SQL Injection Project

Postby Kayla_atlanta » Tue Dec 03, 2019 10:34 pm

I'm stuck on how to edit the php files on the website. I understand majority of the commands, but I do not know how to apply that to this specific site. Please Help

NVM I now need help figuring out how to retrieve passwords. I am trying different log ins to log in as the administrator. This does not seem to work though. :?:

Moderator note: I've combined your two posts into one post and removed your second post. That way, your post will show has still needing a response so the experts will see that your posts have not been answered. Thanks!

Re: SQL Injection Project

Postby AmyCowen » Thu Dec 05, 2019 5:22 pm

It is important that you work through the procedure carefully, step by step. This is an advanced project.

Make sure that you are accessing the files from your virtual machine, as described in the procedure. You'll use a text editor to edit the files.

Step 3 and 4 of the Preventing SQL Injection section: "3. On the virtual desktop (not your regular desktop), navigate to C:\Science Buddies\SQL Injection. This folder contains the PHP files for the example website. "login.php" contains the code for the login page and "search.php" contains the code for the search page. You do not need to edit the other files. 4. On the virtual machine, make a simple change to one of these files in a text editor and save it (for example, change some of the HTML text on the login page). Then, refresh the website (in the browser on your regular desktop) and you should see the updated page. You may want to make backup copies of the original PHP files before you proceed and make more changes."

Science Buddies

https://www.sciencebuddies.org/science- ... #procedure

