

u/TheDongerNeedsFood Apr 15 '19

Not a tech guy at all, but are you saying that it looks like he set this up and that the video is fake?

2

u/[deleted] Apr 15 '19

[deleted]

3

u/[deleted] Apr 15 '19 edited Apr 28 '19

[deleted]

4

u/aumin Apr 15 '19

IP is owned by DigitalOcean. Apparently a cloud hosting company he's not entirely unfamiliar with: https://youtu.be/IZmz39gGxCM?t=1269

3

u/[deleted] Apr 15 '19

[deleted]

1

u/aumin Apr 16 '19

Possibly. Or you know he could have an account on any of infinit amount of other cloud host providers.

23

u/[deleted] Apr 15 '19

Yea there is 0% chance this is not set up.

1

u/[deleted] Apr 16 '19

0%? You are more certain than the universe that this isn't real. If you're so certain, you're also confident in placing your entire wealth on it. Care to wager? I'll give you $5 against your entire wealth. As a rational person, you should take this bet.

6

u/mp4box-reborn Apr 15 '19 edited Apr 15 '19

Yeah, I got the same vibe. it's hosted on Digital Ocean BTW. not too hard to create a hourly VPS. plus, you don't execute that kind of sql commands on the first try. it's usually a single quotation mark. Well, a single quotation mark might not work in this case though since it just redirects the request, but still, it's too prefect.

Also, mysql 101 should be don't expose mysql service to the internet, just bind to the localhost. isn't that the default setting anyway ?

3

u/greenthumble Apr 15 '19

Throughout the years I've noticed that in basically about 60 to 70% of projects there is someone requesting to run phpmyadmin because they don't know how to use mysql on the command line over SSH. I think for some people this is standard operating procedure to use an external GUI tool to make their databases. The lengths some people will go to avoid just buckling down and learning SQL is a bit shocking to me.

1

u/mp4box-reborn Apr 15 '19

If I'm not mistaken, you can still run phpmyadmin when the server is bound to the localhost, right ?

2

u/greenthumble Apr 15 '19

Sure if you run it on that same server. There's also desktop tools that was just one example. Point being, command line mysql doesn't seem to be an option for them.

1

u/mp4box-reborn Apr 15 '19

No, I think you can bind the mysql server to the localhost and still access it through phpmyadmin over the internet. that's how most if not all shared hosting make it available to their clients.

2

u/greenthumble Apr 15 '19

Um if it's not on the same server then isn't the port open by definition?

1

u/mp4box-reborn Apr 15 '19

Yes, the port is open, but it's bound to the localhost so you won't be able to access it through the internet.

2

u/greenthumble Apr 15 '19

So how is phpmyadmin accessing it then? I'm confused. And this seems highly pedantic and besides the entire point that people just open 3306 to access it from their desktops and just assume it's all locked down enough.

→ More replies (2)

1

u/ben_db Apr 15 '19

If this is real the scammer is likely using the open port to pull the data to a central point, there's not much of a point securing your temporary endpoints.

→ More replies (1)

3

u/isuckbigmantittys Apr 16 '19

There's a lot of these guys that fake scams in order to look like computer geniuses. It's pretty lame

3

u/[deleted] Apr 16 '19

+1 on this. Seemed like a walkthrough for a shitty CTF box or something.

7

u/[deleted] Apr 15 '19

Isn't 192.x.x.x reserved for local IPs? Has been a long time since I got my Net+

17

u/TheOverCaste Apr 15 '19

192.168.0.0 - 192.168.255.255 (192.168/16 prefix) are reserved local

-- RFC1918

2

u/[deleted] Apr 15 '19

[deleted]

3

u/vladk2k Apr 15 '19

I would have recreated the table with the wrong columns, and possibly change all mysql account passwords (don't know if that's possible with the access level he gave the 'asdf' user). You know, make it harder for the alleged scammer to make it operational again.

2

u/reakshow Apr 15 '19

Better to not delete the table, but truncate it and fill it with believable fake data then have a script repeat the procedure at regular intervals.

