TryThis0ne >> Challenges >> Realistic
tt0 forum
Viewers: :
Quick reply
Reply
New Topic
 
Avidor93




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 65




Top
Sent on: 26/09/2005, 22:01:22 Reply | Quote | Warn | Edit
i registred - then i dont now what to do.
in the cookie there is nothing...
only user and pass that not help me much...
i am stuck...
any hint?

cp77fk4r
Global Admin



AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 621




Send Email Top
Sent on: 26/09/2005, 22:30:03 Reply | Quote | Warn | Edit
Try to think, how the system know what your rank?
- the system read it from a DataBase.

Try to think how can you change values in the DataBase.

Avidor93




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 65




Top
Sent on: 26/09/2005, 22:34:45 Reply | Quote | Warn | Edit
hmm , i really dont now!!!!
i need to now where is the datebase - but i dont now.
if i want to inject it something - can i do this on the register or something?

cp77fk4r
Global Admin



AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 621




Send Email Top
Sent on: 26/09/2005, 22:51:39 Reply | Quote | Warn | Edit
You don't need to know where the DataBase located, the Query know that and you just need to find some exploitable query :)

good luck!

Avidor93




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 65




Top
Sent on: 26/09/2005, 23:07:49 Reply | Quote | Warn | Edit
hmm - what do you mean - so i can change the value in?
look i try everything - on reg page there is only a form with user password mail
on login
user password
on forum nothing
on control panel -
nothing.

cp77fk4r
Global Admin



AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 621




Send Email Top
Sent on: 27/09/2005, 01:12:45 Reply | Quote | Warn | Edit
everything? it's not seems like that.

Inj3ction




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 102




Send Email Top
Sent on: 27/09/2005, 02:00:21 Reply | Quote | Warn | Edit
Ever heard about sql-injection?

Avidor93




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 65




Top
Sent on: 27/09/2005, 15:25:16 Reply | Quote | Warn | Edit
lets say I am not so good in that..
i mean i thing i will get it
when i learn sql lang...
but anyway ....

how do i do it ?
if i want to inject the login page :
user : admin
pass : a" or 1==1 or "b ?
and how do i not what the table of the level?
i do :
a" or 1==1 and level=1 --
something like that ?
if the name of level table is something else?

cp77fk4r
Global Admin



AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 621




Send Email Top
Sent on: 27/09/2005, 16:05:03 Reply | Quote | Warn | Edit
plus minus, you need to learn SQL.

try to read that :
http://www.unixwiz.net/techtips/sql-injection.html

Avidor93




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 65




Top
Sent on: 27/09/2005, 16:32:22 Reply | Quote | Warn | Edit
edit , READ THE RULES , DO NOT POST ANY OF THE LEVELS PASSWORDS OR THE SOULUTIONS !

this time , its a warnning , next time it will be a BANN..

Edit by : codingr At 27/09/2005, 14:38:15

Avidor93




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 65




Top
Sent on: 27/09/2005, 17:33:58 Reply | Quote | Warn | Edit
Sorry....

shaman66




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 23




Send Email Top
Sent on: 27/09/2005, 18:00:29 Reply | Quote | Warn | Edit
Muahahahaha
It was so freakin' easy after reading that article about injections :D

cp77fk4r
Global Admin



AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 621




Send Email Top
Sent on: 27/09/2005, 18:05:22 Reply | Quote | Warn | Edit
good job! this is the goal of this challenges! to learn :)

pro 1337




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 11




Send Email Top
Sent on: 28/09/2005, 00:28:26 Reply | Quote | Warn | Edit
Too hard to understand this text :>
i'll search 1 like this in hebrow...

but tnx for the hint(sql inj)!

cp77fk4r
Global Admin



AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 621




Send Email Top
Sent on: 28/09/2005, 00:58:05 Reply | Quote | Warn | Edit
If you don't understand the english- try to look at the examples and understand by that.

gitterrost4




AVATAR



Registerd on: 01/01/1970, 04:00:00
Location::
Posts: 3




Send Email Top
Sent on: 04/05/2006, 05:52:27 Reply | Quote | Warn | Edit
I read the whole article about SQL injection and I tried to do it, but there was no reaction at all.
Do i have to insert the code in the address field of my browser?
If yes, I can't find on which page to insert it.

All the times are GMT+2, ISRAEL
TryThis0ne >> Challenges >> Realistic

Quick reply
Reply
New Topic


Page generated using: 12 queries
Design by SBD © GeHeNoM.Net | Powered By Tera-Byte Forums 1.5 © JonJon & HLL
ý