Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Quick SQL Question filter_list
Author
Message
Quick SQL Question #1
Hey guys, i have a quick question. Is there a way download files by using sql injection.? i know a little about it, well enough to gain access to websites and view their files etc etc but i recently came across a site and found a few documents i wouldnt mind taking a look at so if any one here knows the methods then i would very much appreciate the help or simply point me to a tutorial ( i like reading them lol ) thanks in advance =]

Reply

RE: Quick SQL Question #2
Hey, I think function load_file() could help you. I don't know much about it, so here is a part of tutorial from ah forum:
Quote:There is a function called load_file() in mysql, which u can use directly after you found a number of columns. For eg. If you know that website you are playing with is using Joomla, then you also know that file that saves username, passwords of admin/database and even salt to taste is in configurations.php. using load_file, all you have to do is, give a pathname /home/blah blah (that is upto you to figure out) and load configurations.php. Any php file loaded without a request HTTP or HTTPS header, will show the file in its TEXT form and not embedded Once you see the file using load_file(path to config file),3,4.. etc.. There is nothing much left to say.

Check google for some tutorials about it.

Reply

RE: Quick SQL Question #3
To download actual files off a server you are going to need to get root access. If you can do that you have all the files possible. I do not believe you can obtain files via SQLi because that just gets information from databases files.
[username], need some help?, PM me.
[Image: kjKks6Y.png]

Reply

RE: Quick SQL Question #4
thanks to both of you for your replys, just found a pdf tutorial which shows how to use the load_file function so ill give it a go and see what i can do Smile thanks once again guys, much appreciated.

Reply