Username: 
Password: 
Restrict session to IP 

SQL injection  Go to the Training: MySQL II challenge

Global Rank: 3042
Totalscore: 6823
Posts: 3
Thanks: 3
UpVotes: 2
Registered: 8y 91d
Last Seen: 8y 83d
The User is Offline
SQL injection
Google/translate1Thank You!0Good Post!1Bad Post! link
I get stuck.

Sensitive is login authentication, so i try to bypass it writing:
CENSORED
or
CENSORED
but the only message I get is wrong password.

Can anybody give me a hint what I'm doing wrong ?
Last edited by dloser - Jan 05, 2016 - 14:59:17
Global Rank: 1
Totalscore: 760035
Posts: 431
Thanks: 491
UpVotes: 456
Registered: 14y 246d












The User is Offline
RE: SQL injection
Google/translate1Thank You!1Good Post!0Bad Post! link
You are ignoring the crucial part of this challenge: the password check.
Global Rank: 3042
Totalscore: 6823
Posts: 3
Thanks: 3
UpVotes: 2
Registered: 8y 91d
Last Seen: 8y 83d
The User is Offline
RE: SQL injection
Google/translate1Thank You!1Good Post!0Bad Post! link
First of all thanks for hint and quick response.

I tried to end SQL command by -- - or -- or %00 and then comment rest of PHP function with multiline comment /*
Injection looks like:

CENSORED

But still getting message about wrong password.
Last edited by dloser - Jan 05, 2016 - 15:42:13
Global Rank: 1
Totalscore: 760035
Posts: 431
Thanks: 491
UpVotes: 456
Registered: 14y 246d












The User is Offline
RE: SQL injection
Google/translate1Thank You!0Good Post!1Bad Post! link
You cannot comment out PHP code like that. (And if you could, it still wouldn't work.)

B.t.w.: Don't include the injections you are trying in your posts. It could spoil it for others.
tunelko, Redknee, silenttrack, n0tHappy, quangntenemy, TheHiveMind, Z, balicocat, Ge0, samuraiblanco, arraez, jcquinterov, hophuocthinh, alfamen2, burhanudinn123, Ben_Dover, stephanduran89, braddie0, SwolloW, dangarbri have subscribed to this thread and receive emails on new posts.
1 people are watching the thread at the moment.
This thread has been viewed 9036 times.