Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

Basic 18


ghost's Avatar
0 0

Ok I know where to place the injections and i can prove that it is injectable, so i tried to view all the tables on the database so that i may get the table name and go from there with select * from (what i was trying to find) but it wasn't working. I was wondering how could i find out the table name and the different columns in the table and then after all of that what should i be looking for to trigger the challenge completed. Please help


ghost's Avatar
0 0

table name is, what the script pulls out…

and if udont now what columns..try NULLing it out..

Hope That Helps


ghost's Avatar
0 0

OK do i do a Union to place both the queries together? Then what about * it looks like its stripped.


ghost's Avatar
0 0

it would be better if u would PM me with what you got….


ghost's Avatar
0 0

moshbat wrote: so i need to use a n*ll instead of the table name..? Would that be logical…

read my first post..


ghost's Avatar
0 0

Do we have to get an error from the script to get that table name? i can't… I also tried with do.sys*****s but i couldn't get anything…