SQL INJection
#6

Yes. I am already. Someone is entering on my server. I don't know how but he is admin everytime and i don't know how knows the field from database for admin. I had 'pTurbo' and i guess that he knew it if he was adding some values on it.( i have not any hidden cmd because is my gm ).

1. He can see all the password for accounts.. how ?
2. The values like pLevel = 1; must be esaped if is a dialog to set it?
3. A float must be escaped?
4. How can I see the cmd or dialog where he is injecting?
5. Thank you!
Reply


Messages In This Thread
SQL INJection - by Nin9r - 03.06.2016, 22:58
Re: SQL INJection - by SickAttack - 03.06.2016, 23:04
Re: SQL INJection - by Nin9r - 05.06.2016, 09:53
Re: SQL INJection - by Spmn - 05.06.2016, 10:46
Re: SQL INJection - by Konstantinos - 05.06.2016, 10:54
Re: SQL INJection - by Nin9r - 05.06.2016, 11:10
Re: SQL INJection - by Konstantinos - 05.06.2016, 11:19
Re: SQL INJection - by Nin9r - 05.06.2016, 11:22
Re: SQL INJection - by Noris - 05.06.2016, 15:09
Re: SQL INJection - by Nin9r - 05.06.2016, 15:24

Forum Jump:


Users browsing this thread: 1 Guest(s)