Cronos Write-Up by netsecbrad @FellSEC

I will be publishing 1 write-up per day, based off of TJ Null’s OSCP practice list

Nice one - I assume you are prepping for OSCP and if so, good luck!

Thanks, yep - !

Hello, can u tell me how did u know the page was vulnerable to SQLi ? Thanks

Type your comment> @Alphazor said:

Hello, can u tell me how did u know the page was vulnerable to SQLi ? Thanks

It’s more of a convention / standard to just try some basic SQLi against login pages. And since there was no way he had gotten any creds from the enumeration that would probably have been the only way (From intuition, of course.)

Type your comment> @PapyrusTheGuru said:

Type your comment> @Alphazor said:

Hello, can u tell me how did u know the page was vulnerable to SQLi ? Thanks

It’s more of a convention / standard to just try some basic SQLi against login pages. And since there was no way he had gotten any creds from the enumeration that would probably have been the only way (From intuition, of course.)

Thanks, this box is learning a tonshit of new things for me :smiley: