Challenge | SQL inject this website 08-24-2019, 02:38 PM
#1
Hello
Sorry for posting two threads in the same section so close together
I was wondering if anyone is interested in this challenge?
So a bit of background information:
This website is by a company called evsmc
(Electric vehicle surveillance and monitoring centre) (xìnlengyūn cīche gwojiâ jianshung ji gwānli zhūngsin)
evsmc.org
Which requires every electric, bi fuel, hybrid, plugin hybrid, nuclear, and hydrogen cars in the PRC to send their following data to the company, the data sent includes: the license plate, the name and SSN( which contains all information about the owner) of the owner, the wexin id of the driver currently in the car (which allows the government to find the name and SSN), the current speed of the vehicle, the gear the transmission is in, the type of vehicle, the odometer, the electricity voltage, the amount of peripherals connected(and their id and detail) the amount of electricity charge, etc.
And all of the above data are sent to this panel real-time.
https://prnt.sc/owy5ad
I've done a bit of work, and found out their panel ip and port
http://61.149.8.148:6064/#/
And also some data without login required
http://61.149.8.148:6064/#/national
http://61.149.8.148:6064/#/breakdown/
http://61.149.8.148:6064/#/accidentAlarm
So I was just wondering if any of you can SQL inject this website.
As always, play safe, use a VPN when dealing with government sites, and good luck.
Sorry for posting two threads in the same section so close together
I was wondering if anyone is interested in this challenge?
So a bit of background information:
This website is by a company called evsmc
(Electric vehicle surveillance and monitoring centre) (xìnlengyūn cīche gwojiâ jianshung ji gwānli zhūngsin)
evsmc.org
Which requires every electric, bi fuel, hybrid, plugin hybrid, nuclear, and hydrogen cars in the PRC to send their following data to the company, the data sent includes: the license plate, the name and SSN( which contains all information about the owner) of the owner, the wexin id of the driver currently in the car (which allows the government to find the name and SSN), the current speed of the vehicle, the gear the transmission is in, the type of vehicle, the odometer, the electricity voltage, the amount of peripherals connected(and their id and detail) the amount of electricity charge, etc.
And all of the above data are sent to this panel real-time.
https://prnt.sc/owy5ad
I've done a bit of work, and found out their panel ip and port
http://61.149.8.148:6064/#/
And also some data without login required
http://61.149.8.148:6064/#/national
http://61.149.8.148:6064/#/breakdown/
http://61.149.8.148:6064/#/accidentAlarm
So I was just wondering if any of you can SQL inject this website.
As always, play safe, use a VPN when dealing with government sites, and good luck.
johnngnky#5687 BANNED - permed, appeal failed.
contact me exclusively using the below email.
contact@Johnngnky.xyz
contact me exclusively using the below email.
contact@Johnngnky.xyz




![[+]](https://sinister.li/images/modern/collapse_collapsed.png)













