Waraxe IT Security Portal
Login or Register
August 11, 2025
Menu
Home
Logout
Discussions
Forums
Members List
IRC chat
Tools
Base64 coder
MD5 hash
CRC32 checksum
ROT13 coder
SHA-1 hash
URL-decoder
Sql Char Encoder
Affiliates
y3dips ITsec
Md5 Cracker
User Manuals
AlbumNow
Content
Content
Sections
FAQ
Top
Info
Feedback
Recommend Us
Search
Journal
Your Account
User Info
Welcome, Anonymous
Nickname
Password
(Register)

Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144

People Online:
Visitors: 4197
Members: 0
Total: 4197
Full disclosure
Defense in depth -- the Microsoft way (part 91): yet another30 year old bug of the "Properties" shell extension
Rtpengine: RTP Inject and RTP Bleed vulnerabilities despite proper configuration (CVSS v4.0 Score: 9.3 / Critical)
APPLE-SA-07-30-2025-1 Safari 18.6
Defense in depth -- the Microsoft way (part 90): "DigitalSignature" property sheet missing without "Read ExtendedAttributes" access permission
St. Pölten UAS 20250721-0 | Multiple Vulnerabilities in Helmholz Industrial Router REX100 / mbNET.mini
APPLE-SA-07-29-2025-8 visionOS 2.6
APPLE-SA-07-29-2025-7 tvOS 18.6
APPLE-SA-07-29-2025-6 watchOS 11.6
APPLE-SA-07-29-2025-5 macOS Ventura 13.7.7
APPLE-SA-07-29-2025-4 macOS Sonoma 14.7.7
APPLE-SA-07-29-2025-3 macOS Sequoia 15.6
APPLE-SA-07-29-2025-2 iPadOS 17.7.9
APPLE-SA-07-29-2025-1 iOS 18.6 and iPadOS 18.6
Invision Community <= 4.7.20 (calendar/view.php) SQL InjectionVulnerability
CVE?2025?52187 – Stored XSS in School Management System (PHP/MySQL)
Log in Register Forum FAQ Memberlist Search
IT Security and Insecurity Portal

www.waraxe.us Forum Index -> Sql injection -> how to Do Insert
Post new topicReply to topic View previous topic :: View next topic
how to Do Insert
PostPosted: Fri Oct 31, 2008 7:47 pm Reply with quote
fadai
Regular user
Regular user
Joined: Oct 30, 2008
Posts: 11




Code:
pages.php?pId=-1'+UNION+SELECT+ALL+1,UNHEX(HEX(CONCAT(username,0x5e,password,0x5e))),3,4,UNHEX(HEX(username)),6+from+ias_users--+



gives me the MD5 hash and username i am unable to crack the hash.

so can some one tell me how to do the INSERT a username and password?
View user's profile Send private message
PostPosted: Fri Oct 31, 2008 7:55 pm Reply with quote
waraxe
Site admin
Site admin
Joined: May 11, 2004
Posts: 2407
Location: Estonia, Tartu




In case of mysql you can INSERT only if injection occurs in INSERT query, UPDATE is possible in vulnerable UPDATE query and so on ...
But i suggest to seach for possible sessions table in database. Some websites are based purely on php session management, but many others are using their own session handling. So if you find session table and can fetch admin's session ID, then session hijack may be possible, if there is no other security measures (like fixation to IP) in place ...
View user's profile Send private message Send e-mail Visit poster's website
how to Do Insert
www.waraxe.us Forum Index -> Sql injection
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT
Page 1 of 1

Post new topicReply to topic


Powered by phpBB © 2001-2008 phpBB Group



PCWizardHub - Helping you fix, build, and optimize your PC life
All logos and trademarks in this site are property of their respective owner. The comments and posts are property of their posters, all the rest (c) 2004-2024 Janek Vind "waraxe"
Page Generation: 0.027 Seconds