forked from Audi-1/sqli-labs
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Adding modules on Stacked Queries Less-38,39,40,41,42,43,44,45
- Loading branch information
Showing
110 changed files
with
1,832 additions
and
344 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,61 +1,92 @@ | ||
<?PHP | ||
session_start(); | ||
if (isset($_SESSION['username']) && isset($_COOKIE['Auth'])) { | ||
header('Location: logged-in.php'); | ||
} | ||
?> | ||
<?php | ||
//including the Mysql connect parameters. | ||
include("../sql-connections/sql-connect.php"); | ||
?> | ||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" > | ||
<html> | ||
<head> | ||
<meta http-equiv="content-type" content="text/html; charset=ISO-8859-1"> | ||
<title>Less-40 - Stacked based Query </title> | ||
</head> | ||
<body bgcolor="#000000"> | ||
|
||
<div style="text-align:center"> | ||
<form name="login" method="POST" action="login.php"> | ||
|
||
<h2 style="text-align:center;background-image:url('../images/Less-40.jpg');background-repeat:no-repeat;background-position:center center"> | ||
<div style="padding-top:300px;text-align:center;color:#FFFF00;"><?php echo $form_title_in; ?></div> | ||
</h2> | ||
|
||
<div align="center"> | ||
<table style="margin-top:50px;"> | ||
<tr> | ||
<td style="text-align:right"> | ||
<font size="3" color="#FFFF00"> | ||
<strong>Username:</strong> | ||
</td> | ||
<td style="text-align:left"> | ||
<input name="login_user" id="login_user" type="text" value="" /> | ||
</td> | ||
</tr> | ||
<tr> | ||
<td style="text-align:right"> | ||
<font size="3" color="#FFFF00"> | ||
<strong>Password:</strong> | ||
</td> | ||
<td style="text-align:left"> | ||
<input name="login_password" id="login_password" type="password" value="" /> | ||
</td> | ||
</tr> | ||
<tr> | ||
<td colspan="2" style="text-align:right"> | ||
<input name="mysubmit" id="mysubmit" type="submit" value="Login" /><br/><br/> | ||
|
||
<a style="font-size:.8em;color:#FFFF00" href="forgot_password.php">Forgot your password?</a><font size="3" color="#FFFF00"> | ||
||</font> | ||
<a style="font-size:.8em;color:#FFFF00" href="new_user.php">New User click here?</a> | ||
</td> | ||
</tr> | ||
|
||
</table> | ||
</div> | ||
</form> | ||
</div> | ||
</body> | ||
</html> | ||
<?php | ||
error_reporting(0); | ||
include("../sql-connections/db-creds.inc"); | ||
?> | ||
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> | ||
<html xmlns="http://www.w3.org/1999/xhtml"> | ||
<head> | ||
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> | ||
<title>Less-40 **stacked Query String type Blind**</title> | ||
</head> | ||
|
||
<body bgcolor="#000000"> | ||
<div style=" margin-top:70px;color:#FFF; font-size:23px; text-align:center">Welcome <font color="#FF0000"> Dhakkan </font><br> | ||
<font size="3" color="#FFFF00"> | ||
|
||
|
||
<?php | ||
|
||
|
||
|
||
|
||
// take the variables | ||
if(isset($_GET['id'])) | ||
{ | ||
$id=$_GET['id']; | ||
//logging the connection parameters to a file for analysis. | ||
$fp=fopen('result.txt','a'); | ||
fwrite($fp,'ID:'.$id."\n"); | ||
fclose($fp); | ||
|
||
// connectivity | ||
//mysql connections for stacked query examples. | ||
$con1 = mysqli_connect($host,$dbuser,$dbpass,$dbname); | ||
// Check connection | ||
if (mysqli_connect_errno($con1)) | ||
{ | ||
echo "Failed to connect to MySQL: " . mysqli_connect_error(); | ||
} | ||
else | ||
{ | ||
@mysqli_select_db($con1, $dbname) or die ( "Unable to connect to the database: $dbname"); | ||
