Jump to content
ajkaro

SQLi challenge

Recommended Posts

Posted (edited)

Target:

hXXp://www.lesplastiquesdelouest.com/produit.php?id=55

Task:

  • display version with your name
  • display count how many column names start with characters id_ You should use command count() for that result.
  • display list of columns (with their database and table name) where column names start with characters id_
  • use of colors is not obligatory

Proof:

fkskd3.jpg

http://www.anonmgur.com/up/2a4c605406c12ee7c60fccfd9f97165b.jpg

Rules:

  • use union select based SQLi
  • send me your command to PM
  • post picture as proof

Solvers:

-

challenge closed

See tutorial how to solve it:

http://www.hackforums.net/showthread.php?tid=3487536

or

http://zentrixplus.net/forum/index.php?/topic/940-sqli-tutorial-playing-with-dump-in-one-shot-syntax-part-1/

Edited by ajkaro
Posted

Hi Sega,

I don't see 32 items on your list. Compare your picture with mine. Also please add database name to each line in list. After doing that you will see you can't use your present command. You will have to heavy modify your command.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...