Jump to content
EH808

ELearnSecurity Exams

Recommended Posts

ticketID--- sqli sleep . You can use sqlmap

Do you need more?

Share this post


Link to post
Share on other sites

sqlmap -r port_request --dbs --dbms mysql

It will show you everything.

Share this post


Link to post
Share on other sites

look at support.php

You will have access to server 🙂

If you ask me a precise question, I'll answer you. I don't want to spoil the fun of writing everthing. But I will answer for your questions

Share this post


Link to post
Share on other sites

I don't remember exactly but you need create ticket

Share this post


Link to post
Share on other sites

@igoj i'm on the ewapt. I exploited the SQLi and gain access to the MySQL server but it doesn't contain login credentials. Where i can search for the admin credentials? Thanks a lot!

Share this post


Link to post
Share on other sites

this sqli give you evething you looking for ... you can see everthing what is in db

test / password1234

Share this post


Link to post
Share on other sites
5 minutes ago, cipher15 said:

hello bro 🙂 me too 😞

I exploited the sql injection vuln in the User-Agent for the get_visitor.php on the domain but inside the MySQL there isn't a table with credentials. Which subdomain you found? Just to check 😉

Share this post


Link to post
Share on other sites
Just now, cipher15 said:

Yeaa bro that was not it. @igojis talking about. the other sqli vuln bro.

 

Ah ok i'm asking if someone found the credentials on the db by exploiting the User-Agent vuln. If you want, we can proceed together, write to me a PM.

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...