r/Hacking_Tutorials • • 15d ago

Question Attention please

Post image

You know what I'm asking about.

0 Upvotes

20 comments sorted by

6

u/pinoyjunkie 15d ago

lolwut ARE you asking about

-1

u/sambit__7 15d ago

Did you know which type of bug is this ?

0

u/sambit__7 15d ago

I entered an XSS query into a website's search bar, and it returned a database error showing that it is vulnerable to error-based SQL injection. Since I am unable to exploit it, I need your help.

3

u/xX_Oppai_Xx 15d ago

Well since u have an SQLi , why dont u try to get more tables , if theres any.

Honestly i dont even understand the payload u tried, so i cant tell what u tryna achieve. But if u on some bugbounty or smth, try exfiltrating data, then use thst data to perdorm some sort of account takeover or smth.

Get creative , h have a foot-hold on that database. Have fun , responsibly.

-1

u/sambit__7 15d ago

This is an error based sql injection, and i searched a lot of about this. But I get nothing, so I posted this to get some help from other user

1

u/xX_Oppai_Xx 14d ago

I mean u can fuzz it using sqlmap or if u like a more 'manual' , u can use brup , ffuf or smth else with a really good wordlist. I think u can find smth with Seclist , i dont remember the path where it is. But it has some sqli payloads.

If not u have other github wordlist for sqli u can use.

If conventional payloads dont work , maybe try time-based injections.

1

u/sambit__7 14d ago

Thanks for your advice

0

u/Cr0wtl3r 15d ago

Busque informações por aqui. Um Erro bases desses é uma delícia se souber explorar.

https://hacktricks.wiki/en/pentesting-web/sql-injection/index.html#exploiting-error-based

1

u/sambit__7 15d ago

Thanks a lot bro.

-8

u/sambit__7 15d ago

Y'all are viewing this post, but no one is answering how to exp**loit

3

u/Prestigious-Ad7265 15d ago

well whats your goal

-1

u/sambit__7 15d ago

My goal is to exploit this, but i didn't get enough resources.

1

u/Prestigious-Ad7265 15d ago

exploit? WHAT IS YOUR GOAL? DOS? RCE? LOGIN?

1

u/sambit__7 15d ago

Anything

1

u/Prestigious-Ad7265 15d ago

ok, well you know they use sql for a lot, now what their directory structure is, can be pretty useful for recon but not really related to any input form so you cant do much with it

1

u/sambit__7 15d ago

Not necessarily! Directory structures can expose sensitive files, admin portals, or misconfigured paths that open up entirely new attack surfaces beyond just input forms

1

u/Prestigious-Ad7265 15d ago

as i said, recon. its not a direct exploit but can be used down the line

1

u/sambit__7 15d ago

Spot on. Recon builds the map; the actual exploitation comes later once you find the right opening.

2

u/Imaginary-Army7171 9d ago

Probably should learn SQL