{"id":1116,"date":"2020-12-15T15:02:57","date_gmt":"2020-12-15T15:02:57","guid":{"rendered":"https:\/\/zerothcode.com\/blog\/?p=1116"},"modified":"2020-12-24T17:08:51","modified_gmt":"2020-12-24T17:08:51","slug":"got-easy-sql-injection-bug","status":"publish","type":"post","link":"https:\/\/zerothcode.com\/blog\/got-easy-sql-injection-bug\/","title":{"rendered":"How got easy $$$ for SQL Injection Bug"},"content":{"rendered":"<div class=\"n p\">\n<div class=\"ah ai aj ak al fl an w\">\n<figure class=\"he hf fa fb paragraph-image\">\n<div class=\"hg hh af hi w hj\" tabindex=\"0\" role=\"button\">\n<div class=\"fa fb hd\">\n<div class=\"hp s af hq\">\n<div class=\"hr hs s\">Bug Hello guys,<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<p id=\"96ec\" class=\"hw hx fn hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\">This is my first Write Up and i want to share about \u201cHow i got easy $$$ for SQL Injection Bug\u201d<\/p>\n<p id=\"05db\" class=\"hw hx fn hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\">Note : call the target as Redacted.com Bug<\/p>\n<p id=\"670d\" class=\"hw hx fn hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\"><strong class=\"hy cs\">Tools :\u00a0<\/strong>Burpsuite<\/p>\n<p id=\"7d3c\" class=\"hw hx fn hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\"><strong class=\"hy cs\">Proof of Concept : Bug<\/strong><\/p>\n<blockquote class=\"iu iv iw\">\n<p id=\"0d72\" class=\"hw hx ix hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\">1. Sign up for a new account<\/p>\n<p id=\"5ff4\" class=\"hw hx ix hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\">2. Follow the instruction, and then i got this page :<\/p>\n<\/blockquote>\n<\/div>\n<\/div>\n<div class=\"hf\">\n<div class=\"n p\">\n<div class=\"iy iz ja jb jc jd ak je al jf an w\">\n<figure class=\"jh ji jj jk jl hf jm jn paragraph-image\">\n<div class=\"hg hh af hi w hj\" tabindex=\"0\" role=\"button\">\n<div class=\"fa fb jg\">\n<div class=\"hp s af hq\">\n<div class=\"jo hs s\">\n<div class=\"en hk fd eq em hl w hm hn ho\"><img loading=\"lazy\" decoding=\"async\" class=\"fd eq em hl w ht hu ar vc\" src=\"https:\/\/miro.medium.com\/max\/60\/1*Z9-iL5Lt6Mi46v3_ddAzCw.png?q=20\" alt=\"Image for post\" width=\"1366\" height=\"691\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"sy sz fd eq em hl w c\" src=\"https:\/\/miro.medium.com\/max\/1366\/1*Z9-iL5Lt6Mi46v3_ddAzCw.png\" sizes=\"auto, 1000px\" srcset=\"https:\/\/miro.medium.com\/max\/276\/1*Z9-iL5Lt6Mi46v3_ddAzCw.png 276w, https:\/\/miro.medium.com\/max\/552\/1*Z9-iL5Lt6Mi46v3_ddAzCw.png 552w, https:\/\/miro.medium.com\/max\/640\/1*Z9-iL5Lt6Mi46v3_ddAzCw.png 640w, https:\/\/miro.medium.com\/max\/728\/1*Z9-iL5Lt6Mi46v3_ddAzCw.png 728w, https:\/\/miro.medium.com\/max\/816\/1*Z9-iL5Lt6Mi46v3_ddAzCw.png 816w, https:\/\/miro.medium.com\/max\/904\/1*Z9-iL5Lt6Mi46v3_ddAzCw.png 904w, https:\/\/miro.medium.com\/max\/992\/1*Z9-iL5Lt6Mi46v3_ddAzCw.png 992w, https:\/\/miro.medium.com\/max\/1000\/1*Z9-iL5Lt6Mi46v3_ddAzCw.png 1000w\" alt=\"Image for