Jump to content
vlad1395

[Easy/Medium] SQL Injection [4]

Recommended Posts

O noua competitie, care sper ca o sa va placa.

- Sintaxele nu se vor face publice, se vor trimite prin PM !

- Postati aici doar un screen-shot ca dovada ca ati rezolvat (fara a se vedea rezolvarea)

Cerere: Extrageti ce vreti .

Dificultate:Easy/Medium

Metoda: Union Based

Vulnerable Parameter: LE POCHE

SURSA: HF

Proof: ImageShack® - Online Photo and Video Hosting

NOTA:: Injectia se va face DOAR pe parametrul dat de mine.

Solvers

denjacker/daemien

pr00f

scorpy0n

master_of_puppets_jr

symboss

ZeroCold

Edited by vlad1395
Link to comment
Share on other sites

daca ai numarat bine numarul de coloane si le enumeri cu union select + "hint" ... ar trebui sa reusesti.

Ca sa vezi cele 3 coloane CTRL + A .

coloanele le-a numarat bine, mi-a trimis ieri PM.

// master_of_puppets_jr Solved this Challenge

Edited by vlad1395
Link to comment
Share on other sites

HINT

==================

Dupa cum, am promis, am decis sa postez HINT, pentru aceasta competitie. Nu este grea, dar probabil v-at impodmolit la ceva nesemnificativ.

Competia poate fii rezolvata in 3 feluri diferite, output-ul, aparand intr-un mod diferit la fiecare varianta.

[*] Prima varianta, este cel mai usor de gasit, fapt dovedit in gasirea ei de catre 2 Solveri (pr00f, scorpy0n) .

Aceasta consta in aparitia rezultatului generat de sintaxa, in eroarea SQL.

Pasi:

- Numarati Coloanele, folosind "order by" .

- Enumerati-le, folosind "union select" .

- Fiti atemti la ce comment-uri folositi .

- Puneti o afirmatie negativa

- Fiti atenti, unde se face output-ul: http://i.imgur.com/IUDR2.png (pr00f's)

[*] A doua varianta, consta in aceeasi pasi folositi ca si la varianta 1, cu exceptia enumerarii coloanelor cu NULL. Coloanele vulnerabile vor trebui ghicite.

[*] A treia varianta, consta in afisarea coloanelor vulnerabile pe pagina. Pentru aceasta, folositi HINT-ul de la varianta 2, in locul coloanei vulnerabile de la varianta 1 .

Sper ca v-am putut ajuta.

PENTRU INTREBARI, NELAMURIRI DESPRE SQL INJECTION, POSTATI AICI:

http://rstcenter.com/forum/35718-sql-injection-%5B-help-thread-%5D.rst

Edited by vlad1395
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...