} | ||
|
||
|
||
|
||
$sql="SELECT * FROM users WHERE id=('$id') LIMIT 0,1"; | ||
/* execute multi query */ | ||
if (mysqli_multi_query($con1, $sql)) | ||
{ | ||
|
||
|
||
/* store first result set */ | ||
if ($result = mysqli_store_result($con1)) | ||
{ | ||
if($row = mysqli_fetch_row($result)) | ||
{ | ||
echo '<font size = "5" color= "#00FF00">'; | ||
printf("Your Username is : %s", $row[1]); | ||
echo "<br>"; | ||
printf("Your Password is : %s", $row[2]); | ||
echo "<br>"; | ||
echo "</font>"; | ||
} | ||
// mysqli_free_result($result); | ||
} | ||
/* print divider */ | ||
if (mysqli_more_results($con1)) | ||
{ | ||
//printf("-----------------\n"); | ||
} | ||
//while (mysqli_next_result($con1)); | ||
} | ||
|
||
|
||
/* close connection */ | ||
mysqli_close($con1); | ||
|
||
|
||
} | ||
else { echo "Please input the ID as parameter with numeric value";} | ||
|
||
?> | ||
</font> </div></br></br></br><center> | ||
<img src="../images/Less-40.jpg" /></center> | ||
</body> | ||
</html> | ||
|
||
|
||
|
||
|
||
|
||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,92 +1,92 @@ | ||
<?php | ||
error_reporting(0); | ||
include("../sql-connections/db-creds.inc"); | ||
?> | ||
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> | ||
<html xmlns="http://www.w3.org/1999/xhtml"> | ||
<head> | ||
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> | ||
<title>Less-41 **stacked Query String type Blind**</title> | ||
</head> | ||
|
||
<body bgcolor="#000000"> | ||
<div style=" margin-top:70px;color:#FFF; font-size:23px; text-align:center">Welcome <font color="#FF0000"> Dhakkan </font><br> | ||
<font size="3" color="#FFFF00"> | ||
|
||
|
||
<?php | ||
|
||
|
||
|
||
|
||
// take the variables | ||
if(isset($_GET['id'])) | ||
{ | ||
$id=$_GET['id']; | ||
//logging the connection parameters to a file for analysis. | ||
$fp=fopen('result.txt','a'); | ||
fwrite($fp,'ID:'.$id."\n"); | ||
fclose($fp); | ||
|
||
// connectivity | ||
//mysql connections for stacked query examples. | ||
$con1 = mysqli_connect($host,$dbuser,$dbpass,$dbname); | ||
// Check connection | ||
if (mysqli_connect_errno($con1)) | ||
{ | ||
echo "Failed to connect to MySQL: " . mysqli_connect_error(); | ||
} | ||
else | ||
{ | ||
@mysqli_select_db($con1, $dbname) or die ( "Unable to connect to the database: $dbname"); | ||
} | ||
|
||
|
||
|
||
$sql="SELECT * FROM users WHERE id=('$id') LIMIT 0,1"; | ||
/* execute multi query */ | ||
if (mysqli_multi_query($con1, $sql)) | ||
{ | ||
|
||
|
||
/* store first result set */ | ||
if ($result = mysqli_store_result($con1)) | ||
{ | ||
if($row = mysqli_fetch_row($result)) | ||
{ | ||
echo '<font size = "5" color= "#00FF00">'; | ||
printf("Your Username is : %s", $row[1]); | ||
echo "<br>"; | ||
printf("Your Password is : %s", $row[2]); | ||
echo "<br>"; | ||
echo "</font>"; | ||
} | ||
// mysqli_free_result($result); | ||
} | ||
/* print divider */ | ||
if (mysqli_more_results($con1)) | ||
{ | ||
//printf("-----------------\n"); | ||
} | ||
//while (mysqli_next_result($con1)); | ||
} | ||
|
||
|
||
/* close connection */ | ||
mysqli_close($con1); | ||
|
||
|
||
} | ||
else { echo "Please input the ID as parameter with numeric value";} | ||
|
||
?> | ||
</font> </div></br></br></br><center> | ||
<img src="../images/Less-41.jpg" /></center> | ||
</body> | ||
</html> | ||
|
||
|
||
|
||
|
||
|
||
|
||
<?php | ||
error_reporting(0); | ||
include("../sql-connections/db-creds.inc"); | ||
