Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


[HACK] Website Hacking Challenge #2 [/HACK] Difficulty - Medium filter_list
Author
Message
[HACK] Website Hacking Challenge #2 [/HACK] Difficulty - Medium #1
I set the difficulty as medium because *usually* xpath isn't one of the first things noobs learn when getting into SQLi. That being said, if you do know xpath, this should be relatively easy.

Website -
Spoiler:
www.pushingpetals.com


Method - XPATH

Objective - Display the fourth table name onto the page as well as your name. Post a picture as proof then PM me your syntax. (If you don't pm me your syntax, I'm definitely not adding you to the solvers list.)

Proof -
Spoiler:
[Image: DsVIBq5.png]


Solvers:
BreShiE
Adorapuff
XMPP - wrath@xmpp.jp

Reply

RE: [SQLI] SQLI Challenge #2 [/SQLI] Difficulty - Medium #2
I haven't found anything to do with XPATH, but I have found an SQLi. Hmm. However the SQLi does seem very similar to your page. Testing some more.

EDIT: Also the third table for me isn't "member".
[Image: F4Z9Dqw.png]

Reply

RE: [SQLI] SQLI Challenge #2 [/SQLI] Difficulty - Medium #3
(02-16-2014, 08:53 PM)BreShiE Wrote: I haven't found anything to do with XPATH, but I have found an SQLi. Hmm. However the SQLi does seem very similar to your page. Testing some more.

EDIT: Also the third table for me isn't "member".

Sorry fuck, it's the fourth. I just remembered the order starts at 0 and not 1. Changing that.
And if it's vulnerable to SQLi, it's most likely vulnerable to xpath. The page I did it on was vulnerable to both. So be aware of that.
XMPP - wrath@xmpp.jp

Reply

RE: [SQLI] SQLI Challenge #2 [/SQLI] Difficulty - Medium #4
(02-16-2014, 08:57 PM)Crypt Wrote: Sorry fuck, it's the fourth. I just remembered the order starts at 0 and not 1. Changing that.
And if it's vulnerable to SQLi, it's most likely vulnerable to xpath. The page I did it on was vulnerable to both. So be aware of that.

I've never done XPATH Injection before so this is going to be fun. Biggrin

P.S If this IS XPATH Injection, then you may want to change the title. XPATH Injection is completely different to SQLi, however similar. Jus' sayin'
[Image: F4Z9Dqw.png]

Reply

RE: [SQLI] SQLI Challenge #2 [/SQLI] Difficulty - Medium #5
(02-16-2014, 09:03 PM)BreShiE Wrote: I've never done XPATH Injection before so this is going to be fun. Biggrin

P.S If this IS XPATH Injection, then you may want to change the title. XPATH Injection is completely different to SQLi, however similar. Jus' sayin'

Well for the most part they use the same concept so meh
XMPP - wrath@xmpp.jp

Reply

RE: [SQLI] SQLI Challenge #2 [/SQLI] Difficulty - Medium #6
Got there eventually.

[Image: 6YLJU.png]
[Image: F4Z9Dqw.png]

Reply

RE: [HACK] Website Hacking Challenge #2 [/HACK] Difficulty - Medium #7
Took me a few minutes, so I decided to add some color for da lulz.
[Image: r20XCzJ.png]

We have a tut here on SL.
http://www.sinister.ly/thread-xpath-sql-...n-tutorial
(This post was last modified: 02-17-2014, 06:23 AM by Adorapuff.)
#MakeSinisterlySexyAgain

Reply