Welcome to HBH! If you had an account on hellboundhacker.org you will need to reset your password using the Lost Password system before you will be able to login.

Basic 8 **Spoiler** Maybe


ghost's Avatar
0 0

I've been banging my head against the wall pretty much all day on Basic 8. I've read posts years back and articles all which helped a little. I understand I'm suppose to put the SQL injection in the URL of the secure page. This is what I've been trying (it's blacked out):

Thou shalt not spoil

I have tried a lot of different variations of this. I took out the GET, I took out the FROM. A lot of posts said to make it shorter more broad. I've tried password='*' or 'a' instead of username. I have no idea if I'm on the right track or not. Please Help! Thanks


ghost's Avatar
0 0

A little bit, I don't know SQL just from Articles and Posts I've read.


yours31f's Avatar
Retired
10 0

you can pm me.


ghost's Avatar
0 0

You are right. I have already printed out an SQL intro to read. I hate reading for along time on the monitor. But I just want to finish this challenge if possible, or maybe just a screw driver threw my LCD.


ghost's Avatar
0 0

This is what I have now:

They want me to remove it, I don't know why, because it does not work anyway'

Anyone have any suggestions or tips.

Thanks


ghost's Avatar
0 0

moshbat wrote: There's no point telling where to look.

??????????????????????????????????????


yours31f's Avatar
Retired
10 0

moshbat wrote: Please remove the query.


ghost's Avatar
0 0

I thought you were going to bed? yours31f


ghost's Avatar
0 0

moshbat wrote: *There is no point telling it where to look. Typo, sorry.

I'll try that, Thanks


ghost's Avatar
0 0

@topic starter -> remove the query in your first post dude.It is nearly the complete answer. :right:


ghost's Avatar
0 0

I read up on some SQL and managed to figure out Basic 8.

I was putting a space inbetween '=SELECT' That was one thing throwing me off. And the other was I read on one of the post that you don't need the FROM Clause, which you do. And there is no semi colin at the end. Monitors should edit bad advice, it's worse than spoilers. Basically you just select all colums from the family_db table. Thanks for the help, everyone who help me.