Sinisterly
[HACK] Website Hacking Challenge #2 [/HACK] Difficulty - Medium - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking)
+--- Thread: [HACK] Website Hacking Challenge #2 [/HACK] Difficulty - Medium (/Thread-HACK-Website-Hacking-Challenge-2-HACK-Difficulty-Medium)



[HACK] Website Hacking Challenge #2 [/HACK] Difficulty - Medium - Crypt - 02-16-2014

I set the difficulty as medium because *usually* xpath isn't one of the first things noobs learn when getting into SQLi. That being said, if you do know xpath, this should be relatively easy.

Website -
Spoiler:
www.pushingpetals.com


Method - XPATH

Objective - Display the fourth table name onto the page as well as your name. Post a picture as proof then PM me your syntax. (If you don't pm me your syntax, I'm definitely not adding you to the solvers list.)

Proof -
Spoiler:
[Image: DsVIBq5.png]


Solvers:
BreShiE
Adorapuff


RE: [SQLI] SQLI Challenge #2 [/SQLI] Difficulty - Medium - BreShiE - 02-16-2014

I haven't found anything to do with XPATH, but I have found an SQLi. Hmm. However the SQLi does seem very similar to your page. Testing some more.

EDIT: Also the third table for me isn't "member".


RE: [SQLI] SQLI Challenge #2 [/SQLI] Difficulty - Medium - Crypt - 02-16-2014

(02-16-2014, 08:53 PM)BreShiE Wrote: I haven't found anything to do with XPATH, but I have found an SQLi. Hmm. However the SQLi does seem very similar to your page. Testing some more.

EDIT: Also the third table for me isn't "member".

Sorry fuck, it's the fourth. I just remembered the order starts at 0 and not 1. Changing that.
And if it's vulnerable to SQLi, it's most likely vulnerable to xpath. The page I did it on was vulnerable to both. So be aware of that.


RE: [SQLI] SQLI Challenge #2 [/SQLI] Difficulty - Medium - BreShiE - 02-16-2014

(02-16-2014, 08:57 PM)Crypt Wrote: Sorry fuck, it's the fourth. I just remembered the order starts at 0 and not 1. Changing that.
And if it's vulnerable to SQLi, it's most likely vulnerable to xpath. The page I did it on was vulnerable to both. So be aware of that.

I've never done XPATH Injection before so this is going to be fun. Biggrin

P.S If this IS XPATH Injection, then you may want to change the title. XPATH Injection is completely different to SQLi, however similar. Jus' sayin'


RE: [SQLI] SQLI Challenge #2 [/SQLI] Difficulty - Medium - Crypt - 02-16-2014

(02-16-2014, 09:03 PM)BreShiE Wrote: I've never done XPATH Injection before so this is going to be fun. Biggrin

P.S If this IS XPATH Injection, then you may want to change the title. XPATH Injection is completely different to SQLi, however similar. Jus' sayin'

Well for the most part they use the same concept so meh


RE: [SQLI] SQLI Challenge #2 [/SQLI] Difficulty - Medium - BreShiE - 02-16-2014

Got there eventually.

[Image: 6YLJU.png]


RE: [HACK] Website Hacking Challenge #2 [/HACK] Difficulty - Medium - Adorapuff - 02-17-2014

Took me a few minutes, so I decided to add some color for da lulz.
[Image: r20XCzJ.png]

We have a tut here on SL.
http://www.sinister.ly/thread-xpath-sql-injection-tutorial