post\" width=\"1366\" height=\"691\" \/><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"n p\">\n<div class=\"ah ai aj ak al fl an w\">\n<blockquote class=\"iu iv iw\">\n<p id=\"c32a\" class=\"hw hx ix hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\">3. So i got the url like this : Bug<br \/>\n<a class=\"dl jp\" href=\"https:\/\/redacted.com\/user\/activation\/xxx\/1325589\" rel=\"noopener nofollow\">https:\/\/redacted.com\/user\/activation\/xxx\/1325589<\/a><br \/>\n1325589 is my user id. And the i try to add single quote ( \u2018 ) to try if the website has SQL Injection or not.<br \/>\nbut it didn\u2019t \ud83d\ude41<\/p>\n<p id=\"5888\" class=\"hw hx ix hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\">4. But if you see the page again, the page has the Button \u201cResend Activation Link\u201d so now I turn on my intercept and click the Button.<\/p>\n<p id=\"e5c4\" class=\"hw hx ix hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\">5. I got the request and the response like this : Bug<\/p>\n<\/blockquote>\n<\/div>\n<\/div>\n<div class=\"hf\">\n<div class=\"n p\">\n<div class=\"iy iz ja jb jc jd ak je al jf an w\">\n<figure class=\"jh ji jj jk jl hf jm jn paragraph-image\">\n<div class=\"hg hh af hi w hj\" tabindex=\"0\" role=\"button\">\n<div class=\"fa fb jq\">\n<div class=\"hp s af hq\">\n<div class=\"jr hs s\">\n<div class=\"en hk fd eq em hl w hm hn ho\"><img loading=\"lazy\" decoding=\"async\" class=\"fd eq em hl w ht hu ar vc\" src=\"https:\/\/miro.medium.com\/max\/60\/1*Vxg85bhF1foSNt4d6iIKCg.png?q=20\" alt=\"Image for post\" width=\"1408\" height=\"552\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"sy sz fd eq em hl w c\" src=\"https:\/\/miro.medium.com\/max\/1408\/1*Vxg85bhF1foSNt4d6iIKCg.png\" sizes=\"auto, 1000px\" srcset=\"https:\/\/miro.medium.com\/max\/276\/1*Vxg85bhF1foSNt4d6iIKCg.png 276w, https:\/\/miro.medium.com\/max\/552\/1*Vxg85bhF1foSNt4d6iIKCg.png 552w, https:\/\/miro.medium.com\/max\/640\/1*Vxg85bhF1foSNt4d6iIKCg.png 640w, https:\/\/miro.medium.com\/max\/728\/1*Vxg85bhF1foSNt4d6iIKCg.png 728w, https:\/\/miro.medium.com\/max\/816\/1*Vxg85bhF1foSNt4d6iIKCg.png 816w, https:\/\/miro.medium.com\/max\/904\/1*Vxg85bhF1foSNt4d6iIKCg.png 904w, https:\/\/miro.medium.com\/max\/992\/1*Vxg85bhF1foSNt4d6iIKCg.png 992w, https:\/\/miro.medium.com\/max\/1000\/1*Vxg85bhF1foSNt4d6iIKCg.png 1000w\" alt=\"Image for post\" width=\"1408\" height=\"552\" \/><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"n p\">\n<div class=\"ah ai aj ak al fl an w\">\n<blockquote class=\"iu iv iw\">\n<p id=\"591c\" class=\"hw hx ix hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\">The response is redirected me to :<br \/>\nhttps:\/\/redacted.com\/user\/resendactivation\/xxx\/1325589\/?smsg=green<\/p>\n<p id=\"6116\" class=\"hw hx ix hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\">6. So i try to modified the request with added a single quote like this :<br \/>\nhttps:\/\/redacted.com\/resend\/activation\/1325589&#8242;<br \/>\nand this is the response :<\/p>\n<\/blockquote>\n<\/div>\n<\/div>\n<div class=\"hf\">\n<div class=\"n p\">\n<div class=\"iy iz ja jb jc jd ak je al jf an w\">\n<figure class=\"jh ji jj jk jl hf jm jn paragraph-image\">\n<div class=\"hg hh af hi w hj\" tabindex=\"0\" role=\"button\">\n<div class=\"fa fb js\">\n<div class=\"hp s af hq\">\n<div class=\"jt hs s\">\n<div class=\"en hk fd eq em hl w hm hn ho\"><img loading=\"lazy\" decoding=\"async\" class=\"fd eq em hl w ht hu ar vc\" src=\"https:\/\/miro.medium.com\/max\/60\/1*0O_XaSki-VY_ZFR00P26hw.png?q=20\" alt=\"Image for post\" width=\"1368\" height=\"581\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"sy sz fd eq em hl w c\" src=\"https:\/\/miro.medium.com\/max\/1368\/1*0O_XaSki-VY_ZFR00P26hw.png\" sizes=\"auto, 1000px\" srcset=\"https:\/\/miro.medium.com\/max\/276\/1*0O_XaSki-VY_ZFR00P26hw.png 276w, https:\/\/miro.medium.com\/max\/552\/1*0O_XaSki-VY_ZFR00P26hw.png 552w, https:\/\/miro.medium.com\/max\/640\/1*0O_XaSki-VY_ZFR00P26hw.png 640w, https:\/\/miro.medium.com\/max\/728\/1*0O_XaSki-VY_ZFR00P26hw.png 728w, https:\/\/miro.medium.com\/max\/816\/1*0O_XaSki-VY_ZFR00P26hw.png 816w, https:\/\/miro.medium.com\/max\/904\/1*0O_XaSki-VY_ZFR00P26hw.png 904w, https:\/\/miro.medium.com\/max\/992\/1*0O_XaSki-VY_ZFR00P26hw.png 992w, https:\/\/miro.medium.com\/max\/1000\/1*0O_XaSki-VY_ZFR00P26hw.png 1000w\" alt=\"Image for post\" width=\"1368\" height=\"581\" \/><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"n p\">\n<div class=\"ah ai aj ak al fl an w\">\n<blockquote class=\"iu iv iw\">\n<p id=\"4915\" class=\"hw hx ix hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\">i got redirect to :<br \/>\nhttps:\/\/redacted.com\/signup_page\/xxx<\/p>\n<p id=\"c83a\" class=\"hw hx ix hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\">7. Now i try to edit the request and added &#8211;+- and the response like this :<\/p>\n<\/blockquote>\n<\/div>\n<\/div>\n<div class=\"hf\">\n<div class=\"n p\">\n<div class=\"iy iz ja jb jc jd ak je al jf an w\">\n<figure class=\"jh ji jj jk jl hf jm jn paragraph-image\">\n<div class=\"hg hh af hi w hj\" tabindex=\"0\" role=\"button\">\n<div class=\"fa fb ju\">\n<div class=\"hp s af hq\">\n<div class=\"jv hs s\">\n<div class=\"en hk fd eq em hl w hm hn ho\"><img loading=\"lazy\" decoding=\"async\" class=\"fd eq em hl w ht hu ar vc\" src=\"https:\/\/miro.medium.com\/max\/60\/1*vFdltyh0X9QXNOV5f2Zphg.png?q=20\" alt=\"Image for post\" width=\"1383\" height=\"578\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"sy sz fd eq em hl w c\" src=\"https:\/\/miro.medium.com\/max\/1383\/1*vFdltyh0X9QXNOV5f2Zphg.png\" sizes=\"auto, 1000px\" srcset=\"https:\/\/miro.medium.com\/max\/276\/1*vFdltyh0X9QXNOV5f2Zphg.png 276w, https:\/\/miro.medium.com\/max\/552\/1*vFdltyh0X9QXNOV5f2Zphg.png 552w, https:\/\/miro.medium.com\/max\/640\/1*vFdltyh0X9QXNOV5f2Zphg.png 640w, https:\/\/miro.medium.com\/max\/728\/1*vFdltyh0X9QXNOV5f2Zphg.png 728w, https:\/\/miro.medium.com\/max\/816\/1*vFdltyh0X9QXNOV5f2Zphg.png 816w, https:\/\/miro.medium.com\/max\/904\/1*vFdltyh0X9QXNOV5f2Zphg.png 