About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Technology
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it
Go Back   Community > Technology > Network (in)Security
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net.

Reply
 
Thread Tools Display Modes
 #1 
Old 2008-12-06, 03:38
Regular
 
Default SQL injection - where to go next?

I'm trying to inject this one site, and I got this interesting error message by using the classic "'or 1=1--" trick. I'm a complete noob at this, so I haven't had much success with sql injection until I did the trick above and got this error message.

MYSQL ERR:
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '_or_1=1--', PASSWORD('password'), '5f4dcc3b5aa765d61d8327deb882cf99',
'204' at line 8

Problem creating the account.
Please retry or contact the administrator.

Does this mean anything? I'm trying to fish for a password or really anything that would indicate that I can access the tables. Any tips on how to get better at this would help a lot. =)
 #2 
Old 2008-12-06, 04:19
Moderator
 
The fiber optic lines
Default Re: SQL injection - where to go next?

Kind of looks like it already spit the hash out at you. lawl. but where is the U-name?
 #3 
Old 2008-12-06, 04:43
Regular
 
Default Re: SQL injection - where to go next?

Quote:
Originally Posted by Mutant Funk Drink
I'm trying to inject this one site, and I got this interesting error message by using the classic "'or 1=1--" trick. I'm a complete noob at this, so I haven't had much success with sql injection until I did the trick above and got this error message.

MYSQL ERR:
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '_or_1=1--', PASSWORD('password'), '5f4dcc3b5aa765d61d8327deb882cf99',
'204' at line 8

Problem creating the account.
Please retry or contact the administrator.

Does this mean anything? I'm trying to fish for a password or really anything that would indicate that I can access the tables. Any tips on how to get better at this would help a lot. =)


Well the thing is, I used it on a registration page. I know that sounds stupid, but it didn't work on the login, so I figured I'd just see what would happen if I used it when registering. I used the injection as the username. The password was just 'password'. It spit out a hash, but what's the possibility that it could mean anything? And how would I go about decoding it?
 #4 
Old 2008-12-06, 06:08
Regular
 
♣♣♣♣
Default Re: SQL injection - where to go next?

Quote:
Originally Posted by Expl0itz
Kind of looks like it already spit the hash out at you. lawl. but where is the U-name?



It only hashed 'password', I assume that's what he put in the password field :p. It didn't spit out any hash that would probably correspond to an account.

If you could give me the site some way, either via IRC, aim or whatever I can check it out. I'm very good at web hacking.


Btw, edit your shit so it doesn't stretch the damn page Mad.
 #5 
Old 2008-12-06, 07:23
Regular
 
Default Re: SQL injection - where to go next?

That'd be great, Clover! I made an AIM account. The username is burzumvenom.

And sorry about the page stretching. I might try fixing it. I thought that totse used to have better wordwrapping or whatever.
 #6 
Old 2008-12-06, 21:37
Regular
 
♣♣♣♣
Default Re: SQL injection - where to go next?

Alright, I added you. My AIM is SlpCtrl.
 #7 
Old 2008-12-06, 21:46
Moderator
 
The fiber optic lines
Default Re: SQL injection - where to go next?

alright, i added you. My aim is slpctrl.

You son of a bitch!
 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
 

totse.com certificate signatures
 
 
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
Hot Topics