sandra' or 1=1 or ‘a’=‘a i have sql kownledge but i dont understand why in this sentence the a have quotes 'a’?=‘?a
btw=this is suposed to be a xpath injection
source https://www.owasp.org/index.php/XPATH_Injection
In this injection the a isn’t important you can use any string, but you need compare some values to return true, like 1=1, the quotes is just the string syntax, e.g. var='foo' or id=1
var='foo' or id=1
@bolofecal yeah i think i get that; im just curious about why this sentence the first A has two quotes and the second A just one
You might want to read up on/experiment with this subject a bit more; that should answer most basic questions.
You must know that is just part of complete code.
@bolofecal do you mean that the sentence is incomplete??
He probably means that in the context of where it is used, it make sense. Again, find out how these things work and it should be pretty clear.
Right, sorry bad english, in this thread https://www.hackthis.co.uk/forum/level-discussion/intermediate-levels/intermediate-level-6/3696-intermediate-6-help @freewind1012 post a good code that can help, view it and you will understand.
:)
thanks @bolofecal and @dloser, ill keep trying and see what happens jajaj btw @bolofecal i already saw that post, thanks for the help anyway
my spoiler is like this. i don’t know to explalin without bring the answer, but hope this can help. just implement with query string
make the logical like FALSE or TRUE or TRUE and FALSE so the logical will be like ( FALSE expression OR TRUE expression) AND (TRUE ekspression OR FALSE expression)
make the logical like FALSE or TRUE or TRUE and FALSE
so the logical will be like ( FALSE expression OR TRUE expression) AND (TRUE ekspression OR FALSE expression)
This site only uses cookies that are essential for the functionality of this website. Cookies are not used for tracking or marketing purposes.
By using our site, you acknowledge that you have read and understand our Privacy Policy, and Terms of Service.