Web Requests - CRUD API Issue

Hello everyone,

This seems like a simple task that has been driving me nuts. The CRUD API section has the following question: First, try to update any city’s name to be ‘flag’. Then, delete any city. Once done, search for a city named ‘flag’ to get the flag.

I am having issues with the PUT request (update):

  1. Update
    curl -X PUT “http://161.35.33.243:30573/api.php/city/London” -d ‘{“city_name”:“flag”}’ -H “Content-Type: application/json”

I am getting the following error:

Unknown column ’ ’ in ‘field list’.

I literally copied the example in the lesson and replaced the IP:PORT.
I had no issues deleting a record and reading records. I have tried modifying ‘city_name’ in case the SQL db uses something else, but I kept getting the same error. Interesting enough, if I replace my json data with empty brackets, I get another error:

You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ‘where city_name=‘Houston’’

Even the error shows that I am using the correct column name. I’m completely lost.

Hey!

I just used this with no issues: curl http://142.93.39.188:30592/api.php/city/London -X PUT -d '{"city_name":"flag"}' -H "Content-Type: application/json"

Reset the target machine and try one more time. If you get it to work, keep this thread in mind: Web requests - crud api

Feel free to DM me with screenshots.
-onthesauce

1 Like

Hello,

I just tried your curl request and I’m still getting the same issue. I tried the PUT method first with no success. Below you will see me use GET with success. I then reset the machine and tried again. No luck.

I gave up and started editing and resending these requests using Firefox devtools and was able to get the flag. Great success! Thanks for your help!

Nice! Yeah, I was using the pwnbox, think about using it for certain exercises when you are having trouble. Especially when copying commands from the section. Windows may handle the examples from the course differently because the authors have wrote them with Linux in mind.

Please only tell me about command.!!!

What do you want me to tell you about the curl command? I’d rather you tell me about the issue you are having and we go from there. That way when other people have the same issue they will know how to deal with it and they won’t just be copying and pasting commands from the forum.
-onthesauce

Question: First, try to update any city’s name to be ‘flag’. Then, delete any city. Once done, search for a city named ‘flag’ to get the flag.
Answer: ??
Can you Please teach a little about this question and then it’s solution.
That’s what all I wanted to say.

Please tell me . I’m stuck here.

Question: First, try to update any city’s name to be ‘flag’. Then, delete any city. Once done, search for a city named ‘flag’ to get the flag.
Answer: ??
Can you Please teach a little about this question and then it’s solution.
That’s what all I wanted to say.