Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

Basic 9 - the right injection on the right page


ghost's Avatar
0 0

Hello,

For this challenge I have found the directory of files therefore I am trying all of them with different variations of %00.

I have been using this which is not a spoiler as it does not work although please can you tell me if it is anywhere near: ?search=search&submit=Search%00

Cheers Dyzlexik


Ingelo's Avatar
q|^.^|p - Say w00t!
0 0

<!– The Admin also said something about null or something like that, and he made a special script that it cannot be injected by the url. but i don't know what he is talking about (why dont you find out)–>


ghost's Avatar
0 0

Yeah I found that message early on in the source but cheers anyway.

Can you tell me if im anywhere near please.

Or give another clue as ive been stuck on this one for ages.

Cheers


Ingelo's Avatar
q|^.^|p - Say w00t!
0 0

Well.. You know the files there are. :) Try use the null while searching for files :)


interslice's Avatar
Member
0 0

ur on the right track.

HINT: dont use poison NULL byte in the url bar.


interslice's Avatar
Member
0 0

ur on the right track.

HINT: dont use poison NULL byte in the url bar.