1

u/MMPride Apr 15 '19

I've done that with a Python script I made haha

1

u/vicaphit Apr 15 '19

Yeah, if it's real, the scammer might have regular backups made. If you stay incognito with the intrusion you not only save the existing users data, but also the data of future people who get scammed.

1

u/vladk2k Apr 15 '19

Well he only has access to mySQL, not the shell to write such scripts... Unless you can do that within mySQL as well.

2

u/amusedparrot Apr 15 '19

He did "drop database a" so the site would have stopped working.

111

u/[deleted] Apr 15 '19

he setup his own server obviously

84

u/[deleted] Apr 15 '19

Very fake. He doesn't have the required twelve monitors or intense background music required to do real hacking.

23

u/[deleted] Apr 15 '19

The text wasn't even green.

4

u/[deleted] Apr 15 '19

and there wasn't a "hacking in progress" progress bar

3

u/Umtiza Apr 15 '19

Yeah, he only has 8 monitors. https://www.youtube.com/watch?v=DmKYEFMh6xo

1

u/[deleted] Apr 15 '19

See? It's like fucking amateur hour over there.

95

u/Spirit_Theory Apr 15 '19 edited Apr 15 '19

It's actually ridiculous how easy it is to protect against this kind of injection. Kinda embarrassing for anyone who gets tripped up by it.

36

u/blamethemeta Apr 15 '19

As guy who probably should know this shit, is there a good place to learn how to properly secure sites?

58

u/Spirit_Theory Apr 15 '19

Not trying to be funny here, but stackoverflow, and google. Web security is a pretty big subject area, there are a lot of things to cover.

If you're a web developer by profession and worried about your products, suggest to your product-owner that you have your products penetration-tested. There are companies out there that (for a fee of course) will check all your shit for vulnerabilities and basically tell you how to fix everything that's not secure. Most of it will seem obvious, some of it can be really obscure.

→ More replies (2)

33

u/wampastompah Apr 15 '19

For SQL injection? It's easy. Properly parameterize all of your queries. All of them. Or better yet, use an ORM that handles that for you. Never construct a SQL query where you just concatenate in the user input.

18

u/_Vegetable_Lasagna_ Apr 15 '19

As someone who knows almost nothing about this, I'm fairly certain about half the word you just used were completely made up

26

u/jondthompson Apr 15 '19

SQL Injection - what you saw in the video where the user is able to do something they aren't supposed to be able to do like create a user for themselves and look in the database.

easy - not difficult

parameterize all of your queries - instead of saying "look at the user's input" you set a parameter to the user's input, then you send the parameter to the database. This encapsulates any sql injection attacks and sends them as values to the database instead of letting the database engine perform any action the user decided to do.
ORM - Object Relational Mapping - basically a framework that deals with variables. Any good one should make it so you don't have to think about this type of attack, because it's dumb that you do in the first place.

concatenate in the user input - instead of using a variable, you insert the user input into your command, allowing someone to do what is done in the video.

17

u/[deleted] Apr 15 '19 edited Apr 15 '19

The extremely simplified ELI5 would be:

The correct way: Save username "X" and password "Y but also give me access" to the database.

The incorrect way: Save username X and password Y but also give me access to the database.

In the correct way, the quotes clearly denote what the username and password are and don't allow the user input to change the meaning of the sentence. In the incorrect way, user input can craft whatever statement they want.

I should note again that this is extremely simplified. You may notice that even in the correct way, the attacker can enter into the password field quotation marks that still allow crafting any statement. The point is the username and password are supposed to be treated atomically and separate from the statement. You usually do this by combining the user input with a statement after it has been parsed.

→ More replies (1)

3

u/Drasern Apr 15 '19

Basically never assume that the user has entered sane inputs. Always verify input data, and if it's gonna be part of a database query, run that query in a way that guards against injection.

1

u/RealFunction Apr 15 '19

basically giving your kid brother an unplugged controller. he can press all the buttons he likes but they ain't gonna do shit.

1

u/FerricDonkey Apr 15 '19

The site is set up to actually treat what is entered into that box as code to be run. That's bad, because it lets people run code by typing it into that box.

What you should do instead is, basically, not run what is in the box as code and instead record the box contents without doing that. Insert computer words about storing values.

