Thisislegal.com
:[ Offline ]:

welcome, please log-in:




 Remember Me  ?
About: Remember Me
Ticking this box will make the site remember you for 24 hours. However, each time you visit the site this time is renewed, so if you are a regular visitor you will stay logged in.


Register An Account
Forgot Password?

:[ Forums ]:
Latest Post In:
Challenge Help
Topic:
Challenge 5
By:
Tiffyish
:[ Like ]:
:[ Alexa ]:
 
:[ Forums ]:
 Thisislegal ForumsChallenge Help → SQL injection 2

Topic: SQL injection 2
Pages:
1
2
3
4
5
6
7
8
9
10
  Author:  Message:
BuRNeD
Offline
Forum Rank: Active User
rankrankrankrank
avatar
Posts: 112
Thanks: 14
Moderator

thank
This is the wrong way... Try testing the first way you tried. The 1/2 of the challenge is no big deal. Read again the posts from the beggining this might help.

SPOILER:SQL Challenge 1 very similiar


P.S: Posts from this topic only help if you have done the 1/2 of this challenge so you don't need them for now. You'll need them after you log in. (2/2)

  #21   Back To Top
t0mmy9
Offline
Forum Rank: 1337
rankrankrankrankrank
avatar
Posts: 395
Thanks: 75
Administrator

thank
xyberz09, that is about 70% correct - good job.

As BuRNeD says, this is similar to the first SQL, so you have to think about merging the first SQL solution and more to complete this part of the challenge


SPOILER:think what could be added after the "or" in your SQL

Signatures added! go to my account to add your own
  #22   Back To Top
xyberz09
Offline
Forum Rank: Contributor
rankrankrank
avatar
Posts: 50
Thanks: 9
Contributor
  Users email address is on profile page
thank
@BuRNeD: I've already completed the first SQL challenge. That's was wayyyy too easy. And I think I've also completed 1/2 of this chall

(I get this text: Logged in as us3r.



Due to some unexplained break-ins recently to this site, we have added an extra feature to prove you are the owner of this account.)

So I guess I'm doing something wrong after I log in :|



@t0mmy9: You're asking me to merge the 1st SQL solution and something more for this chall. I get that. But my question is do I have to do this is the while logging in or after that?





PS: By thew way, It's getting a little confusing as to where to inject the malicious SQL. At the login prompt? When I'm logged in as us3r? Or when I logout and login again as admin?
  #23   Back To Top
t0mmy9
Offline
Forum Rank: 1337
rankrankrankrankrank
avatar
Posts: 395
Thanks: 75
Administrator

thank
Yeh it is supposed to be confusing.


SPOILER:its all from the login box

Signatures added! go to my account to add your own
  #24   Back To Top
fred777
Offline
Forum Rank: n00b
rank
avatar
Posts: 5
Thanks: 2
Standard User

thank
Yes its a normal sql injection, and you can add your select-query with UNION.
  #25   Back To Top
Pages:
5

Locked.



Online (last 15 mins): snarewolf, metallover

DareYourMind   WeChall.net   Thenetsend.info   Powered by CloudFlare   Download Firefox   Opera Web Browser
Valid XHTML 1.0 Transitional
Home | Challenges | Forums | Contact | About (Disclaimer)
Copyright © 2007-12 Thisislegal.com, All Rights Reserved.


:[ ShoutBox ]:
Guest - Login to post comments


shoutbox bot:
no more proxy
iS33stars:
It helps if you read the tutorials before you attempt a challenge.
howboutdemboyzz:
wheres the proxy they offer?
mejizz420:
uh... i got lucky with the first challenge... dont really get the second challenge..
Nutu2000:
man, what are you doing here if you can't look at the source code of a web page?
adapt760:
whts the pass word for the 1st challenege
zurenarrh:
Nobody really uses the forums :/
Pages: 1, 2...343
Goto:
 
0.403 sec