English
German
French
Spanish
Albanian
Arabic
Dutch
Bosnian
Serbian
Turkish
Czech
Finnish
Hungarian
Italian
Polish
Russian
Estonian
Urdu
News
Links
Sites
Forum
Ranking
Challenges
Downloads
Register
New Sites
HackMyVM
pwn.college
PWN.TN
PromptRiddle
PyDéfis
CryptoHack
247CTF
Énigmes À Thématiques
New Users
aenigma4mentis
junghoon
GRD
SimonMeow
staraax
kikinator
kuwo__
leekon_
104 Online
Guest(x95)
,
ethanjohnson89
,
livinskull
,
MAZI_
,
SARE
,
tutolmin
,
xseris
,
zipr0n8
Signup
Hide Sidebar
Restrict session to IP
Register
Forgot password
Statistics
45 Sites
188 Challs
9150 Posts
68630 Users
45 donations
1 Shop
45 Active Sites
World of Wargame
WeChall
TheBlackSheep
Rankk
Electrica
NewbieContest
BrainQuest
Net-Force
HackThisSite
elhacker.net
TryThis0ne
TDHack
+Ma's Reversing
Hacker.org
HackBBS
Root-Me
SPOJ
Revolution Elite
W3Challs
Gekkó
Webhacking.kr
Reversing.Kr
SuNiNaTaS
Hacking-Challenges
OverTheWire.org
RedTigers Hackit
Defend the Web
Mod-X
Omega Project
ae27ff
pwnable.kr
RingZer0 Team Online CTF
pwnable.tw
Hack The Box
try to decrypt
MysteryTwister
LordofSQLi
Énigmes À Thématiques
247CTF
CryptoHack
PyDéfis
PromptRiddle
PWN.TN
pwn.college
HackMyVM
Top 10 Players
dloser
benito255
jusb3
Caesum
tehron
phoenix1204
lordOric
thefinder
Xaav
Akorlith
Last 20 Activities
bobko
livinskull
inselaffe03
AutisticAlpaca
alexc0
amirhoseinvali
ChanoSho
livinskull
AACDAI
TeeJay
LouisJ
Blue_Box
kpks
wjsrhkdtn123
aenigma4mentis
ethanjohnson89
aenigma4mentis
aenigma4mentis
cheerfulbull
junghoon
Online within 1d
50 Users
ethanjohnson89
MAZI_
zipr0n8
xseris
livinskull
tutolmin
SARE
playteddypicker
shukularuni
inselaffe03
fier3c
noother
alexc0
AutisticAlpaca
volfgox
amirhoseinvali
r_karoly
tehron
cheerfulbull
Blue_Box
more
WeChall
->
Challenges
->
Challenge: Training: MySQL II
SQL injection
Go to the Training: MySQL II challenge
Some enlightenment required
Double query
flaps
Global Rank: 3111
Totalscore: 6831
Posts: 3
Thanks: 3
UpVotes: 2
Registered: 9y 32d
Last Seen: 9y 25d
The User is Offline
SQL injection
Jan 05, 2016 - 14:11:49 (9y 27d)
Google/translate
1
Thank You!
0
Good Post!
1
Bad Post!
link
I get stuck.
Click for spoiler
Sensitive is login authentication, so i try to bypass it writing:
CENSORED
or
CENSORED
but the only message I get is wrong password.
Can anybody give me a hint what I'm doing wrong ?
Last edited by dloser - Jan 05, 2016 - 14:59:17
dloser
Global Rank: 1
Totalscore: 758717
Posts: 437
Thanks: 497
UpVotes: 470
Registered: 15y 188d
The User is Offline
RE: SQL injection
Jan 05, 2016 - 15:00:02 (9y 27d)
Google/translate
1
Thank You!
1
Good Post!
0
Bad Post!
link
You are ignoring the crucial part of this challenge: the password check.
flaps
Global Rank: 3111
Totalscore: 6831
Posts: 3
Thanks: 3
UpVotes: 2
Registered: 9y 32d
Last Seen: 9y 25d
The User is Offline
RE: SQL injection
Jan 05, 2016 - 15:37:37 (9y 27d)
Google/translate
1
Thank You!
1
Good Post!
0
Bad Post!
link
First of all thanks for hint and quick response.
Click for spoiler
I tried to end SQL command by -- - or -- or %00 and then comment rest of PHP function with multiline comment /*
Injection looks like:
CENSORED
But still getting message about wrong password.
Last edited by dloser - Jan 05, 2016 - 15:42:13
dloser
Global Rank: 1
Totalscore: 758717
Posts: 437
Thanks: 497
UpVotes: 470
Registered: 15y 188d
The User is Offline
RE: SQL injection
Jan 05, 2016 - 15:48:02 (9y 27d)
Google/translate
1
Thank You!
0
Good Post!
1
Bad Post!
link
You cannot comment out PHP code like that. (And if you could, it still wouldn't work.)
B.t.w.: Don't include the injections you are trying in your posts. It could spoil it for others.
tunelko
,
Redknee
,
silenttrack
,
n0tHappy
,
nonfungiblesecurity
,
quangntenemy
,
TheHiveMind
,
Z
,
balicocat
,
Ge0
,
samuraiblanco
,
arraez
,
jcquinterov
,
hophuocthinh
,
alfamen2
,
burhanudinn123
,
Ben_Dover
,
stephanduran89
,
braddie0
,
SwolloW
,
dangarbri
,
csuquvq
have subscribed to this thread and receive emails on new posts.
0 people are watching the thread at the moment.
This thread has been viewed 9725 times.