![]() |
|
Weird SQLi or False Positive? - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking) +--- Thread: Weird SQLi or False Positive? (/Thread-Weird-SQLi-or-False-Positive) |
Weird SQLi or False Positive? - whatever - 03-13-2015 This got posted on HF not long ago - rentagrandma.com/browse-grandmas.php?z=40935&r=10&j=2 What you use to trigger the error is putting \ at the end of the j or z parameters. I tried every other thing that could trigger and and nothing else works. Apparently it's some big website so I thought I'd take a swing at it. I've tried literally every. single. SQLi method I know and no dice. I even took the time to download SQLmap on my VPS and tried it with risk 3 and level 3 and still fucking nothing. Can anyone confirm that this is or isn't a real vulnerability that can be exploited? RE: Weird SQLi or False Positive? - huglander - 03-13-2015 Add the extension .php.jpg to any file and the same error occurs as you get on his "shell" http://rentagrandma.com/browse-grandmas.php.jpg Anyways I tried too but I couldnt get anything. RE: Weird SQLi or False Positive? - whatever - 03-13-2015 (03-13-2015, 06:41 PM)huglander Wrote: Add the extension .php.jpg to any file and the same error occurs as you get on his "shell" That's exactly what I thought, I knew he was bullshitting too because in addition to the 512 error it also gives a small 404 near the bottom. |