Username: 
Password: 
Restrict session to IP 

There is no escape  Go to the No Escape challenge

Global Rank: 253
Totalscore: 87266
Postitused: 1639
Aitäh: 1339
Üleshääled: 887
Registreeritud: 16y 75d




Viimati nähtud: 9h 33m
Kasutaja on hetkel väljas
There is no escape
Google/translate5Aitäh!3Hea postitus!0Halb postitus! link
As this is more or less a training challenge, i'd like to give some general hints:

If you are doing your injections, make sure you don`t end a query with semicolon(;). The php mysql extension does not like that.

There is a trim() for all $_GET and $_POST data. This means any trailing space get`s removed.

In this challenge, the / character is filtered. So you can not use /**/ as mysql comment style. A nice working mysql comment style for this challenge is: ?vote_for= blub%20--%20foo

everything after ' -- ' is treated as comment, but the trailing space is important.

At last, let me give you a specific hint for this challenge: mysql_real_escape_string() might not work for your input!

Also keep in mind: Our exploits are mostly not simulated and "Code you see is code in use"

Good luck!
The geeks shall inherit the properties and methods of object earth.
Global Rank: 6194
Totalscore: 2020
Postitused: 5
Aitäh: 4
Üleshääled: 4
Registreeritud: 13y 123d
Viimati nähtud: 3y 315d
Kasutaja on hetkel väljas
RE: There is no escape
Google/translate1Aitäh!0Hea postitus!1Halb postitus! link
Is it really possible with an MySQL-Injection? Cant pass trough the mysql_real_escape_string().
My Thougts was to manipulate simply that +1.
%20--%20 the Comment doesnt work or?

%20--%20 Shows an ErrorMessage like this:
MySqlError(1054): Unknown column 'bill -- ' in 'field list' in Query:
UPDATE noescvotes SET `bill -- `=`bill -- `+1 WHERE id=1

But all after the comment should not parsed or?
No matter the comments are only usefull if i can put a ' after my bill or george.

If another hint would break the challenge for others please write me a PM Smile
Thx for so much fun!
And sorry for my bad english iam german.
Viimati muudetud grMf - Jaanuar 03, 2011 - 01:10:44
Global Rank: 253
Totalscore: 87266
Postitused: 1639
Aitäh: 1339
Üleshääled: 887
Registreeritud: 16y 75d




Viimati nähtud: 9h 33m
Kasutaja on hetkel väljas
RE: There is no escape
Google/translate2Aitäh!1Hea postitus!0Halb postitus! link
Look closely again how the query is build Smile
Injecting mysql in this challenge is quite easy.
The geeks shall inherit the properties and methods of object earth.
Global Rank: 6194
Totalscore: 2020
Postitused: 5
Aitäh: 4
Üleshääled: 4
Registreeritud: 13y 123d
Viimati nähtud: 3y 315d
Kasutaja on hetkel väljas
RE: There is no escape
Google/translate2Aitäh!2Hea postitus!0Halb postitus! link
Thx this was close enough Smile
Great Challenge!
Global Rank: 15867
Totalscore: 68
Postitused: 1
Aitäh: 1
Üleshääled: 1
Registreeritud: 12y 229d
Viimati nähtud: 11y 55d
Kasutaja on hetkel väljas
RE: There is no escape
Google/translate1Aitäh!1Hea postitus!0Halb postitus! link
Ive been trying evrything and searched for the mysql_real_escape_string(), but could get to nowhere. Can you please give me another clue ?? Please please .-) I found that the function does not excape some chars, but could find any usefull with them.

Thank you
Viimati muudetud estenole - September 20, 2011 - 18:49:15
Global Rank: 253
Totalscore: 87266
Postitused: 1639
Aitäh: 1339
Üleshääled: 887
Registreeritud: 16y 75d




Viimati nähtud: 9h 33m
Kasutaja on hetkel väljas
RE: There is no escape
Google/translate1Aitäh!0Hea postitus!1Halb postitus! link
There is already a very big hint in my previous post ... and you are on a good track ... keep trying!
The geeks shall inherit the properties and methods of object earth.
Global Rank: 14408
Totalscore: 114
Postitused: 1
Aitäh: 1
Üleshääled: 1
Registreeritud: 8y 36d
Viimati nähtud: 7y 302d
Kasutaja on hetkel väljas
RE: There is no escape
Google/translate1Aitäh!1Hea postitus!0Halb postitus! link
Gizmore first post helps out the most as i was stuck on commenting the rest of the command
Global Rank: 5048
Totalscore: 3089
Postitused: 2
Aitäh: 1
Üleshääled: 0
Registreeritud: 7y 246d
Viimati nähtud: 7y 229d
Kasutaja on hetkel väljas
RE: There is no escape
Google/translate0Aitäh!0Hea postitus!0Halb postitus! link
Huh... I kept getting errors until I added the trailing space, and now I get two green boxes (Vote counted for [INJECTION] and All votes have been reset), leading me to believe that I solved it, but it doesn't show up as solved in my challenges, and I am not on the Heroes list.
Global Rank: 1
Totalscore: 759872
Postitused: 431
Aitäh: 491
Üleshääled: 456
Registreeritud: 14y 278d












Kasutaja on hetkel väljas
RE: There is no escape
Google/translate1Aitäh!1Hea postitus!0Halb postitus! link
Check the code. There are two ways to get those messages, only one is the solution.
Global Rank: 5048
Totalscore: 3089
Postitused: 2
Aitäh: 1
Üleshääled: 0
Registreeritud: 7y 246d
Viimati nähtud: 7y 229d
Kasutaja on hetkel väljas
RE: There is no escape
Google/translate1Aitäh!0Hea postitus!0Halb postitus! link
Hah, I got it. It just didn't like me going overboard and using 999 instead of 111 in my injection.
Redknee, dbhui1984, testlele, tunelko, silenttrack, n0tHappy, quangntenemy, TheHiveMind, Z, balicocat, Ge0, samuraiblanco, arraez, jcquinterov, hophuocthinh, alfamen2, burhanudinn123, Ben_Dover, stephanduran89, braddie0, JanLitwin17, SwolloW, dangarbri have subscribed to this thread and receive emails on new posts.
1 vaatavad hetkel seda teemat.
Seda teemat on vaadatud 17645 korda.