Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

Basic 29

ghost's Avatar
0 0

so, i can log in as all three users, but i dont really understand how i'm supposed to find the 'answer'

starofale's Avatar
0 0

I suspect you're trying a standard SQL-style injection. I know that there are some injections that only show you part of the database. If you dump the whole database the answer is pretty obvious.

From the HBHBot:

Read up on XPath and how XML works. Also, check the source. You need to work out what the injection should be specifically for this challenge - you can't use a generic one.

ghost's Avatar
0 0

I'm trying to put //* into my query to dump everything, still no luck..

Not sure if that was a spoiler <.< if it is, I'll remove it.

ghost's Avatar
0 0

Nevermind, I got it :D