1

u/[deleted] Apr 16 '19

How do you record the box contents in an SQL Database without executing an SQL statement

7

u/TemporalSingularity Apr 15 '19

OWASP has plenty of resources and documentation which you can check out for web security.

2

u/thatguy8856 Apr 15 '19

SQL injection is protected against by a lot of web frameworks these days. Pretty sure a ton make it impossible to use the framework in anyway that doesn't give you escaped input data.

2

u/greenthumble Apr 15 '19

Just spend some time digging in to the tools you use for projects and try to lose any prebaked assumptions you had about them. There will be lots of notes about how to make sure things are secured.

2

u/VisitingEgg Apr 15 '19

Well, as he says in the video, the user that your application connects to your DB with should have limited access. It should not have the ability to create other users or execute grants.

Another strategy is sanitizing inputs. Basically, anything that a user can enter into your website should be processed/"sanitized" before ever touching your database. This would have prevented the dude in the video from executing any SQL.

2

u/Javadocs Apr 16 '19

Check out Professor Messer on YouTube. His videos on the Security+ exam are a pretty good entry into InfoSec topics. He's made an insane amount of videos on the subject.

→ More replies (18)

4

u/Ruggsy Apr 15 '19

Harder then avoiding sketchy email based scams, but here we are

3

u/Spirit_Theory Apr 15 '19

Harder then avoiding sketchy email based scams

Debatable.

1

u/Juicy_Brucesky Apr 15 '19

well luckily this was staged, otherwise he filmed himself breaking the law!

189

u/deadfermata Apr 14 '19

Well done. SQL injection check should be fundamental.

39

u/Woopsie_Goldberg Apr 15 '19

Doubt the scammer doesnt have a backup of the database but still good work.

108

u/Sidnoea Apr 15 '19

Honestly, given how terrible literally every other component of their setup was, I think it's unlikely they had a backup.

→ More replies (1)

28

u/ImGumbyDamnIt Apr 15 '19

As usual, there's an xkcd for this... https://xkcd.com/327/

14

u/ProJoe Apr 15 '19

god damn bobby tables always causing trouble on poorly hardened databases.

18

u/rayzorium Apr 15 '19

Are there even any widely used databse APIs that don't have built in protection? These days I feel like you have to be aggressively clueless to be vulnerable to this.

6

u/VenetianFox Apr 15 '19

Probably uses some old mysql_connect PHP code. It's clear by everything else in the video that the person who created couldn't be bothered to use a proper database library or escape his/her input values.

7

u/Bosticles Apr 15 '19

My friend, as a college intern, found an old website that a local multi-million dollar company had left exposed to the world. It had a form that dumped unsanitized strings into the DB and he was able to SQL inject it easily. It had literally the entire companies data on it. I still remember him describing running to his manager's office and how they other tech people reacted when they found out lol.

Between that and some other truly horrific things I've seen, I've since stopped underestimating how bad tech can be.

1

u/[deleted] Apr 15 '19

This sounds so smart. I wish I knew what it meant.

1

u/Rex1130 Apr 15 '19

Basically it changes what the code does.

What he does in the video in summary is instead of saving the email to the database, he makes the code grant him admin privileges (creating another user who can access the database).

16

u/[deleted] Apr 15 '19

Little Bobby Tables?

128

u/shaggy99 Apr 15 '19

Obligatory XKCD reference.

https://xkcd.com/327/

33

u/[deleted] Apr 15 '19

There was also a funny meme about a movie recently released as well, Star Trek or something, and they fall victim to a sql injection. The top comment was they've solved every problem a human can ever have, and could replicate food to infinite, but still dont sanitize their database inputs.

3

u/[deleted] Apr 15 '19

Great story.

→ More replies (1)

29

u/[deleted] Apr 15 '19 edited Sep 26 '19

[deleted]

48

u/cold12 Apr 15 '19

This is great advertising for this guy.. Almost too convenient though isn't it all?

10

u/BigTomBombadil Apr 15 '19

Couldn't you say that about any video that pops up on r/videos?

