Sinisterly
Does anyone could help me out with this SQL injection ? - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking)
+--- Thread: Does anyone could help me out with this SQL injection ? (/Thread-Does-anyone-could-help-me-out-with-this-SQL-injection)

Pages: 1 2


Does anyone could help me out with this SQL injection ? - kertiman06 - 05-11-2013

Hi guys,

i'm currently trying to inject some SQL from the Cookie, so here is the situation:
when I log on into the website, a cookie containing my username is created.
as fucked up as it seems, if I change that value, then i can find myself logged into the account of someone else.
anyway, thank's to that cookie, my firstname and lastname are printed on the main screen, so i guess the code is stupidly asking something like
SELECT fname, lname, andmore... FROM profil WHERE username="+thecookie+"

So i've made a script in order to launch http requests using custom GET/POST/COOKIES datas, and this is the log of my requests:

YES = my name is shown
NO = my name's blank (no result)

So, the request with cookie set as:
----cookie_user=kerti06' and '1' = '1
the result is:
==>YES

----cookie_user=kerti06' and '1' = '0
==>NO

i conclude that something is injectable, so after come test for comments (--+, # etc...), i keep going:

----cookie_user=kerti06' order by 100 #
===>NO

----cookie_user=kerti06' order by 1 #
===>YES

............after several requests:

----cookie_user=kerti06' order by 29 #
===>YES

----cookie_user=kerti06' order by 30 #
===>NO

i conclude that the number of columns is 29, but when i do:

----cookie_user=this_username_doesnt_exist' union all select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29 #
===>NO

my noob question is that why in this last request, my name is not replaced by a number between 1 and 29 ?


RE: Does anyone could help me out with this SQL injection ? - MrGeek - 05-11-2013

(05-11-2013, 04:15 PM)kertiman06 Wrote: Hi guys,
my noob question is that why in this last request, my name is not replaced by a number between 1 and 29 ?

If you post the link or PM me, I can help you to make your injections.
For now I can't clearly guess.
Mr.Geek


RE: Does anyone could help me out with this SQL injection ? - kertiman06 - 05-11-2013

Unfortunately i won't give the link, but i still need help about it
the URL is formed like that:
http://www.the_website.com/cgi-bin/the_page.cgi
i don't know may be that gives information about the laguage used, and then the database type, problably not mysql but a fucked up one with weird SQL syntaxe that could explain why my union all select doesn't work ?? i have no idea i'm just trying to figure it out


RE: Does anyone could help me out with this SQL injection ? - Linuxephus™ - 05-11-2013

(05-11-2013, 08:19 PM)kertiman06 Wrote: Unfortunately i won't give the link, but i still need help about it
the URL is formed like that:
http://www.the_website.com/cgi-bin/the_page.cgi
i don't know may be that gives information about the laguage used, and then the database type, problably not mysql but a fucked up one with weird SQL syntaxe that could explain why my union all select doesn't work ?? i have no idea i'm just trying to figure it out

Make sure you continue to use very specifically crafted words to avoid your thread being flagged as BlackHat activity which would then have to be removed from the public domain.:thumbs:


RE: Does anyone could help me out with this SQL injection ? - MrGeek - 05-12-2013

(05-11-2013, 08:19 PM)kertiman06 Wrote: Unfortunately i won't give the link, but i still need help about it
the URL is formed like that:
http://www.the_website.com/cgi-bin/the_page.cgi
i don't know may be that gives information about the laguage used, and then the database type, problably not mysql but a fucked up one with weird SQL syntaxe that could explain why my union all select doesn't work ?? i have no idea i'm just trying to figure it out

Well in that case you can PM me.
Then , I could figure a way you out.
If not, probably I can't help you :headbash:


RE: Does anyone could help me out with this SQL injection ? - kertiman06 - 05-13-2013

(05-11-2013, 10:27 PM)Linuxephus™ Wrote:
(05-11-2013, 08:19 PM)kertiman06 Wrote: Unfortunately i won't give the link, but i still need help about it
the URL is formed like that:
http://www.the_website.com/cgi-bin/the_page.cgi
i don't know may be that gives information about the laguage used, and then the database type, problably not mysql but a fucked up one with weird SQL syntaxe that could explain why my union all select doesn't work ?? i have no idea i'm just trying to figure it out

Make sure you continue to use very specifically crafted words to avoid your thread being flagged as BlackHat activity which would then have to be removed from the public domain.:thumbs:

What words did i use that could make think i'm doing any hacking activities ?

