![]() |
|
Challenge | SQL inject this website - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking) +--- Thread: Challenge | SQL inject this website (/Thread-Challenge-SQL-inject-this-website) |
Challenge | SQL inject this website - Johnngnky - 08-24-2019 Hello Sorry for posting two threads in the same section so close together I was wondering if anyone is interested in this challenge? So a bit of background information: This website is by a company called evsmc (Electric vehicle surveillance and monitoring centre) (xìnlengyūn cīche gwojiâ jianshung ji gwānli zhūngsin) evsmc.org Which requires every electric, bi fuel, hybrid, plugin hybrid, nuclear, and hydrogen cars in the PRC to send their following data to the company, the data sent includes: the license plate, the name and SSN( which contains all information about the owner) of the owner, the wexin id of the driver currently in the car (which allows the government to find the name and SSN), the current speed of the vehicle, the gear the transmission is in, the type of vehicle, the odometer, the electricity voltage, the amount of peripherals connected(and their id and detail) the amount of electricity charge, etc. And all of the above data are sent to this panel real-time. https://prnt.sc/owy5ad I've done a bit of work, and found out their panel ip and port http://61.149.8.148:6064/#/ And also some data without login required http://61.149.8.148:6064/#/national http://61.149.8.148:6064/#/breakdown/ http://61.149.8.148:6064/#/accidentAlarm So I was just wondering if any of you can SQL inject this website. As always, play safe, use a VPN when dealing with government sites, and good luck. RE: Challenge | SQL inject this website - Botany - 11-10-2019 Wow man, that is some serious stuff here, you should probably keep this all to yourself. Seriously. RE: Challenge | SQL inject this website - mothered - 11-11-2019 (08-24-2019, 02:38 PM)Johnngnky Wrote: As always, play safe, use a VPN when dealing with government sites, and good luck. There's a lot more to anonymity than just a VPN. For Instance (just briefly), encrypt your DNS servers, connect to the Tor network (Tor over VPN with a bridged connection at the entry node), disable WebRTC & WebGL, minimize canvas & font fingerprinting with at least a 1:50 ratio, exclude the 14 eyes countries at the exit node and apply VPN over Tor thereafter. There's more Involved, but this Is only a simple configuration. RE: Challenge | SQL inject this website - SickPsycko - 11-11-2019 To be fair you didn't do most the work lol. Most the work is scanning and enumeration. |