Reading Log Files in Postgresql Sql Injection – Tutorial

Hey everyone,

So I guess it’s time to learn something juicy about Postgresql.
If you’re injecting a Website based on a Postgresql database then you might wanna check your privileges because this will simply allow you to use lots of interesting Postgresql Functions in case you could:
You can find most of these functions in here: http://www.postgresql.org/docs/9.4/static/functions-admin.html

What we will be covering in this Tutorial is related to reading Log/Config Files, so lets just get started.
Continue reading “Reading Log Files in Postgresql Sql Injection – Tutorial”

Blind Postgresql Sql Injection – Tutorial

Hello everyone,
I just realized that there is no Advanced Postgresql Blind Sql Injection  around the Internet and that’s why I decided to make this.
There’s a lot to learn, it took me some time to get things working just fine.
We have a live target: http://www.must.edu.eg/Reports/College_TT.php?College_Id=7

This tutorial consists on letting you know everything you have to know about Postgresql Sql Injection and much more when it comes to Blind Postgresql Sql Injection.
I tried to Sql Inject this target using Popular tools such as Havij and Sqlmap but they failed while CppSqlInjector succeeded.
Take your time to read, it’s kind of confusing if you’re not familiar with Postgresql but I did add a lot of information in here that should be really useful to everyone.
Continue reading “Blind Postgresql Sql Injection – Tutorial”

Design a site like this with WordPress.com
Get started