Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Challenge | SQL inject this website filter_list
Author
Message
Challenge | SQL inject this website #1
Hello

Sorry for posting two threads in the same section so close together

I was wondering if anyone is interested in this challenge?

So a bit of background information:
This website is by a company called evsmc
(Electric vehicle surveillance and monitoring centre) (xìnlengyūn cīche gwojiâ jianshung ji gwānli zhūngsin)

evsmc.org

Which requires every electric, bi fuel, hybrid, plugin hybrid, nuclear, and hydrogen cars in the PRC to send their following data to the company, the data sent includes: the license plate, the name and SSN( which contains all information about the owner) of the owner, the wexin id of the driver currently in the car (which allows the government to find the name and SSN), the current speed of the vehicle, the gear the transmission is in, the type of vehicle, the odometer, the electricity voltage, the amount of peripherals connected(and their id and detail) the amount of electricity charge, etc.

And all of the above data are sent to this panel real-time.
https://prnt.sc/owy5ad

I've done a bit of work, and found out their panel ip and port

http://61.149.8.148:6064/#/

And also some data without login required

http://61.149.8.148:6064/#/national

http://61.149.8.148:6064/#/breakdown/

http://61.149.8.148:6064/#/accidentAlarm


So I was just wondering if any of you can SQL inject this website.

As always, play safe, use a VPN when dealing with government sites, and good luck.
johnngnky#5687 BANNED - permed, appeal failed.


contact me exclusively using the below email.

contact@Johnngnky.xyz

[+] 1 user Likes Johnngnky's post
Reply

RE: Challenge | SQL inject this website #2
Wow man, that is some serious stuff here, you should probably keep this all to yourself. Seriously.

Reply

RE: Challenge | SQL inject this website #3
(08-24-2019, 02:38 PM)Johnngnky Wrote: As always, play safe, use a VPN when dealing with government sites, and good luck.

There's a lot more to anonymity than just a VPN.

For Instance (just briefly), encrypt your DNS servers, connect to the Tor network (Tor over VPN with a bridged connection at the entry node), disable WebRTC & WebGL, minimize canvas & font fingerprinting with at least a 1:50 ratio, exclude the 14 eyes countries at the exit node and apply VPN over Tor thereafter.

There's more Involved, but this Is only a simple configuration.
[Image: AD83g1A.png]

Reply

RE: Challenge | SQL inject this website #4
To be fair you didn't do most the work lol. Most the work is scanning and enumeration.
“Lord, protect me from my friends; I can take care of my enemies.”  - Volitaire

Reply