?> | ||
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> | ||
<html xmlns="http://www.w3.org/1999/xhtml"> | ||
<head> | ||
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> | ||
<title>Less-41 **stacked Query Intiger type blind**</title> | ||
</head> | ||
|
||
<body bgcolor="#000000"> | ||
<div style=" margin-top:70px;color:#FFF; font-size:23px; text-align:center">Welcome <font color="#FF0000"> Dhakkan </font><br> | ||
<font size="3" color="#FFFF00"> | ||
|
||
|
||
<?php | ||
|
||
|
||
|
||
|
||
// take the variables | ||
if(isset($_GET['id'])) | ||
{ | ||
$id=$_GET['id']; | ||
//logging the connection parameters to a file for analysis. | ||
$fp=fopen('result.txt','a'); | ||
fwrite($fp,'ID:'.$id."\n"); | ||
fclose($fp); | ||
|
||
// connectivity | ||
//mysql connections for stacked query examples. | ||
$con1 = mysqli_connect($host,$dbuser,$dbpass,$dbname); | ||
// Check connection | ||
if (mysqli_connect_errno($con1)) | ||
{ | ||
echo "Failed to connect to MySQL: " . mysqli_connect_error(); | ||
} | ||
else | ||
{ | ||
@mysqli_select_db($con1, $dbname) or die ( "Unable to connect to the database: $dbname"); | ||
} | ||
|
||
|
||
|
||
$sql="SELECT * FROM users WHERE id=$id LIMIT 0,1"; | ||
/* execute multi query */ | ||
if (mysqli_multi_query($con1, $sql)) | ||
{ | ||
|
||
|
||
/* store first result set */ | ||
if ($result = mysqli_store_result($con1)) | ||
{ | ||
if($row = mysqli_fetch_row($result)) | ||
{ | ||
echo '<font size = "5" color= "#00FF00">'; | ||
printf("Your Username is : %s", $row[1]); | ||
echo "<br>"; | ||
printf("Your Password is : %s", $row[2]); | ||
echo "<br>"; | ||
echo "</font>"; | ||
} | ||
// mysqli_free_result($result); | ||
} | ||
/* print divider */ | ||
if (mysqli_more_results($con1)) | ||
{ | ||
//printf("-----------------\n"); | ||
} | ||
//while (mysqli_next_result($con1)); | ||
} | ||
|
||
|
||
/* close connection */ | ||
mysqli_close($con1); | ||
|
||
|
||
} | ||
else { echo "Please input the ID as parameter with numeric value";} | ||
|
||
?> | ||
</font> </div></br></br></br><center> | ||
<img src="../images/Less-41.jpg" /></center> | ||
</body> | ||
</html> | ||
|
||
|
||
|
||
|
||
|
||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,17 @@ | ||
<html> | ||
<head> | ||
<title> | ||
Account Create | ||
</title> | ||
</head> | ||
<body bgcolor="#000000"> | ||
<div align="right"> | ||
<a style="font-size:.8em;color:#FFFF00" href='index.php'><img src="../images/Home.png" height='45'; width='45'></br>HOME</a> | ||
</div> | ||
<div style=" margin-top:150px;color:#FFF; font-size:24px; text-align:center"> | ||
<center> | ||
<img src="../images/acc-create.jpg"> | ||
</center> | ||
</div> | ||
</body> | ||
</html> |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,26 @@ | ||
<?PHP | ||
session_start(); | ||
if (!isset($_COOKIE["Auth"])) | ||
{ | ||
if (!isset($_SESSION["username"])) | ||
{ | ||
header('Location: index.php'); | ||
} | ||
header('Location: index.php'); | ||
} | ||
?> | ||
<html> | ||
<head> | ||
</head> | ||
<body bgcolor="#000000"> | ||
<div align="right"> | ||
<a style="font-size:.8em;color:#FFFF00" href='index.php'><img src="../images/Home.png" height='45'; width='45'></br>HOME</a> | ||
</div> | ||
</div> | ||
<div style=" margin-top:150px;color:#FFF; font-size:24px; text-align:center"> | ||
<center> | ||
<img src="../images/slap1.jpg"> | ||
</center> | ||
</div> | ||
</body> | ||
</html> |
Oops, something went wrong.