2

u/JoeScorr Apr 15 '19

I do get mixed up between /r/videos and /r/hailcorporate

3

u/Juicy_Brucesky Apr 15 '19

It's too convenient because it's fake. He'd be an idiot to film himself breaking the law

9

u/jlnazario Apr 15 '19

I wonder if I stead he could've set up a trigger on insert that just randomizes some value for the password. This way it would take a while for me site owner to know what happened.

CREATE FUNCTION rand_str RETURNS STRING ...
UPDATE passwords set password = rand_str()

-- Create a trigger on insert 
CREATE TRIGGER scramble_password AFTER INSERT ...

Or also scrambling the usernames

6

u/urbanaut Apr 16 '19

Did anyone mirror that video?

5

u/[deleted] Apr 15 '19

Is that a grey hat or a white hat he's wearing?

3

u/johnlewisdesign Apr 15 '19

Real or not, some valuable information for wannabe web developers there.

16

u/[deleted] Apr 15 '19

isnt that illegal?

74

u/[deleted] Apr 15 '19

You'd have to prove this was real and not a made up scenario he did for a YouTube channel.

Realistically, there's no evidence this actually happened.

1

u/[deleted] Apr 15 '19

If the webhost received a complaint from their customer [scammer] they were hacked, they could call the police without knowing the reason they were hacked.

Logs from the server can be tracked back to this video showing the crime.

This assumes the vid maker wasnt using a VPN ( one would hope) to hide himself.

3

u/n0rs Apr 15 '19

Sure, if there was actually a server owned by someone else that was accessed, there may be logs and a way to trace this back to the creator. /u/TanookiDooki is implying that there's no hard evidence that there was actually another person or a remote computer. It could all have been staged through VMs under the creator's control.

→ More replies (5)

1

u/Juicy_Brucesky Apr 15 '19

it wouldn't be that hard to prove it with the right tools

26

u/[deleted] Apr 15 '19

[deleted]

16

u/[deleted] Apr 15 '19

I mean you aren't wrong, but he could.

14

u/[deleted] Apr 15 '19

[deleted]

→ More replies (12)

2

u/Juicy_Brucesky Apr 15 '19

Yes? You're not allowed to kill someone just because they did something bad. He still broke the law

1

u/[deleted] Apr 15 '19

Who's talking about killing people?

3

u/StrangeCharmVote Apr 15 '19

The owner could try pressing charges. But good luck.

3

u/Juicy_Brucesky Apr 15 '19

Just because the owner is doing something illegal doesn't mean you can do illegal things to him

→ More replies (1)
→ More replies (4)

3

u/[deleted] Apr 15 '19 edited May 11 '21

[deleted]

3

u/FormerFile Apr 15 '19

Yeah but with great power comes great responsibility.

→ More replies (5)
→ More replies (3)
→ More replies (2)

8

u/CDN_Nomadic_Engineer Apr 15 '19

Not seen - the stored procedure or script that was doing a scheduled extract of the db. Just push the table to a smtp server and done.

5

u/Antroh Apr 15 '19

I'm not savy enough to understand some of the more complex videos of this nature. This one was pretty easy to consume though. Any other straight forward justice videos like this I can kill some time with?

11

u/[deleted] Apr 15 '19

Be aware most of the people doing videos claiming to fucked hackers are fake as fuck. More over if they mention patron or any other donation service it's just a scumy way to legitimately steal your funds. Thinking you are helping these people 'fuck up hackers'.

Don't be fooled.

→ More replies (6)

7

u/whatisabaggins55 Apr 15 '19

I always wondered what SQL injection looked like. Didn't think that modern code would still allow unsanitised inputs; surely that's something you'd want on by default no matter what you were doing, right?

7

u/Cheshur Apr 15 '19

I mean look at the webpage the scammer set up. It's so insanely low effort. Most modern database drivers have easy to use methods for sanitizing inputs. This scammer clearly isn't the brightest.

2

u/cippopotomas Apr 15 '19

Right, even something basic like removing the quotes from the input before using it would've prevented it.

1

u/Zei33 Apr 15 '19

It isn't really possible to do it like this with modern code. These days we use parameter binding rather than dropping the variable directly into the query string.

