Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

Basic 9


ghost's Avatar
0 0

I've tried putting SELECT * FROM ****_ in the login.php url but it wont work. I think it has something to do with NUL and /0 or %00 in the SQL query. CAn someone please give me a hint in the right direction


ghost's Avatar
0 0

You are in the right direction. Do you know how to use the Poison Null Byte attack?


ghost's Avatar
0 0

A little bit, i dont know where to put the SQL though.


ghost's Avatar
0 0

…:D


ghost's Avatar
0 0

I'm still stuck does anyone have any hints as to where i put the 00%