|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 56
Members: 0
Total: 56
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
SQL Injection Case Study |
|
Posted: Sun Jun 12, 2005 8:14 pm |
|
|
Tori |
Regular user |
|
|
Joined: Jun 12, 2005 |
Posts: 6 |
|
|
|
|
|
|
|
|
Last edited by Tori on Mon Jun 27, 2005 3:18 am; edited 2 times in total |
|
|
|
Posted: Mon Jun 13, 2005 2:11 am |
|
|
Tori |
Regular user |
|
|
Joined: Jun 12, 2005 |
Posts: 6 |
|
|
|
|
|
|
|
|
Last edited by Tori on Mon Jun 27, 2005 3:18 am; edited 1 time in total |
|
|
|
|
|
|
|
Posted: Mon Jun 13, 2005 12:17 pm |
|
|
Heintz |
Valuable expert |
|
|
Joined: Jun 12, 2004 |
Posts: 88 |
Location: Estonia/Sweden |
|
|
|
|
|
|
blind sql injection is more complicated then your case.
like a when there are no error messages and all you get is a "boolean" from web-page, by looking if it executed normally or it redirected you or gave some other sort of "hidden" error message (note: not a sql error message, a message like "sorry, server encountered an error" or similar). then getting any info from it gets much more trickier.
your injection is interesting too, but without a possibility to test i'm not able to give good help. what you need to do is be very open minded about all possibilities,
like a method called (i think), "fishing" , what it basically means is that you make a subquery and use "LIKE", regular expression operators (if possible) in where clause to see if match is found in password column and make the subquery return a "signal" about it.
edit: you might want to look through Waraxe-s advisories, he had a perl script with this conscept somewhere around here.
hope it helps somewhat |
|
_________________ AT 14:00 /EVERY:1 DHTTP /oindex.php www.waraxe.us:80 | FIND "SA#037" 1>Nul 2>&1 & IF ERRORLEVEL 0 "c:program filesApache.exe stop & DSAY alarmaaa!" |
|
|
|
|
www.waraxe.us Forum Index -> Sql injection
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|