You must be logged in to post Login Register

Search Forums:


 






Sql Injection Challenge!

UserPost

11:55 pm
December 20, 2007


clarke

Active Member

posts 223

what ever happened to esc ^^^ did he get his prize t-shirt and did you guys design a t-shirt just for the 2 winners or do you have extras or something?

7:25 pm
December 21, 2007


Patchy

Champaign, IL

Admin

posts 1643

lol actually we haven't had time to send there prizes yet. We will very soon though. Also, we have always planned to sell the tshirts, but it may be a while before we get our shit together and start making them.

"From the perspective of these infinites, all finites are equal, and I see no reason for fixing our imagination on one rather than on another."n~ Blaise Pascal, Pensées

6:47 am
December 31, 2007


xkyve

CS

Member

posts 15

Crongats marcel and esc. I'm impressed with the ideea, never would have figured it out on my own :P P, I'm new to SQL. Saw the video, very well explained. I didn't understand something. How did he know how many columns there are (how many null's to put)?

10:05 am
December 31, 2007


GONZO

Guru

posts 569

You add a null until you get an error I think I know a little about sql but im manly wireless hacker.

4:44 am
January 1, 2008


xkyve

CS

Member

posts 15

But what happens when the site doesn't display the errors?
hide_errors();
So when you inject values with tamper data into the search function, the errors won't show up. How do you know then how many columns it has? There are 7 columns, did he know from the GET method? If yes, could he know from somewhere else?

LATER EDIT: I think another way would be to view the source codes. Perhaps also install and try it on your own SQL server.

4:11 am
March 27, 2008


AlloveR

Active Member

posts 124

i finished the challenge=]

i still kind of confused where the 15 comes from? can someone explain this to me please?

also why does the # work and not –

Password Cracking | Simple md5, sha1 and Salted!

http://cr4ck.me

12:46 am
March 30, 2008


Patchy

Champaign, IL

Admin

posts 1643

What 15?
# and — are just two different types of comments that work on different sql servers.

"From the perspective of these infinites, all finites are equal, and I see no reason for fixing our imagination on one rather than on another."n~ Blaise Pascal, Pensées

5:04 pm
April 9, 2008


esc

Member

posts 15

no t-shirts. but is ok. i did it for fun. i hope there will be new challange to try.

5:05 pm
April 10, 2008


Patchy

Champaign, IL

Admin

posts 1643

Really?? We sent that forever ago! well that's pretty lame. email me your address again and we'll try again when we get home from school. sorry man.

"From the perspective of these infinites, all finites are equal, and I see no reason for fixing our imagination on one rather than on another."n~ Blaise Pascal, Pensées

12:44 am
April 11, 2008


esc

Member

posts 15

email sent.

1:18 am
July 23, 2008


shafee815

Newbie

posts 1

how i can find a temper data in Firefox browser

10:26 am
July 23, 2008


Patchy

Champaign, IL

Admin

posts 1643

"From the perspective of these infinites, all finites are equal, and I see no reason for fixing our imagination on one rather than on another."n~ Blaise Pascal, Pensées

9:44 pm
August 10, 2008


sickwitit

Newbie

posts 1

can the Wp-Forums Source Code be used on a Windows Vista CPU?

5:43 pm
August 14, 2008


Patchy

Champaign, IL

Admin

posts 1643

What?! The source code is php why wouldn't it work.

"From the perspective of these infinites, all finites are equal, and I see no reason for fixing our imagination on one rather than on another."n~ Blaise Pascal, Pensées

10:07 pm
August 14, 2008


excid3

Active Member

posts 179

sickwitit, do you understand the basics of web software? it has to be usable by ANY web browser in order for it to be useful. if your operating system is capable of connecting to the internet and running a web browser…then the code can be used on it…

8:27 am
August 15, 2008


CrashOverron

Moderator

posts 377

[quote][b]QUOTE[/b] (excid3 @ )
sickwitit, do you understand the basics of web software? it has to be usable by ANY web browser in order for it to be useful. if your operating system is capable of connecting to the internet and running a web browser…then the code can be used on it…[/quote]

actually php is a server-side language meaning that whatever computer it is running on has to have php installed, when you're looking at a web page that is written in php the host server has php installed so it runs even if you dont have it

8:13 am
January 11, 2010


vboot

england

Newbie

posts 1

Patchy said:

I’m proud to announce the first Infinity Exists’ Hacking Challenge! The challenge is to find a Sql Injection flaw in our forums, and exploit it to extract password hashes. The first person to complete this challenge will receive a free Infinity Exists T-shirt. The Sql Injection vulnerability is hidden deep in Infinity Exists’ forums, and will be much harder to find then the vulnerability demonstrated in Full Disclosure Episode 11. Tips to help you get started: 1. Watch Full Disclosure Episode 11! 2. Download Wp-Forums Source Code 3. The variable that is used to manipulate the Sql Statement is a POST variable. Good Luck!


hi im new at this any basic challenges you could set me would be extremly helpful.

infact any help at all is good help!

and also is there a way to make the portsign hacking simulator gui into a real security penertration system?Confused 

6:59 pm
June 13, 2010


kg2905

CT

Newbie

posts 2

When starting each VM, I get the message "Host USB device connections disabled. The connection to the VMware USB Arbitration Service was unsuccessful. Please check the status of this service in the Microsoft Management Console."
I am running Windows Vista
There is no icon for USB in the VMware window below the guest window, so I cannot click to connect any device. USB controller is present in Settings.

What can be done to connect USB devices to my VMs in Workstation 7?

Kg2905

1:39 am
June 14, 2010


madf0x

Active Member

posts 224

Wrong location ya friggen idiot

Before you ask a question read this: http://freeworld.thc.org/root/docs/smart-questions.html it will make your life and everyone else's life easier.

12:32 pm
June 18, 2010


nc

Newbie

posts 2

hi

eroor sql inejct

You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '; < , . /')' at line 1


for web site


http://gallery.beyluxe.com/login.html

plz help me CryCry

ty



About the Infinity Exists forum

Most Users Ever Online:

164


Currently Online:

12 Guests

Forum Stats:

Groups: 4

Forums: 22

Topics: 1945

Posts: 9586

Membership:

There are 8004 Members

There has been 1 Guest

There are 2 Admins

There are 3 Moderators

Top Posters:

GONZO – 569

slicer45 – 270

Teddy – 240

madf0x – 224

clarke – 223

gube – 214

Administrators: Patchy (1643 Posts), Nox (40 Posts)

Moderators: CrashOverron (377 Posts), Override (207 Posts), Copy (163 Posts)