How I got straight 15 blind time-based sqlis in WordPress plugins
Blind time-based sqli is more difficult to find and can be esaily ignored by the scanners like sqlmap. This post covers the importance of manual testing and code review.
Blind time-based sqli is more difficult to find and can be esaily ignored by the scanners like sqlmap. This post covers the importance of manual testing and code review.
Hey everyone! This is shreya and the blog post covers the step by step guide to pwn secnotes from hackthebox. Secnotes is a medium windows machine. Initial foothold on the box is based on exploiting the sqli on the login page where we get the creds to access smb share. Since we have read.write access on the share, we will be exploiting…