(05-12-2013, 05:11 AM)MrGeek Wrote:
(05-11-2013, 08:19 PM)kertiman06 Wrote: Unfortunately i won't give the link, but i still need help about it
the URL is formed like that:
http://www.the_website.com/cgi-bin/the_page.cgi
i don't know may be that gives information about the laguage used, and then the database type, problably not mysql but a fucked up one with weird SQL syntaxe that could explain why my union all select doesn't work ?? i have no idea i'm just trying to figure it out

Well in that case you can PM me.
Then , I could figure a way you out.
If not, probably I can't help you :headbash:

i already read the tut about social engineering, so i can't really give you the link... even in PM, do i know you ? ...
well i forgot that hacking is all about personnal, nothing sharable unless you really trust in someone. And it's well known that the hackers use the newbies for them own

anyway i will figure out how to reach my goal, there are bunch of great tut on that community


RE: Does anyone could help me out with this SQL injection ? - kertiman06 - 05-13-2013

(05-11-2013, 10:27 PM)Linuxephus™ Wrote:
(05-11-2013, 08:19 PM)kertiman06 Wrote: Unfortunately i won't give the link, but i still need help about it
the URL is formed like that:
http://www.the_website.com/cgi-bin/the_page.cgi
i don't know may be that gives information about the laguage used, and then the database type, problably not mysql but a fucked up one with weird SQL syntaxe that could explain why my union all select doesn't work ?? i have no idea i'm just trying to figure it out

Make sure you continue to use very specifically crafted words to avoid your thread being flagged as BlackHat activity which would then have to be removed from the public domain.:thumbs:

What words did i use that could make think i'm doing any hacking activities ?

(05-12-2013, 05:11 AM)MrGeek Wrote:
(05-11-2013, 08:19 PM)kertiman06 Wrote: Unfortunately i won't give the link, but i still need help about it
the URL is formed like that:
http://www.the_website.com/cgi-bin/the_page.cgi
i don't know may be that gives information about the laguage used, and then the database type, problably not mysql but a fucked up one with weird SQL syntaxe that could explain why my union all select doesn't work ?? i have no idea i'm just trying to figure it out

Well in that case you can PM me.
Then , I could figure a way you out.
If not, probably I can't help you :headbash:

i already read the tut about social engineering, so i can't really give you the link... even in PM, do i know you ? ...
well i forgot that hacking is all about personnal, nothing sharable unless you really trust in someone. And it's well known that the hackers use the newbies for them own

anyway i will figure out how to reach my goal, there are bunch of great tut on that community


RE: Does anyone could help me out with this SQL injection ? - kertiman06 - 05-13-2013

(05-11-2013, 10:27 PM)Linuxephus™ Wrote:
(05-11-2013, 08:19 PM)kertiman06 Wrote: Unfortunately i won't give the link, but i still need help about it
the URL is formed like that:
http://www.the_website.com/cgi-bin/the_page.cgi
i don't know may be that gives information about the laguage used, and then the database type, problably not mysql but a fucked up one with weird SQL syntaxe that could explain why my union all select doesn't work ?? i have no idea i'm just trying to figure it out

Make sure you continue to use very specifically crafted words to avoid your thread being flagged as BlackHat activity which would then have to be removed from the public domain.:thumbs:

What words did i use that could make think i'm doing any hacking activities ?

(05-12-2013, 05:11 AM)MrGeek Wrote:
(05-11-2013, 08:19 PM)kertiman06 Wrote: Unfortunately i won't give the link, but i still need help about it
the URL is formed like that:
http://www.the_website.com/cgi-bin/the_page.cgi
i don't know may be that gives information about the laguage used, and then the database type, problably not mysql but a fucked up one with weird SQL syntaxe that could explain why my union all select doesn't work ?? i have no idea i'm just trying to figure it out

Well in that case you can PM me.
Then , I could figure a way you out.
If not, probably I can't help you :headbash:

i already read the tut about social engineering, so i can't really give you the link... even in PM, do i know you ? ...
well i forgot that hacking is all about personnal, nothing sharable unless you really trust in someone. And it's well known that the hackers use the newbies for them own

anyway i will figure out how to reach my goal, there are bunch of great tut on that community


RE: Does anyone could help me out with this SQL injection ? - Linuxephus™ - 05-13-2013

(05-13-2013, 09:53 PM)kertiman06 Wrote: What words did i use that could make think i'm doing any hacking activities ?

Re-read the original comment, then you'll know no reference was made to you using words that reference "hacking activities", which in itself is not a problem considering that's what the Community here is for, yes?
But of course.
Rather, what was stated was for you to continue using words that would not trigger a BlackHat activities flag.
See the difference where you misunderstood and what was actually being stated?
You do?
Excellent.


RE: Does anyone could help me out with this SQL injection ? - Linuxephus™ - 05-13-2013

(05-13-2013, 09:53 PM)kertiman06 Wrote: What words did i use that could make think i'm doing any hacking activities ?

Re-read the original comment, then you'll know no reference was made to you using words that reference "hacking activities", which in itself is not a problem considering that's what the Community here is for, yes?
But of course.
Rather, what was stated was for you to continue using words that would not trigger a BlackHat activities flag.
See the difference where you misunderstood and what was actually being stated?
You do?
Excellent.