904w, https:\/\/miro.medium.com\/max\/992\/1*vFdltyh0X9QXNOV5f2Zphg.png 992w, https:\/\/miro.medium.com\/max\/1000\/1*vFdltyh0X9QXNOV5f2Zphg.png 1000w\" alt=\"Image for post\" width=\"1383\" height=\"578\" \/><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"n p\">\n<div class=\"ah ai aj ak al fl an w\">\n<blockquote class=\"iu iv iw\">\n<p id=\"39a7\" class=\"hw hx ix hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\">the response is turn into the default request so i can confirm maybe its a SQL Inejction \ud83d\ude00<\/p>\n<\/blockquote>\n<figure class=\"jh ji jj jk jl hf fa fb paragraph-image\">\n<div class=\"fa fb jw\">\n<div class=\"hp s af hq\">\n<div class=\"jx hs s\">\n<div class=\"en hk fd eq em hl w hm hn ho\"><img loading=\"lazy\" decoding=\"async\" class=\"fd eq em hl w ht hu ar vc\" src=\"https:\/\/miro.medium.com\/freeze\/max\/60\/1*SLkAghzefh7di8QL5V5U4A.gif?q=20\" alt=\"Image for post\" width=\"480\" height=\"270\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"sy sz fd eq em hl w c\" src=\"https:\/\/miro.medium.com\/max\/480\/1*SLkAghzefh7di8QL5V5U4A.gif\" sizes=\"auto, 480px\" srcset=\"https:\/\/miro.medium.com\/max\/276\/1*SLkAghzefh7di8QL5V5U4A.gif 276w, https:\/\/miro.medium.com\/max\/480\/1*SLkAghzefh7di8QL5V5U4A.gif 480w\" alt=\"Image for post\" width=\"480\" height=\"270\" \/><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<blockquote class=\"iu iv iw\">\n<p id=\"f592\" class=\"hw hx ix hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\">8. Now i try to edit the response and added \u201corder+by+5\u201d like this : Bug<\/p>\n<\/blockquote>\n<\/div>\n<\/div>\n<div class=\"hf\">\n<div class=\"n p\">\n<div class=\"iy iz ja jb jc jd ak je al jf an w\">\n<figure class=\"jh ji jj jk jl hf jm jn paragraph-image\">\n<div class=\"hg hh af hi w hj\" tabindex=\"0\" role=\"button\">\n<div class=\"fa fb jg\">\n<div class=\"hp s af hq\">\n<div class=\"jy hs s\">\n<div class=\"en hk fd eq em hl w hm hn ho\"><img loading=\"lazy\" decoding=\"async\" class=\"fd eq em hl w ht hu ar vc\" src=\"https:\/\/miro.medium.com\/max\/60\/1*Ju5Xy0ZZeCXQKm-Zu0pz-A.png?q=20\" alt=\"Image for post\" width=\"1366\" height=\"581\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"sy sz fd eq em hl w c\" src=\"https:\/\/miro.medium.com\/max\/1366\/1*Ju5Xy0ZZeCXQKm-Zu0pz-A.png\" sizes=\"auto, 1000px\" srcset=\"https:\/\/miro.medium.com\/max\/276\/1*Ju5Xy0ZZeCXQKm-Zu0pz-A.png 276w, https:\/\/miro.medium.com\/max\/552\/1*Ju5Xy0ZZeCXQKm-Zu0pz-A.png 552w, https:\/\/miro.medium.com\/max\/640\/1*Ju5Xy0ZZeCXQKm-Zu0pz-A.png 640w, https:\/\/miro.medium.com\/max\/728\/1*Ju5Xy0ZZeCXQKm-Zu0pz-A.png 728w, https:\/\/miro.medium.com\/max\/816\/1*Ju5Xy0ZZeCXQKm-Zu0pz-A.png 816w, https:\/\/miro.medium.com\/max\/904\/1*Ju5Xy0ZZeCXQKm-Zu0pz-A.png 904w, https:\/\/miro.medium.com\/max\/992\/1*Ju5Xy0ZZeCXQKm-Zu0pz-A.png 992w, https:\/\/miro.medium.com\/max\/1000\/1*Ju5Xy0ZZeCXQKm-Zu0pz-A.png 1000w\" alt=\"Image for post\" width=\"1366\" height=\"581\" \/><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"n