Exploit SQL Injection webzonegamerz Ranking

Page 1 of 3 123 LastLast
Results 1 to 15 of 37
  1. #1
    Member shark-latan is offline
    MemberRank
    May 2009 Join Date
    Veracruz de IgnLocation
    62Posts

    ! Exploit SQL Injection webzonegamerz Ranking

    This needs to be repaired urgently

    PHP Code:
    /ranking.php?Dios=&Order=LVL&Tribe=128%20declare%20@sql%20varchar(800)%20set%20@sql=0x(string to hex code)%20exec(@sql)%20select%201%20from%20Tantra..TantraBackup00%20where%201=
    Last edited by shark-latan; 01-09-14 at 04:30 AM.


  2. #2
    Enthusiast alxndr is offline
    MemberRank
    Nov 2012 Join Date
    Lima, PerúLocation
    45Posts

    Re: Exploit SQL Injection webzonegamerz Ranking

    Seems like one of my injection methods xd, try banning 'declare' word on your anti_sql.php

    - - - Updated - - -

    To see how serious it is, here is a video guys:


  3. #3
    Tantra Freelancer A v a r a is offline
    MemberRank
    Apr 2014 Join Date
    In Your HeadLocation
    554Posts

    Re: Exploit SQL Injection webzonegamerz Ranking

    Yeah seems so very serious.

  4. #4
    Member shark-latan is offline
    MemberRank
    May 2009 Join Date
    Veracruz de IgnLocation
    62Posts

    Re: Exploit SQL Injection webzonegamerz Ranking

    this is too serious, so that IP and ID of Colombia, is doing injection attacks to a server where I am working ...

    is just one of the server where the Alxndr shown in the video ...

  5. #5
    Tantra Freelancer A v a r a is offline
    MemberRank
    Apr 2014 Join Date
    In Your HeadLocation
    554Posts

    Re: Exploit SQL Injection webzonegamerz Ranking

    Quote Originally Posted by shark-latan View Post
    this is too serious, so that IP and ID of Colombia, is doing injection attacks to a server where I am working ...

    is just one of the server where the Alxndr shown in the video ...
    The server in the video is from colombia? wow!

  6. #6
    Member metan0ia is offline
    MemberRank
    Feb 2014 Join Date
    71Posts

    Re: Exploit SQL Injection webzonegamerz Ranking

    i think that server already fixed .. that sql injection

  7. #7
    Enthusiast alxndr is offline
    MemberRank
    Nov 2012 Join Date
    Lima, PerúLocation
    45Posts

    Re: Exploit SQL Injection webzonegamerz Ranking

    Quote Originally Posted by metan0ia View Post
    i think that server already fixed .. that sql injection
    I tried to help them

  8. #8
    Tantra Freelancer A v a r a is offline
    MemberRank
    Apr 2014 Join Date
    In Your HeadLocation
    554Posts

    Re: Exploit SQL Injection webzonegamerz Ranking

    I hope the owner of that server can post what he did to fix the said problem.

  9. #9
    Ronin Dev John is offline
    MemberRank
    Mar 2011 Join Date
    /dev/nullLocation
    382Posts

    Re: Exploit SQL Injection webzonegamerz Ranking

    Hahahahahahaha LOL

    $variable2 = str_replace("tobanned", "toremplaze", $variable1);

  10. #10
    Member metan0ia is offline
    MemberRank
    Feb 2014 Join Date
    71Posts

    Re: Exploit SQL Injection webzonegamerz Ranking

    @John

    sir is that the code on how to fix the sql injection problem?

  11. #11
    Ronin Dev John is offline
    MemberRank
    Mar 2011 Join Date
    /dev/nullLocation
    382Posts

    Re: Exploit SQL Injection webzonegamerz Ranking

    Quote Originally Posted by metan0ia View Post
    @John

    sir is that the code on how to fix the sql injection problem?
    No exactly, with this, they can be guided to create anti injection code.

  12. #12
    Enthusiast alxndr is offline
    MemberRank
    Nov 2012 Join Date
    Lima, PerúLocation
    45Posts

    Re: Exploit SQL Injection webzonegamerz Ranking

    People here do not want to be guided, they want the solution, lol

  13. #13
    Tantra Freelancer A v a r a is offline
    MemberRank
    Apr 2014 Join Date
    In Your HeadLocation
    554Posts

    Re: Exploit SQL Injection webzonegamerz Ranking

    Quote Originally Posted by alxndr View Post
    People here do not want to be guided, they want the solution, lol
    Yeah I agree but sometimes I really would like to help too. Better to exchange ideas.

  14. #14
    Ronin Dev John is offline
    MemberRank
    Mar 2011 Join Date
    /dev/nullLocation
    382Posts

    Re: Exploit SQL Injection webzonegamerz Ranking

    Quote Originally Posted by alxndr View Post
    People here do not want to be guided, they want the solution, lol




    You are absolutely right, it's a shame that no longer exist hungry people of know.

  15. #15
    Tantra/Web Development jbeitz107 is offline
    MemberRank
    Mar 2012 Join Date
    USALocation
    1,471Posts

    Re: Exploit SQL Injection webzonegamerz Ranking

    guys it is pretty simple to fix this issue. get rid of the get method and use post



Page 1 of 3 123 LastLast

Advertisement