Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

basic 9


ghost's Avatar
0 0

i finshed this challenge now without fully understanding it…. I couldnt find a good page on PNB so i injected the pnb to the right spot and got to the messed up script and i beet the challenge but i wanna no why the cereten string worked!!! that couldnt of been a real pnb attack right because would be injecting that really take me to the good job page contunue on?


ghost's Avatar
0 0

Two things, thats a bug and thats a spoiler


ghost's Avatar
0 0

im still lost


ghost's Avatar
0 0

The file is correct, but there is no need 4 SQL injection here!

You have to use Poison NULL on this file.

If you dont know what it is…. then…. Google it! (as always)


Uber0n's Avatar
Member
0 0

Yes.. This is really simple, don't make it too complicated :happy:


ghost's Avatar
0 0

i cant find and good tutorails i only no what it does not how to use it i keep finding garbage article


alfredwolf's Avatar
Member
0 0

think about what it says you can use the null byte in the url so where would you place it. come on it's on the page that searches for files.


ghost's Avatar
0 0

ok i just beet it but im wonder y pnb worked can i pm some1


ghost's Avatar
0 0

i did a search on google for "poisen null", and i came up with nothing. can someone be little bit more specific as to what i should google? thx in advanced


ghost's Avatar
0 0

never mind, i just got the misison. this is a very good one, seeing as it introduces a new type of exploit :)


Uber0n's Avatar
Member
0 0

remotec2 wrote: i did a search on google for "poisen null", and i came up with nothing. can someone be little bit more specific as to what i should google? thx in advanced

It's spelled "poison", maybe that's why you didn't get anything :p