Waraxe IT Security Portal  
  Login or Register
::  Home  ::  Search  ::  Your Account  ::  Forums  ::   Waraxe Advisories  ::  Tools  ::
March 28, 2024
Menu
 Home
 Logout
 Discussions
 Forums
 Members List
 IRC chat
 Tools
 Base64 coder
 MD5 hash
 CRC32 checksum
 ROT13 coder
 SHA-1 hash
 URL-decoder
 Sql Char Encoder
 Affiliates
 y3dips ITsec
 Md5 Cracker
 User Manuals
 AlbumNow
 Content
 Content
 Sections
 FAQ
 Top
 Info
 Feedback
 Recommend Us
 Search
 Journal
 Your Account



User Info
Welcome, Anonymous
Nickname
Password
(Register)

Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9145

People Online:
Visitors: 711
Members: 0
Total: 711
PacketStorm News
·301 Moved Permanently

read more...
Log in Register Forum FAQ Memberlist Search
IT Security and Insecurity Portal

www.waraxe.us Forum Index -> Sql injection -> some problems with mysql injection
Post new topic  Reply to topic View previous topic :: View next topic 
some problems with mysql injection
PostPosted: Mon Sep 22, 2008 2:03 pm Reply with quote
baby_1
Regular user
Regular user
 
Joined: Sep 19, 2008
Posts: 12




Hello dears
i have some problem with mysql injection so if there is no problem plz tell me solutions.


1) i found a site that i can inject mysql commands i can use INTo outfile and load_file and information_schema.user_privileges for file is good but with the load_file i only can read the "/etc/passwd" & content of that
but when i user this command load_file("/") the page show me agian the numbers (it means that load_file only shome me /etc/passwd)
now what should i do ? how can i found where im (directory)?

3)i can create a php file in the /tmp but i colud create that in /home/public because mysql show me "Can't create/write to file '/home/public/baby.php"
now agian what should i do? how can i run php file with url

4)when i use load_file to read my php file this function show me agian the numbers don't show me the content of php file.

could you give me a good arthicle about mysql injection(link for dw)

Tanx a lot
View user's profile Send private message
PostPosted: Tue Sep 23, 2008 6:22 am Reply with quote
baby_1
Regular user
Regular user
 
Joined: Sep 19, 2008
Posts: 12




Plz help me
help me
help me
help me
View user's profile Send private message
Re: some problems with mysql injection
PostPosted: Tue Sep 23, 2008 10:28 am Reply with quote
waraxe
Site admin
Site admin
 
Joined: May 11, 2004
Posts: 2407
Location: Estonia, Tartu




baby_1 wrote:
Hello dears
i have some problem with mysql injection so if there is no problem plz tell me solutions.


1) i found a site that i can inject mysql commands i can use INTo outfile and load_file and information_schema.user_privileges for file is good but with the load_file i only can read the "/etc/passwd" & content of that
but when i user this command load_file("/") the page show me agian the numbers (it means that load_file only shome me /etc/passwd)
now what should i do ? how can i found where im (directory)?

3)i can create a php file in the /tmp but i colud create that in /home/public because mysql show me "Can't create/write to file '/home/public/baby.php"
now agian what should i do? how can i run php file with url

4)when i use load_file to read my php file this function show me agian the numbers don't show me the content of php file.

could you give me a good arthicle about mysql injection(link for dw)

Tanx a lot


1. you can't list files in directory with "load_file()" Smile

2. there are security issues, called "full path disclosure". Basically you just provoke server side to issue error message, revealing full path to affected script. This is what you need.

3. not having write permissions to webroot directoy is very common problem actually. Defacers usually wanna write new index.html file to webroot, but fail to do so ...
What you need, is good php/apache/linux knowledge. Because privilege escalation is not easy task Smile

4. you can read php script source with "load_file()", right? Have you looked at html source of returned webpage??
View user's profile Send private message Send e-mail Visit poster's website
PostPosted: Tue Sep 23, 2008 12:56 pm Reply with quote
baby_1
Regular user
Regular user
 
Joined: Sep 19, 2008
Posts: 12




Excuse me sir, is there is no problem i send the target to you that you can tell me better the solutions, becuase i see the source of the page but there is no result of my php file and other things...
if you accpet plz tell me
Tanks a lot about your usefull information
View user's profile Send private message
PostPosted: Tue Sep 23, 2008 1:28 pm Reply with quote
KOODOS
Regular user
Regular user
 
Joined: Sep 23, 2008
Posts: 12




brilliant accent....its like watching a film where a foreigner tries to speak english Laughing
View user's profile Send private message
PostPosted: Wed Sep 24, 2008 10:52 am Reply with quote
baby_1
Regular user
Regular user
 
Joined: Sep 19, 2008
Posts: 12




yes , thats right , i cant speack english very well , so im sorry that i write very bad ,
View user's profile Send private message
some problems with mysql injection
  www.waraxe.us Forum Index -> Sql injection
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Post new topic  Reply to topic  




Powered by phpBB © 2001-2008 phpBB Group






Space Raider game for Android, free download - Space Raider gameplay video - Zone Raider mobile games
All logos and trademarks in this site are property of their respective owner. The comments and posts are property of their posters, all the rest (c) 2004-2020 Janek Vind "waraxe"
Page Generation: 0.128 Seconds