Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

Basic 8


haklite's Avatar
Member
0 0

Hi All, Ok this is my last basic challenge and its frying my head.

This is what I have so far:

?name of query=$_GET p******d FROM name of query;

Can someone give me a hint as to what im doing wrong?


ghost's Avatar
0 0

Think of a more simple query,


haklite's Avatar
Member
0 0

hmm, as in using only the query on the error page? like:

?S*T password F query found not in error

?


haklite's Avatar
Member
0 0

Anyone?


ghost's Avatar
0 0

check the source,it says how to begin your query and it's not ELET after the ? but something else. the error message,contains the actual query. the source says what to put after the ?

regards…


ghost's Avatar
0 0

you seem to be injecting more of a php/SQL hybrid….its a pure SQL injection…other than that your looking good


ghost's Avatar
0 0

ignorant banter


haklite's Avatar
Member
0 0

Can I PM someone with this? I really need help, what Im doing now Im pretty sure should work.


haklite's Avatar
Member
0 0

Never mind, I got it. Stupid spaces!!


ghost's Avatar
0 0

anyone wanna briefly explain sql? where do u inject it? password box or url? havent had any sql experiance.


ghost's Avatar
0 0

Yeah…I now have basic 1-7 done and #14. Stuck on #8 ; ;

First of all, I found "secure-area.php" but where in the heck is the "sql query?" it is in the source I think…but I don't know where ><

@_@ Lmfao, I only entered secure-area.php in the URL! I didn't enter a random string lmao. Ok I will try to continue with this…


ghost's Avatar
0 0

Hm…do we enter mr.sql in the source and save the html page? Or in the URL bar…I have never used sql before _


ghost's Avatar
0 0

ok, im a bit new to mysql but can some one give me a little hint of what i should use in the query i have been trying for weeks now and i can get any where!! :(

please help :xx:


ghost's Avatar
0 0

never mind, im am so annoyed because it was so simple!!! :angry:

anyway, for those who can't figure it out, well it has got to be the most annoying thing untill you realise that you are trying to hard :D

good luck :p


ghost's Avatar
0 0

and this is why im glad i learned sql lol


ghost's Avatar
0 0

and this is why im glad i learned sql lol