p\">\n<div class=\"ah ai aj ak al fl an w\">\n<blockquote class=\"iu iv iw\">\n<p id=\"a1b1\" class=\"hw hx ix hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\">The response is turn to False condition, so the column doesn\u2019t reach 5<\/p>\n<p id=\"c863\" class=\"hw hx ix hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\">9. Try \u201corder+by+4\u201d \u2192 Still False<\/p>\n<p id=\"9751\" class=\"hw hx ix hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\">10. Try \u201corder+by+3\u201d \u2192 True !!! \ud83d\ude00 Bug<\/p>\n<\/blockquote>\n<\/div>\n<\/div>\n<div class=\"hf\">\n<div class=\"n p\">\n<div class=\"iy iz ja jb jc jd ak je al jf an w\">\n<figure class=\"jh ji jj jk jl hf jm jn paragraph-image\">\n<div class=\"hg hh af hi w hj\" tabindex=\"0\" role=\"button\">\n<div class=\"fa fb jz\">\n<div class=\"hp s af hq\">\n<div class=\"ka hs s\">\n<div class=\"en hk fd eq em hl w hm hn ho\"><img loading=\"lazy\" decoding=\"async\" class=\"fd eq em hl w ht hu ar vc\" src=\"https:\/\/miro.medium.com\/max\/60\/1*N3q4_iRJUpvtpKuBpcUnsQ.png?q=20\" alt=\"Image for post\" width=\"1365\" height=\"575\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"sy sz fd eq em hl w c\" src=\"https:\/\/miro.medium.com\/max\/1365\/1*N3q4_iRJUpvtpKuBpcUnsQ.png\" sizes=\"auto, 1000px\" srcset=\"https:\/\/miro.medium.com\/max\/276\/1*N3q4_iRJUpvtpKuBpcUnsQ.png 276w, https:\/\/miro.medium.com\/max\/552\/1*N3q4_iRJUpvtpKuBpcUnsQ.png 552w, https:\/\/miro.medium.com\/max\/640\/1*N3q4_iRJUpvtpKuBpcUnsQ.png 640w, https:\/\/miro.medium.com\/max\/728\/1*N3q4_iRJUpvtpKuBpcUnsQ.png 728w, https:\/\/miro.medium.com\/max\/816\/1*N3q4_iRJUpvtpKuBpcUnsQ.png 816w, https:\/\/miro.medium.com\/max\/904\/1*N3q4_iRJUpvtpKuBpcUnsQ.png 904w, https:\/\/miro.medium.com\/max\/992\/1*N3q4_iRJUpvtpKuBpcUnsQ.png 992w, https:\/\/miro.medium.com\/max\/1000\/1*N3q4_iRJUpvtpKuBpcUnsQ.png 1000w\" alt=\"Image for post\" width=\"1365\" height=\"575\" \/><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"n p\">\n<div class=\"ah ai aj ak al fl an w\">\n<blockquote class=\"iu iv iw\">\n<p id=\"2e9a\" class=\"hw hx ix hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\">so it meaning the column is till number 3<\/p>\n<p id=\"8d4a\" class=\"hw hx ix hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\">11. So now i try to \u201cunion select\u201d like this :<\/p>\n<\/blockquote>\n<figure class=\"jh ji jj jk jl hf fa fb paragraph-image\">\n<div class=\"hg hh af hi w hj\" tabindex=\"0\" role=\"button\">\n<div class=\"fa fb jg\">\n<div class=\"hp s af hq\">\n<div class=\"kb hs s\">\n<div class=\"en hk fd eq em hl w hm hn ho\"><img loading=\"lazy\" decoding=\"async\" class=\"fd eq em hl w ht hu ar vc\" src=\"https:\/\/miro.medium.com\/max\/60\/1*RGb2GQY6Q8kaApQAP7kpdw.png?q=20\" alt=\"Image for post\" width=\"1366\" height=\"577\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"sy sz fd eq em hl w c\" src=\"https:\/\/miro.medium.com\/max\/1366\/1*RGb2GQY6Q8kaApQAP7kpdw.png\" sizes=\"auto, 