|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 86
Members: 0
Total: 86
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
|
I suggest, that everything would be in the table Students I need to know (passwords), but actually how can I get an output what the data is in the table? Is there a trick to display the message someho ... |
|
|
|
|
actually i got a little bit further, but still quite in the 'dark':
I think I found a solution which let's me use Union:
First I found that I am able to look how many fields the table students has ... |
|
|
|
|
correction, when entering
‘ UNION SELECT 1,1,1 FROM validTableName%00
I get following:
Actually I don't understand it completely, because it seems that is not the whole string of the statem ... |
|
|
|
|
thanks a lot for this hint... it points me into a new direction. I was really looking forward for this comment thing %00....
however when using union and %00 -
‘ UNION SELECT 1,1,1 FROM Students ... |
|
|
|
|
Hello everyone,
I am new here, right, but hey.... it's always a first timer somewhere...
Short story: I found a website which has a injectable login.asp page...
Login Screen
Inputs: Email &am ... |
|
|
Page 1 of 1 |
All times are GMT |
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|