Sinisterly
Weird SQLi or False Positive? - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking)
+--- Thread: Weird SQLi or False Positive? (/Thread-Weird-SQLi-or-False-Positive)



Weird SQLi or False Positive? - whatever - 03-13-2015

This got posted on HF not long ago - rentagrandma.com/browse-grandmas.php?z=40935&r=10&j=2

What you use to trigger the error is putting \ at the end of the j or z parameters. I tried every other thing that could trigger and and nothing else works.

Apparently it's some big website so I thought I'd take a swing at it. I've tried literally every. single. SQLi method I know and no dice. I even took the time to download SQLmap on my VPS and tried it with risk 3 and level 3 and still fucking nothing.

Can anyone confirm that this is or isn't a real vulnerability that can be exploited?


RE: Weird SQLi or False Positive? - huglander - 03-13-2015

Add the extension .php.jpg to any file and the same error occurs as you get on his "shell"
http://rentagrandma.com/browse-grandmas.php.jpg
Anyways I tried too but I couldnt get anything.


RE: Weird SQLi or False Positive? - whatever - 03-13-2015

(03-13-2015, 06:41 PM)huglander Wrote: Add the extension .php.jpg to any file and the same error occurs as you get on his "shell"
http://rentagrandma.com/browse-grandmas.php.jpg
Anyways I tried too but I couldnt get anything.

That's exactly what I thought, I knew he was bullshitting too because in addition to the 512 error it also gives a small 404 near the bottom.