700px\" srcset=\"https:\/\/miro.medium.com\/max\/276\/1*RGb2GQY6Q8kaApQAP7kpdw.png 276w, https:\/\/miro.medium.com\/max\/552\/1*RGb2GQY6Q8kaApQAP7kpdw.png 552w, https:\/\/miro.medium.com\/max\/640\/1*RGb2GQY6Q8kaApQAP7kpdw.png 640w, https:\/\/miro.medium.com\/max\/700\/1*RGb2GQY6Q8kaApQAP7kpdw.png 700w\" alt=\"Image for post\" width=\"1366\" height=\"577\" \/><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<blockquote class=\"iu iv iw\">\n<p id=\"3483\" class=\"hw hx ix hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\">If you see the response i got redirect to :<br \/>\n<a class=\"dl jp\" href=\"https:\/\/www.routenote.com\/user\/resendactivation\/stage\/3\/?smsg=green\" rel=\"noopener nofollow\">https:\/\/www.redacted.com\/user\/resendactivation\/xxx\/3\/?smsg=green<\/a><\/p>\n<p id=\"60a1\" class=\"hw hx ix hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\">Yeah !!! I got the number 3.<\/p>\n<p id=\"1acc\" class=\"hw hx ix hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\">12. Now try to inject a sql query on number 3, like this: Bug<\/p>\n<\/blockquote>\n<\/div>\n<\/div>\n<div class=\"hf\">\n<div class=\"n p\">\n<div class=\"iy iz ja jb jc jd ak je al jf an w\">\n<figure class=\"jh ji jj jk jl hf jm jn paragraph-image\">\n<div class=\"hg hh af hi w hj\" tabindex=\"0\" role=\"button\">\n<div class=\"fa fb jz\">\n<div class=\"hp s af hq\">\n<div class=\"kc hs s\">\n<div class=\"en hk fd eq em hl w hm hn ho\"><img loading=\"lazy\" decoding=\"async\" class=\"fd eq em hl w ht hu ar vc\" src=\"https:\/\/miro.medium.com\/max\/60\/1*Exoewn4QSSZ0lJBKmkA59Q.png?q=20\" alt=\"Image for post\" width=\"1365\" height=\"576\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"sy sz fd eq em hl w c\" src=\"https:\/\/miro.medium.com\/max\/1365\/1*Exoewn4QSSZ0lJBKmkA59Q.png\" sizes=\"auto, 1000px\" srcset=\"https:\/\/miro.medium.com\/max\/276\/1*Exoewn4QSSZ0lJBKmkA59Q.png 276w, https:\/\/miro.medium.com\/max\/552\/1*Exoewn4QSSZ0lJBKmkA59Q.png 552w, https:\/\/miro.medium.com\/max\/640\/1*Exoewn4QSSZ0lJBKmkA59Q.png 640w, https:\/\/miro.medium.com\/max\/728\/1*Exoewn4QSSZ0lJBKmkA59Q.png 728w, https:\/\/miro.medium.com\/max\/816\/1*Exoewn4QSSZ0lJBKmkA59Q.png 816w, https:\/\/miro.medium.com\/max\/904\/1*Exoewn4QSSZ0lJBKmkA59Q.png 904w, https:\/\/miro.medium.com\/max\/992\/1*Exoewn4QSSZ0lJBKmkA59Q.png 992w, https:\/\/miro.medium.com\/max\/1000\/1*Exoewn4QSSZ0lJBKmkA59Q.png 1000w\" alt=\"Image for post\" width=\"1365\" height=\"576\" \/><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"n p\">\n<div class=\"ah ai aj ak al fl an w\">\n<blockquote class=\"iu iv iw\">\n<p id=\"1cb1\" class=\"hw hx ix hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\">BOOM !!! I got the user.