Zum Inhalt wechseln

Als Gast hast du nur eingeschränkten Zugriff!


Anmelden 

Benutzerkonto erstellen

Du bist nicht angemeldet und hast somit nur einen sehr eingeschränkten Zugriff auf die Features unserer Community.
Um vollen Zugriff zu erlangen musst du dir einen Account erstellen. Der Vorgang sollte nicht länger als 1 Minute dauern.

  • Antworte auf Themen oder erstelle deine eigenen.
  • Schalte dir alle Downloads mit Highspeed & ohne Wartezeit frei.
  • Erhalte Zugriff auf alle Bereiche und entdecke interessante Inhalte.
  • Tausche dich mich anderen Usern in der Shoutbox oder via PN aus.
 

   

Foto

Help with sqli or xss

- - - - -

  • Bitte melde dich an um zu Antworten
Eine Antwort in diesem Thema

#1
saske46

saske46

    Leecher

  • Members
  • PIP
  • Likes
    0
  • 1 Beiträge
  • 0 Bedankt
Hello my friends, few days ago, for causality i found a error in a site, seems like sqli


Query failed: You have an error in your SQL syntax; check the manual corresponds to your MySQL server did version for the right syntax to use near 'AND can_sesion =' c552de646b04ee4514c06cc3d22c744 '' at line 1



But the error only Appears if you change the value of the cookie, example: PHPSESSID: c552 ** .... and i changed for PHPSESSID: C543 ** ... The error work, i try to add some values ??‹??‹before PHPSESSID: [] C543 ** .. and appers to be a sqli, but if i try other commands like + union + select + 1--, do not appers nothing.

I read a few tutorials, and maybe this is a xss?, Can any one help me "documents, videos or links" to know how to exploit did type of vul? and if this is sqli xss or, thx.

Bearbeitet von saske46, 21 September 2014 - 23:47 Uhr.


#2
ProHex

ProHex

    Hacker

  • Moderator
  • Likes
    212
  • 219 Beiträge
  • 185 Bedankt

Query failed: You have an error in your SQL syntax; check the manual corresponds to your MySQL server did version for the right syntax to use near 'AND can_sesion =' c552de646b04ee4514c06cc3d22c744 '' at line 1

an xss has nothing to do with a mysql server error.

also there could be just a problem with the implementation of the session ids - but from what i see, the error code shows a query - so it is an sql injection.

Now to the solution:

as you may know an sql injection is based on injecting sql statements into an existing query which is not properly sanitized. in this case it may be, that the query is not finished yet, which means that afterwards a query could be executed. Closing the query wouldnt help since more or less it could be an additional query in another line.

I would prefer getting more information about the site and about where you found this error. once i get these infos i can help you further.

Bearbeitet von ProHex, 22 September 2014 - 20:30 Uhr.




  Thema Forum Themenstarter Statistik Letzter Beitrag

Besucher die dieses Thema lesen:

Mitglieder: , Gäste: , unsichtbare Mitglieder:


This topic has been visited by 26 user(s)


    , AdlerRhy, auchegal, Becks, bones, Botmopp, Ch!ller, Cube, curlz, CyberFlash, DarkSky, Dr. Spic, FalkE, Framerater, gutzuu, pdr0, Platin, ProHex, rastalani, saske46, smc2014, sniffer, th30n3, Unkiii, Xenio, XoiL
Die besten Hacking Tools zum downloaden : Released, Leaked, Cracked. Größte deutschsprachige Hacker Sammlung.