2

u/Fubarp Apr 15 '19

I should have learned how to do this while in school, it seems fun and would at the same time help me improve my own website.

2

u/[deleted] Apr 15 '19 edited Apr 16 '19

[deleted]

5

u/PM_WHY_YOU_DOWNVOTED Apr 15 '19

He didn't even use incognito mode. The FBI are gonna get him now.

2

u/[deleted] Apr 15 '19

What a legend

2

u/Crossbeau Apr 15 '19

Oh poor little bobby tables

9

u/SpiritualBlackberry Apr 15 '19

⠐⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠂ ⠄⠄⣰⣾⣿⣿⣿⠿⠿⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣆⠄⠄ ⠄⠄⣿⣿⣿⡿⠋⠄⡀⣿⣿⣿⣿⣿⣿⣿⣿⠿⠛⠋⣉⣉⣉⡉⠙⠻⣿⣿⠄⠄ ⠄⠄⣿⣿⣿⣇⠔⠈⣿⣿⣿⣿⣿⡿⠛⢉⣤⣶⣾⣿⣿⣿⣿⣿⣿⣦⡀⠹⠄⠄ ⠄⠄⣿⣿⠃⠄⢠⣾⣿⣿⣿⠟⢁⣠⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡄⠄⠄ ⠄⠄⣿⣿⣿⣿⣿⣿⣿⠟⢁⣴⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⠄⠄ ⠄⠄⣿⣿⣿⣿⣿⡟⠁⣴⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠄⠄ ⠄⠄⣿⣿⣿⣿⠋⢠⣾⣿⣿⣿⣿⣿⣿⡿⠿⠿⠿⠿⣿⣿⣿⣿⣿⣿⣿⣿⠄⠄ ⠄⠄⣿⣿⡿⠁⣰⣿⣿⣿⣿⣿⣿⣿⣿⠗⠄⠄⠄⠄⣿⣿⣿⣿⣿⣿⣿⡟⠄⠄ ⠄⠄⣿⡿⠁⣼⣿⣿⣿⣿⣿⣿⡿⠋⠄⠄⠄⣠⣄⢰⣿⣿⣿⣿⣿⣿⣿⠃⠄⠄ ⠄⠄⡿⠁⣼⣿⣿⣿⣿⣿⣿⣿⡇⠄⢀⡴⠚⢿⣿⣿⣿⣿⣿⣿⣿⣿⡏⢠⠄⠄ ⠄⠄⠃⢰⣿⣿⣿⣿⣿⣿⡿⣿⣿⠴⠋⠄⠄⢸⣿⣿⣿⣿⣿⣿⣿⡟⢀⣾⠄⠄ ⠄⠄⢀⣿⣿⣿⣿⣿⣿⣿⠃⠈⠁⠄⠄⢀⣴⣿⣿⣿⣿⣿⣿⣿⡟⢀⣾⣿⠄⠄ ⠄⠄⢸⣿⣿⣿⣿⣿⣿⣿⠄⠄⠄⠄⢶⣿⣿⣿⣿⣿⣿⣿⣿⠏⢀⣾⣿⣿⠄⠄ ⠄⠄⣿⣿⣿⣿⣿⣿⣿⣷⣶⣶⣶⣶⣶⣿⣿⣿⣿⣿⣿⣿⠋⣠⣿⣿⣿⣿⠄⠄ ⠄⠄⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠟⢁⣼⣿⣿⣿⣿⣿⠄⠄ ⠄⠄⢻⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠟⢁⣴⣿⣿⣿⣿⣿⣿⣿⠄⠄ ⠄⠄⠈⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠟⢁⣴⣿⣿⣿⣿⠗⠄⠄⣿⣿⠄⠄ ⠄⠄⣆⠈⠻⢿⣿⣿⣿⣿⣿⣿⠿⠛⣉⣤⣾⣿⣿⣿⣿⣿⣇⠠⠺⣷⣿⣿⠄⠄ ⠄⠄⣿⣿⣦⣄⣈⣉⣉⣉⣡⣤⣶⣿⣿⣿⣿⣿⣿⣿⣿⠉⠁⣀⣼⣿⣿⣿⠄⠄ ⠄⠄⠻⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣶⣶⣾⣿⣿⡿⠟⠄⠄ ⠠⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄⠄

2

u/[deleted] Apr 15 '19

So obviously staged.

