|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
500 Server Error! |
|
Posted: Tue Oct 14, 2008 6:31 am |
|
|
Cablekid |
Advanced user |
|
|
Joined: Jul 14, 2007 |
Posts: 85 |
|
|
|
|
|
|
|
Hey when i do
Code: | site.com/index.php?start=-999+union+select+id,adminname,password+from+ts_admin |
I get a 500 server error! So how dose one fix this?
I heard it was because of my sql format. |
|
|
|
|
Posted: Tue Oct 14, 2008 4:03 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
I guess, that server throws error 500 instead of showing meaningful sql error messages, right?
Now, do you have allready working sql injection pattern? If you do:
Code: |
site.com/index.php?start=-1+UNION+SELECT+111,222,333
|
... then you have visual feedback of "111", "222" and "333"? |
|
|
|
|
Posted: Tue Oct 14, 2008 4:27 pm |
|
|
Cablekid |
Advanced user |
|
|
Joined: Jul 14, 2007 |
Posts: 85 |
|
|
|
|
|
|
|
When i do
Code: | -1+UNION+SELECT+111,222,333 | It still comes up internal server error.
I dont have a working sql pattern, I don't think their allowing union select.
I know id adminname password are all the tables in the ts_admin coloum. |
|
|
|
|
Posted: Tue Oct 14, 2008 4:41 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
I can see, that vulnerable parameter is "start", so probably injection does occur in "LIMIT x,y" section of the sql query. And in most cases it's not exploitable. There is "INTO OUTFILE" method and possible "UNION" too, if there is no "ORDER BY" in use, but still, in most cases it's not exploitable, if it's in "LIMIT" part ... |
|
|
|
|
Posted: Tue Oct 14, 2008 7:34 pm |
|
|
Cablekid |
Advanced user |
|
|
Joined: Jul 14, 2007 |
Posts: 85 |
|
|
|
|
|
|
|
HAha ur right just got my hands on the source codev |
|
|
|
|
www.waraxe.us Forum Index -> Sql injection
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|