Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

Basic 18


SySTeM's Avatar
-=[TheOutlaw]=-
20 0

Basic 18 has been released for beta testing, it was made by me and is fairly hard.

You can find it: here

Comments etc would be appreciated.

People who've beaten it:

Placebo, Larika, V1P3R, hack4u, What_A_Legend, mozzer, only_samurai, AldarHawk


ghost's Avatar
0 0

grr, i'm having trouble guessing the name of the db.


SySTeM's Avatar
-=[TheOutlaw]=-
20 0

Placebo wrote: grr, i'm having trouble guessing the name of the db.

That's why it's blind xD think logically and you'll get it


ghost's Avatar
0 0

well, i have been, but maybe logic isn't on my side today. i've tried like 10 different variations of logical names but no luck.


SySTeM's Avatar
-=[TheOutlaw]=-
20 0

Placebo wrote: well, i have been, but maybe logic isn't on my side today. i've tried like 10 different variations of logical names but no luck.

PM me with what you tried


ghost's Avatar
0 0

whew

Finally got it. Nice one system, and thx for the help.


SySTeM's Avatar
-=[TheOutlaw]=-
20 0

Placebo wrote: whew

Finall got it. Nice on system, and thx for the help.

Thanks :) any improvements you could suggest?


ghost's Avatar
0 0

none that i could really suggest. how many others have beaten it so far?


ghost's Avatar
0 0

Its supposed to get some errors before guess the right sql?


ghost's Avatar
0 0

no you don't get any errors.


SySTeM's Avatar
-=[TheOutlaw]=-
20 0

Placebo wrote: none that i could really suggest. how many others have beaten it so far?

Not sure, I'll update my top post when people post they've beaten it, congrats, apart from me, you're the only one who's beaten it methinks!


ghost's Avatar
0 0

sweet. if I can think of any suggestions I'll be sure to let you know.


ghost's Avatar
0 0

can i pm what im tring?


ghost's Avatar
0 0

You can pm me if you want, or if you'd rather ask the creator that's cool too.


ghost's Avatar
0 0

thanks i got it now


SySTeM's Avatar
-=[TheOutlaw]=-
20 0

Larika wrote: thanks i got it now

Any comments on it? Improvements that could be made etc


ghost's Avatar
0 0

I think is hard "as basic challenge". Ill suggest only to make display a error whit the db name, so the people dont waste time changing db names but only tring to guess the right query. The scope is to make a blind sql injection not to guess filenames. However i found it a very good challenge. Congrats to the creator.


SySTeM's Avatar
-=[TheOutlaw]=-
20 0

You don't have to guess any filenames, you're supposed to use logic to guess the table name, which is sorta obvious as it's an article system.

This challenge is based on how I learned blind injections, where I had to guess the table etc, but if more people want it to spit an error out with the table name in, I'll consider changing it


ghost's Avatar
0 0

I got it thinking at real 4 in hts. The solution is very similar too.


ghost's Avatar
0 0

ive been looking into it. i think im having the same problem like you guys have had. i couldnt get the database of the articles.

great challenge though


SySTeM's Avatar
-=[TheOutlaw]=-
20 0

hack4u wrote: ive been looking into it. i think im having the same problem like you guys have had. i couldnt get the database of the articles.

great challenge though

You need the TABLE NAME not the db name, you already mentioned teh table name in your post.


ghost's Avatar
0 0

i done it :D

Comments On Challenge: A well made challenge, good work system :) difficulty - Medium/hard (between both lol)

The challenge is pretty good, only thing to improve is maybe a few errors. :)


ghost's Avatar
0 0

yeah finished it up.

Positives: -differnt than everything else -nice coding :P

Negatives: -some errors would help but would ruin the point of the blind part -maybe make the articles some short crappy funny things … cuz i hate just seeing Article #


SySTeM's Avatar
-=[TheOutlaw]=-
20 0

hack4u wrote: yeah finished it up.

Positives: -differnt than everything else -nice coding :P

Negatives: -some errors would help but would ruin the point of the blind part -maybe make the articles some short crappy funny things … cuz i hate just seeing Article #

I would make it show some article content, but all it does is echo the id and strip the rest of the crap out


What_A_Legend's Avatar
...Legend?
0 0

Done It.

Well I'd like to agree with all the other suggestions and the good points I like the idea of a Blind SQL injection challenge as i had no exspirence in this until now. Gave me a chance to learn something new

Good work S_M


ghost's Avatar
0 0

done and very nice. notice you didnt change anything since i helped you debug it…. lawl


AldarHawk's Avatar
The Manager
0 0

Nicely written up. The one area was a bit of a give away but what can you do eh?

Pros: New type that is yet to be done, Good backend code, nice challenge Cons: Layout is a little bland(but again it is a Basic), system got MORE points for this!

HAR HAR HAR

Nice one man.


ghost's Avatar
0 0

:( I was working on somehting liek this lol I dont htink i got the table name either. It shouldn't give it to you that just isnt blind sql.


ghost's Avatar
0 0

If you of all people can't get the table name :P

Remember that tool we worked on in the summer?