Jump to content
Furnicarul

SQL

Recommended Posts

Am citit la sql si am invatat cat de cat dupa ce iar nu am stiut ceva...Am invatat sa folosesc sqlmap si Burpsuite, sa decriptez Rot13 cipher, si sa fac cat de cat cerintele de la CTF alea mai usoare gen..Alea cu zip, cu imagini, sa folosesc binwalk, dosbox cat de cat, cat sa aflu flagurile cand dau DEBUG si strings...

Am o problema acum, sunt blocat la nivelul 3 http://ctf.infosecinstitute.com/ctf2/exercises/ex3.php nu inteleg cee ar trebui sa fac..

================================================================================================================================

Pai ori inveti, ori ba.

Scrie acolo Vulnerability: Data Validation; Parameter Delimiter.

Ai si hint: When you login you would see exactly how user's access level is determined in the text file, "The delimiter used to separate fields like username and password is just a newline.

Folosesti Burp, creezi cont in aplicatia ctf, vezi request-ul HTTP.

Fiecare user are un rol/drept. Tu ai normal, trebuie sa devii admin.

Te joci cu Burp Repeater. Gasesti request-ul de inregistrare la tab-ul Proxy, apoi HTTP History si ii dai Send to Repeater la POST request.

Adaugi newline in request, cum scrie in hint - o sa fie encoded. %0d%0a - spre exemplu intri aici, apesi enter de 2 ori (newline) si dai encode.

https://www.w3schools.com/tags/ref_urlencode.asp

https://www.degraeve.com/reference/urlencoding.php

Request-ul trebuie sa fie de forma:

user=FurnicaObosita&password=FurnicaObosita&lname=FurnicaObosita%0d%0arole:admin... -> %0d%0a - encoded newlines

 

Tu zilele trecute nu stiai basic SQL si acum ai trecut la Burp Suite. Da' ai relatii in oras si parteneriate, esti combinator...si noi fraierii tai, nu?

Nu-mi mai scrie prin PM ca nu te mai ajut.

Edited by ARUBA
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...