Welcome to HBH! If you had an account on hellboundhacker.org you will need to reset your password using the Lost Password system before you will be able to login.

Ok this is just confusing to me (basic 8)


ghost's Avatar
0 0

Ok I've tried like 12 different injections into every concieveable place you can inject. People on the forums say to make it broader but I don't think you can get much more broad than:

[removed - spoilers]

Or more broad:

SELECT * FROM * WHERE username='Drake'

Unless possibly this would work:

SELECT * FROM *

Or why not, let's try:

SELECT *

I found the error (and hence the table) and feel free to yell at me in case any of those are spoilers and the reason they don't work is because they just don't like me.


ghost's Avatar
0 0

lol this is another UNREALISTIC challenge…


ghost's Avatar
0 0

Well, you're just not injecting it into the right place. How about checking the source before or after any injection.


ghost's Avatar
0 0

Still doesn't make sense. Yes I've looked at the source, and yes I've tried interjecting everywhere on the page with the exception of the HBH login form.

One moment.

Nope, didn't work.

Why don't any of the other injections work?


ghost's Avatar
0 0

You have to use some logic when viewing the source of a certain page of this challenge. A hint, look at the url right now. Do you see the .php?something=? Think about that while looking at the source.