Login Register






The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.
Thread Rating:
  • 0 Vote(s) - 0 Average


How to hack this error? filter_list
Author
Message
How to hack this error? #1
Hi,

When I check SQli with ' i get error for SQLi but when I order by 1-- there is no error

http://example/product_info.php?Path=25_35&products_id=31251'

The error:

You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '31251' and pd.language_id = '1' and p.products_status=1' at line 1
select p.products_id, pd.products_name, pd.products_description, p.products_model, p.products_quantity, p.products_image, pd.products_url, p.products_price, p.products_tax_class_id, p.products_date_added, p.products_image_xl_6, p.products_date_available, p.manufacturers_id from products p, products_description pd where p.products_id = '31251\' and pd.products_id = '31251' and pd.language_id = '1' and p.products_status=1

How I can hack with that?

Reply

RE: How to hack this error? #2
Follow this tutorial it might help you.
http://www.hackcommunity.com/Thread-Tuto...-Injection

Reply

RE: How to hack this error? #3
(02-19-2013, 11:45 AM)τhε.τhinkεr Wrote: Follow this tutorial it might help you.
http://www.hackcommunity.com/Thread-Tuto...-Injection

I follow already but when i use order by 1-- it redirect to homepage.

Reply

RE: How to hack this error? #4
(02-19-2013, 04:01 PM)blackcobra Wrote:
(02-19-2013, 11:45 AM)τhε.τhinkεr Wrote: Follow this tutorial it might help you.
http://www.hackcommunity.com/Thread-Tuto...-Injection

I follow already but when i use order by 1-- it redirect to homepage.

Did you try order by 2--;3--;4--...?

Reply

RE: How to hack this error? #5
(02-19-2013, 06:48 PM)τhε.τhinkεr Wrote:
(02-19-2013, 04:01 PM)blackcobra Wrote:
(02-19-2013, 11:45 AM)τhε.τhinkεr Wrote: Follow this tutorial it might help you.
http://www.hackcommunity.com/Thread-Tuto...-Injection

I follow already but when i use order by 1-- it redirect to homepage.

Did you try order by 2--;3--;4--...?

I tried it already but still redirect to homepage. Do u know anthor method to bypass?

Thanks

Reply

RE: How to hack this error? #6
Nope bro sorry, but you can always PM 1llusion, V1P3R, Wild Hacker etc. maybe they can help you.

Reply

RE: How to hack this error? #7
Hi,

there are multiple kinds of SQL injection. The guide explains just one, look up error based SQL injection. Also, there is a difference between injecting an integer value or a string and also there is a difference between ' and ".
I'm not a master of SQLi so these are my two cents.
Staff will never ever ask you for your personal information.
We know everything about you anyway.

Reply

RE: How to hack this error? #8
Hi,

there are multiple kinds of SQL injection. The guide explains just one, look up error based SQL injection. Also, there is a difference between injecting an integer value or a string and also there is a difference between ' and ".
I'm not a master of SQLi so these are my two cents.
Staff will never ever ask you for your personal information.
We know everything about you anyway.

Reply

RE: How to hack this error? #9
(02-20-2013, 08:22 PM)τhε.τhinkεr Wrote: Nope bro sorry, but you can always PM 1llusion, V1P3R, Wild Hacker etc. maybe they can help you.
PM via skype or yahoo?

Reply

RE: How to hack this error? #10
(02-20-2013, 08:22 PM)τhε.τhinkεr Wrote: Nope bro sorry, but you can always PM 1llusion, V1P3R, Wild Hacker etc. maybe they can help you.
PM via skype or yahoo?

Reply







Users browsing this thread: 1 Guest(s)