avenue of attack

Access logs

Evil3d11
5 years ago

0

okay so I’ve played around with it and I’ve chose an SQL injection as an avenue of attack due to the fact that changing the IP would seem to just be logged as new IP from a different user (>> unless it tracks via the auto login instead of the IP so you can pass by making a few quick requests[/Spoiler]) but I’ve run into the problem with the encoding I’ve tried the normal methods like double encoding and ascii sequence but I can seem to slip anything past yet. any got anyone got any hints on bypassing that encoding.

[Spoiler]my thinking is that if I can execute an SQL injection I can delete the log and still submit login details

1reply
2voices
175views
fred [feuerstein]
5 years ago

0

Re-read the task-description. It is mentioned there, how the attempts are handled to block the ip. This it what you want to think about. Extra-Hint: you don’t need to log in ;)

Discussion thread has been locked. You can no longer add new posts.
1 of 2

This site only uses cookies that are essential for the functionality of this website. Cookies are not used for tracking or marketing purposes.

By using our site, you acknowledge that you have read and understand our Privacy Policy, and Terms of Service.

Dismiss