time-based-inference

1 article
sort: new top best
clear filter
0 8/10

A detailed walkthrough of exploiting a blind SQL injection vulnerability in a JSON-RPC API by leveraging an IN() clause to infer boolean results through asset count variations, and bypassing WAF filters using Unicode escape sequences to extract database information.

TomNomNom MySQL
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 19 hours ago · details