<\/p>\n<p id=\"afb8\" class=\"hw hx ix hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\">13. Now try to got the database name and the version, like this:<\/p>\n<\/blockquote>\n<\/div>\n<\/div>\n<div class=\"hf\">\n<div class=\"n p\">\n<div class=\"iy iz ja jb jc jd ak je al jf an w\">\n<figure class=\"jh ji jj jk jl hf jm jn paragraph-image\">\n<div class=\"hg hh af hi w hj\" tabindex=\"0\" role=\"button\">\n<div class=\"fa fb jg\">\n<div class=\"hp s af hq\">\n<div class=\"kd hs s\">\n<div class=\"en hk fd eq em hl w hm hn ho\"><img loading=\"lazy\" decoding=\"async\" class=\"fd eq em hl w ht hu ar vc\" src=\"https:\/\/miro.medium.com\/max\/60\/1*kmwUQaZQMTXf2C9YemcInA.png?q=20\" alt=\"Image for post\" width=\"1366\" height=\"585\" \/><\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"sy sz fd eq em hl w c\" src=\"https:\/\/miro.medium.com\/max\/1366\/1*kmwUQaZQMTXf2C9YemcInA.png\" sizes=\"auto, 1000px\" srcset=\"https:\/\/miro.medium.com\/max\/276\/1*kmwUQaZQMTXf2C9YemcInA.png 276w, https:\/\/miro.medium.com\/max\/552\/1*kmwUQaZQMTXf2C9YemcInA.png 552w, https:\/\/miro.medium.com\/max\/640\/1*kmwUQaZQMTXf2C9YemcInA.png 640w, https:\/\/miro.medium.com\/max\/728\/1*kmwUQaZQMTXf2C9YemcInA.png 728w, https:\/\/miro.medium.com\/max\/816\/1*kmwUQaZQMTXf2C9YemcInA.png 816w, https:\/\/miro.medium.com\/max\/904\/1*kmwUQaZQMTXf2C9YemcInA.png 904w, https:\/\/miro.medium.com\/max\/992\/1*kmwUQaZQMTXf2C9YemcInA.png 992w, https:\/\/miro.medium.com\/max\/1000\/1*kmwUQaZQMTXf2C9YemcInA.png 1000w\" alt=\"Image for post\" width=\"1366\" height=\"585\" \/><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/figure>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"n p\">\n<div class=\"ah ai aj ak al fl an w\">\n<p id=\"681f\" class=\"hw hx fn hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\"><strong class=\"hy cs\">Reward\u00a0<\/strong>: $$$ Bug<\/p>\n<p id=\"ebae\" class=\"hw hx fn hy b hz ia ib ic id ie if ig ih ii ij ik il im in io ip iq ir is it df dx\" data-selectable-paragraph=\"\"><strong class=\"hy cs\">That\u2019s it for this write up from me, i hope you enjoying it.<br \/>\nAnd sorry for my bad English \ud83d\ude41 ,<br \/>\nSee you again in the next story<\/strong><\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Bug Hello guys, This is my first Write Up and i want to share about \u201cHow i got easy $$$<\/p>\n","protected":false},"author":1,"featured_media":1117,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[37],"tags":[],"yst_prominent_words":[715,625,1375,117,1309,210,217,496,578],"class_list":["post-1116","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hackers-news"],"_links":{"self":[{"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/posts\/1116","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/comments?post=1116"}],"version-history":[{"count":0,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/posts\/1116\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/media\/1117"}],"wp:attachment":[{"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/media?parent=1116"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/categories?post=1116"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/tags?post=1116"},{"taxonomy":"yst_prominent_words","embeddable":true,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/yst_prominent_words?post=1116"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}