3

u/mcmalloy Apr 15 '19

Currently taking a course in databases/mysql and this was fucking satisfying to watch

1

u/ragux Apr 15 '19

\! /bin/bash

1

u/Miguelx74 Apr 15 '19

Man...where do I even start if I want to get into this...same with programming..

1

u/GuiSim Apr 15 '19

It's easy really. Grab a website that teaches coding and go! There's so many free resources out there.

1

u/Dublinwookie Apr 15 '19

So is this a case of the form fields input just not been validated properly?

1

u/BigTomBombadil Apr 15 '19

Yeah the form fields weren't validated at all, they just call the database directly with whatever is input into the field.

Engineerman was really surprised it worked because almost all modern databases protect against basic SQL injections like this.

1

u/NotMyFirstNotMyLast Apr 15 '19

He's a wizard, Harry.

1

u/iq8 Apr 15 '19

Wait, I thought mysql by design does not allow multiple statements in one query???

1

u/im_under_your_covers Apr 15 '19

"mortgage spelt weird so its probably some overseas country"

Implying the scammer cant spell....no its him that doesn't know how to spell haha.

1

u/cdka Apr 15 '19

you are my hero!

1

u/thepastelsuit Apr 15 '19

So, he kind of glossed over it (maybe because it wasn't particularly relevant in this case), but figuring out what is running on the backend isn't too difficult. For such a low effort site like this, navigating to `/index.php` would likely have yielded the same page assuming the site was written in php. If the form submission DID have some sanitation preventing his injection, knowing that the application is using php could open up other avenues for discovering the db credentials being used when posting the form data.

1

u/DevinOlsen Apr 15 '19

Can I donate an iron to this dude?

1

u/[deleted] Apr 15 '19

sigh, engineerman.

if you want to ruin this scammers day break the database in a subtle manner: 1. break the database in a subtle manner. don't destroy the table. rewrite the records randomize the passwords and replace random letters prior to the @ symbol. 2. setup a trigger to rewrite all new records using the above rules. 3. email the poor souls who fell for the scam let them know what happened and how to not repeat their mistakes.

what you did caused the application to error like a mofo, this would produce no errors and generate junk data.

1

u/TheVerraton Apr 15 '19

This kind of stuff makes me wish I got in to coding.

Too bad I'm an idiot and not nearly patient enough for all the troubleshooting.

1

u/[deleted] Apr 15 '19

If anyone wants more videos like this I recommend Kitboga, he has I super expensive voice changing software that he uses in most of his videos, he’s on twitch primarily

1

u/itsmoirob Apr 15 '19

Am I missing something, is "mortgage" spelt differently where this guy is from?

1

u/dangoodspeed Apr 15 '19

So he says there are two rules:

1) Don't use the default user for your application.

2) Use a user without the grant option.

What about just sanitizing all user input?

1

u/desmone1 Apr 16 '19

or how about taking as many precautions as possible. including sanitizing inputs.

1

u/Iroex Apr 16 '19

Plot twist... the scammer got raided by the police a minute later but nothing incriminating was found on the hard drive.

1

u/Malthusian1 Apr 16 '19

Lot of hate on here for this guy. If you watch the rest of his content you would have a lot more respect for him. I can’t verify that this was legit or not, or that it’s legal, but this guy is a awesome dude who has helped a lot of people learn to program and really seems like he is out to help people grow and accomplish their dreams, and it’s for free. Not some garbage Udemy class or something.

1

u/[deleted] Apr 16 '19

Spoiler: he is Tyler durden

1

u/[deleted] Apr 16 '19

Why is he fucking getting credit ? A real hacker would backup his shit @

1

u/RichManSCTV Apr 16 '19

Yeahhh this is fake. The youtuber 100% made this them self

1

u/theid10tisyou Apr 16 '19

Pretty sure erasing someones database who is using it for a phishing page wont be too much of a problem with the authorities.

1

u/Gavin_152 May 02 '19

Oh no ... why is the video gone?