Exploit SQL Injection webzonegamerz Ranking
This needs to be repaired urgently
PHP Code:
/ranking.php?Dios=&Order=LVL&Tribe=128%20declare%20@sql%20varchar(800)%20set%20@sql=0x(string to hex code)%20exec(@sql)%20select%201%20from%20Tantra..TantraBackup00%20where%201=1
Re: Exploit SQL Injection webzonegamerz Ranking
Seems like one of my injection methods xd, try banning 'declare' word on your anti_sql.php
- - - Updated - - -
To see how serious it is, here is a video guys:
http://youtu.be/QtA3GyevgOw
Re: Exploit SQL Injection webzonegamerz Ranking
Yeah seems so very serious.
Re: Exploit SQL Injection webzonegamerz Ranking
this is too serious, so that IP and ID of Colombia, is doing injection attacks to a server where I am working ...
is just one of the server where the Alxndr shown in the video ...
Re: Exploit SQL Injection webzonegamerz Ranking
Quote:
Originally Posted by
shark-latan
this is too serious, so that IP and ID of Colombia, is doing injection attacks to a server where I am working ...
is just one of the server where the Alxndr shown in the video ...
The server in the video is from colombia? wow!
Re: Exploit SQL Injection webzonegamerz Ranking
i think that server already fixed .. that sql injection
Re: Exploit SQL Injection webzonegamerz Ranking
Quote:
Originally Posted by
metan0ia
i think that server already fixed .. that sql injection
I tried to help them
Re: Exploit SQL Injection webzonegamerz Ranking
I hope the owner of that server can post what he did to fix the said problem.
Re: Exploit SQL Injection webzonegamerz Ranking
Hahahahahahaha LOL
Quote:
$variable2 = str_replace("tobanned", "toremplaze", $variable1);
Re: Exploit SQL Injection webzonegamerz Ranking
@John
sir is that the code on how to fix the sql injection problem?
Re: Exploit SQL Injection webzonegamerz Ranking
Quote:
Originally Posted by
metan0ia
@
John
sir is that the code on how to fix the sql injection problem?
No exactly, with this, they can be guided to create anti injection code.
Re: Exploit SQL Injection webzonegamerz Ranking
People here do not want to be guided, they want the solution, lol
Re: Exploit SQL Injection webzonegamerz Ranking
Quote:
Originally Posted by
alxndr
People here do not want to be guided, they want the solution, lol
Yeah I agree but sometimes I really would like to help too. Better to exchange ideas.
Re: Exploit SQL Injection webzonegamerz Ranking
Quote:
Originally Posted by
alxndr
People here do not want to be guided, they want the solution, lol
You are absolutely right, it's a shame that no longer exist hungry people of know.
Re: Exploit SQL Injection webzonegamerz Ranking
guys it is pretty simple to fix this issue. get rid of the get method and use post