Sinisterly
Application of Binary search in SQLI - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Tutorials (https://sinister.li/Forum-Tutorials)
+--- Thread: Application of Binary search in SQLI (/Thread-Application-of-Binary-search-in-SQLI)

Pages: 1 2


RE: Application of Binary search in SQLI - Deque - 06-18-2013

I understood it that way and when I mentioned that some code would be nice, I didn't mean a function searching for a value in an array. That's something everyone can find with google.

I apprechiate the practical way of explaining this algorithm. But doing this manually is only the first step in understanding, if you really work on a problem like this you can go a step further and create your own script that does the binary search for you (everything else is cumbersome, a good hacker should have some lazyness when it comes to repeated tasks). So I think such a script would be a great addition to your tutorial.

Edit:
Quote:Then we try with 20. Again we get the same error. So it's between 1 and 20 as well.

50 / 2 = 25, not 20.
If you choose an arbitrary number you are not doing a binary search. Binary search always takes the element in the middle.


RE: Application of Binary search in SQLI - RogueCoder - 06-18-2013

(06-18-2013, 08:47 PM)Deque Wrote: I understood it that way and when I mentioned that some code would be nice, I didn't mean a function searching for a value in an array. That's something everyone can find with google.

I apprechiate the practical way of explaining this algorithm. But doing this manually is only the first step in understanding, if you really work on a problem like this you can go a step further and create your own script that does the binary search for you (everything else is cumbersome, a good hacker should have some lazyness when it comes to repeated tasks). So I think such a script would be a great addition to your tutorial.

Edit:
Quote:Then we try with 20. Again we get the same error. So it's between 1 and 20 as well.

50 / 2 = 25, not 20.
If you choose an arbitrary number you are not doing a binary search. Binary search always takes the element in the middle.

Yeah that's true. I use sqlmap normally, then some manual testing if sqlmap fails me. But sometimes I just like to do everything manually Smile It serves two purposes. One, it keeps my knowledge sharp, Two, it kills time when I'm bored Smile

I also fixed the error.. Changed 20 to 25 and 10 to 12


RE: Binary search algorithm - MrGeek - 06-19-2013

Well written tut mate Smile
Binary Search is very useful in Boolean-Based SQLi