Posts: 2468 Location: Brighton, UK Joined: 30.11.04 Rank: Uber Elite
Posted on 05-04-05 17:45
this is as far as i have gotten:
got the admin details (but have to use that last)
attempted SQL injection on access.php, But im guessing this is the right track, but im getting syntax errors:
You have an error in your SQL syntax. Check the manual that corresponds to your MySQL server version for the right syntax to use near 'SELECT * FROM XXXXX WHERE id=1' at line 1
yeah, i've been trying to guess a password. What i've seen with the teachers is that Ms. Jennifer Smith has an id of 20 and Ms. Yoshi James has an id of 1, yet there are only 16 teachers in the list. I've managed to find one that isn't a real id so far, and that's id=6. It's probably nothing, but you never know....
I was also able to generate the error you got Mr_Cheese, from the teacherinfo.php url.
Edited by on 07-04-05 20:41
RE: mission 7
Posts: Location: Joined: 01.01.70 Rank: Guest
Posted on 04-09-05 15:29
I can, I only don't get the table name
Hellbound Hackers is the collective work of the staff and the community and is therefore licensed under the CC BY-NC-SA license.