English
German
French
Spanish
Albanian
Dutch
Bosnian
Serbian
Turkish
Czech
Finnish
Hungarian
Italian
Polish
Russian
Estonian
Urdu
News
Links
Sites
Forum
Ranking
Challenges
Downloads
Register
New Sites
PWN.TN
PromptRiddle
PyDéfis
CryptoHack
247CTF
Énigmes À Thématiques
LordofSQLi
MysteryTwister
New Users
Drast
cryptoman
destroyer
novice-22
sk3d
jiwoon
simoStar
Nieokrzesany
40 Online
Guest(x26)
,
Drast
,
EG24
,
jusb3
,
kraikill
,
MadRider
,
rlm34t
,
selmazing
,
TaterTot
,
tehron
,
xseris
Signup
Hide Sidebar
Restrict session to IP
Register
Forgot password
Statistics
50 Sites
161 Challs
8289 Posts
60811 Users
33 donations
50 Active Sites
World of Wargame
WeChall
Rankk
Electrica
NewbieContest
LOST-Chall
Yashira
BrainQuest
Net-Force
HackThisSite
ThisisLegal.com
elhacker.net
TryThis0ne
TDHack
+Ma's Reversing
Hacker.org
HackBBS
Root-Me
SPOJ
Revolution Elite
W3Challs
Gekkó
Webhacking.kr
µContest
Valhalla
Reversing.Kr
SuNiNaTaS
Yoire
Hacking-Challenges
OverTheWire.org
RedTigers Hackit
Tasteless
Defend the Web
Mod-X
Omega Project
ae27ff
pwnable.kr
RingZer0 Team Online CTF
Hacker Gateway
pwnable.tw
Hack The Box
try to decrypt
MysteryTwister
LordofSQLi
Énigmes À Thématiques
247CTF
CryptoHack
PyDéfis
PromptRiddle
PWN.TN
Top 10 Players
dloser
benito255
Caesum
jusb3
tehron
phoenix1204
lordOric
thefinder
Akorlith
yachoor
Last 20 Activities
EG24
ringbo
ogi
Drast
ogi
jusb3
balicocat
balicocat
sk3d
Drast
luadoles
r3v3rs3_sh3ll
mrmask4588
s4ch1n
cryptoman
ethanpu
smarinoc
T567U1
thefinder
XtxXD
Online within 1d
49 Users
TaterTot
rlm34t
tehron
EG24
MadRider
selmazing
xseris
Drast
jusb3
kraikill
ogi
r_karoly
balicocat
sirl1on
lpldswa
faust
SevenPlath
mrmask4588
cryptoman
luadoles
more
WeChall
->
Challenges
->
Challenge: Training: MySQL II
SQL injection
Go to the Training: MySQL II challenge
Some enlightenment required
Double query
flaps
Global Rank: 2834
Totalscore: 6799
Posts: 3
Thanks: 3
UpVotes: 2
Registered: 6y 144d
Last Seen: 6y 137d
The User is Offline
SQL injection
Jan 05, 2016 - 14:11:49 (6y 139d)
Google/translate
1
Thank You!
0
Good Post!
1
Bad Post!
link
I get stuck.
Click for spoiler
Sensitive is login authentication, so i try to bypass it writing:
CENSORED
or
CENSORED
but the only message I get is wrong password.
Can anybody give me a hint what I'm doing wrong ?
Last edited by dloser - Jan 05, 2016 - 14:59:17
dloser
Global Rank: 1
Totalscore: 761846
Posts: 420
Thanks: 474
UpVotes: 434
Registered: 12y 300d
The User is Offline
RE: SQL injection
Jan 05, 2016 - 15:00:02 (6y 139d)
Google/translate
1
Thank You!
1
Good Post!
0
Bad Post!
link
You are ignoring the crucial part of this challenge: the password check.
flaps
Global Rank: 2834
Totalscore: 6799
Posts: 3
Thanks: 3
UpVotes: 2
Registered: 6y 144d
Last Seen: 6y 137d
The User is Offline
RE: SQL injection
Jan 05, 2016 - 15:37:37 (6y 138d)
Google/translate
1
Thank You!
1
Good Post!
0
Bad Post!
link
First of all thanks for hint and quick response.
Click for spoiler
I tried to end SQL command by -- - or -- or %00 and then comment rest of PHP function with multiline comment /*
Injection looks like:
CENSORED
But still getting message about wrong password.
Last edited by dloser - Jan 05, 2016 - 15:42:13
dloser
Global Rank: 1
Totalscore: 761846
Posts: 420
Thanks: 474
UpVotes: 434
Registered: 12y 300d
The User is Offline
RE: SQL injection
Jan 05, 2016 - 15:48:02 (6y 138d)
Google/translate
1
Thank You!
0
Good Post!
1
Bad Post!
link
You cannot comment out PHP code like that. (And if you could, it still wouldn't work.)
B.t.w.: Don't include the injections you are trying in your posts. It could spoil it for others.
tunelko
,
Redknee
,
silenttrack
,
n0tHappy
,
quangntenemy
,
TheHiveMind
,
Z
,
balicocat
,
Ge0
,
samuraiblanco
,
arraez
,
jcquinterov
,
hophuocthinh
,
alfamen2
,
burhanudinn123
,
Ben_Dover
,
stephanduran89
,
braddie0
have subscribed to this thread and receive emails on new posts.
1 people are watching the thread at the moment.
This thread has been viewed 7863 times.