SQLi Hacking Challange | 1k prize
by - Thursday, January 1, 1970 at 12:00 AM
(June 5, 2022, 11:52 PM)pompompurin Wrote: Challenge Hosted by @420

I already have the money in my wallet and I'm holding it for whoever is able to dump it first. The prize is $1000 USD in Bitcoin.

The challenge is this:
- There is an SQLi Vulnerability on https://coolproxies.com
- He's known about it for years now, but has never found anyone skilled enough to figure out how to exploit it correctly.

Here is the vulnerable page: https://coolproxies.com/pl/freeproxylist.php?cc='

Also to give you a helping hand, you can bypass Cloudflares WAF which will block 99% of SQLi attacks by attempting to attack the vulnerability from the backend.

Backend: https://192.99.224.79/pl/freeproxylist.php?cc=' (MAKE SURE YOU HAVE THE HEADER "Host: coolproxies.com" set or else it will not show up, example: https://i.breached.co/gt3SIuDsaaFRhJZ4.png)

To prove that you've indeed hacked it, you will need to provide the list of databases, the first 10 user entries, and a working example. First person to get it wins.

Good luck !


The server is down
5Cr1P7K1DD135
Reply
Error 525 ssl handjob failed :-/
fishing luxury hookers and catching BUTT.erflies. la vida es bonita
Reply
@Sleep just won.
Reply
Sleep will dump this so fast!
Reply
(June 7, 2022, 04:17 AM)mud Wrote: @Sleep just won.


cap

\" I was nothing, I came from nothing, I got nothing, never asked for nothing. But now... Well, you watch the news. I did that. By. My. Self. The fuck did you ever do?\" -Iraq

Reply
owner has read this article, he provides sample to successfully prove 1000$ and fix it, LOL
Leave a telegram, I will contact you
Reply
(June 7, 2022, 06:07 AM)Max Wrote: Sleep will dump this so fast!


"SleepTheGod"  :sleepy:
:pomlove: Thank you @FederalAgentBrad for the VIP Rank and Thank you @tty for the GOD Rank.
Thank you @nan9e for the gift >.<
:pomlove:
Reply
Winner is @TarTarX, congrats to them !

https://pompur.in
Reply


 Users viewing this thread: SQLi Hacking Challange | 1k prize: No users currently viewing.