Username: 
Password: 
Restrict session to IP 

What do I DO  Go to the Training: MySQL I challenge

Global Rank: 6402
Totalscore: 1955
Posts: 8
Thanks: 5
UpVotes: 5
Registered: 1y 330d
Last Seen: 1y 302d
The User is Offline
What do I DO
Google/translate1Thank You!1Good Post!0Bad Post! link
What am I meant to do here? I've exhausted every resource I could find on SQL injection and the only thing I can get is a database error.
Global Rank: 31
Totalscore: 317623
Posts: 185
Thanks: 186
UpVotes: 209
Registered: 16y 326d
livinskull`s Avatar





Last Seen: 9h 59m
The User is Offline
RE: What do I DO
Google/translate1Thank You!2Good Post!0Bad Post! link
Maybe take your time and don't try to rush things Smile

This is based on one of the simplest SQLI techniques, which is also the most widespread thing you should find when researching.
But of course, you can't just always simply copy paste a solution and hope that it works.

A database error is a good start, actually.
Check out the source code, and look where and how you can potentially influence the query executed.
Global Rank: 6402
Totalscore: 1955
Posts: 8
Thanks: 5
UpVotes: 5
Registered: 1y 330d
Last Seen: 1y 302d
The User is Offline
RE: What do I DO
Google/translate1Thank You!1Good Post!0Bad Post! link
Yeah, uh, problem with that, I'd already tried to use the source code to come up with my own input, and uh

Didn't work, gave the error again
Global Rank: 1
Totalscore: 758744
Posts: 437
Thanks: 497
UpVotes: 470
Registered: 15y 182d












The User is Offline
RE: What do I DO
Google/translate1Thank You!2Good Post!0Bad Post! link
I'd say the best way to understand what is happening is to run the code locally. That way you can debug it a bit (e.g. add some extra output) to see what is really happening.

Now, to really run the same code locally might be a bit involved, but setting up your own webserver with PHP and SQL will be useful for more than just this challenge. If you don't want to go that far now, you can get a long way by playing with online sandboxes that are available these days. Just make sure that for SQL the sandbox is using the same language variant as the challenge is (MySQL or MariaDB).
Global Rank: 228
Totalscore: 94500
Posts: 1689
Thanks: 1363
UpVotes: 925
Registered: 16y 343d




Last Seen: 5d 1h
The User is Offline
RE: What do I DO
Google/translate0Thank You!1Good Post!0Bad Post! link
I'd break a quote for this: 'Good Luck's'!
The geeks shall inherit the properties and methods of object earth.
tunelko, jjsorianor, Redknee, silenttrack, n0tHappy, nonfungiblesecurity, quangntenemy, TheHiveMind, Z, balicocat, Ge0, samuraiblanco, arraez, jcquinterov, hophuocthinh, alfamen2, burhanudinn123, Ben_Dover, stephanduran89, braddie0, SwolloW, dangarbri, csuquvq have subscribed to this thread and receive emails on new posts.
1 people are watching the thread at the moment.
This thread has been viewed 1415 times.