|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 53
Members: 0
Total: 53
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
Help with this injection |
|
Posted: Mon Mar 02, 2009 12:56 am |
|
|
delta |
Advanced user |
|
|
Joined: Jan 11, 2009 |
Posts: 60 |
|
|
|
|
|
|
|
Hello again ppl =]
I'm trying a new injection and I think this won't be easy =[
Eg. of url:
Quote: | www.site.com/post.php?do=remove&p=[TOPIC ID] |
Anything that i put after the topic id don't matter, the page loads ok.
The error comes when I put an invalid ID or nothing.
Quote: | SELECT * FROM post_blabla AS post_blabla INNER JOIN user AS user USING (userid) WHERE post_blabla.postid IN () ORDER BY post_blabla.username ASC;
MySQL Error : You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ') ORDER BY post_blabla.username ASC' at line 1 |
The error show where the injection part is. I tried some things, but without any success. Any ideia ? |
|
|
|
|
Posted: Fri Mar 06, 2009 3:17 pm |
|
|
delta |
Advanced user |
|
|
Joined: Jan 11, 2009 |
Posts: 60 |
|
|
|
|
|
|
|
Soo... No one? |
|
|
|
|
Posted: Fri Mar 06, 2009 3:40 pm |
|
|
ingh1pped |
Advanced user |
|
|
Joined: Dec 13, 2008 |
Posts: 88 |
|
|
|
|
|
|
|
|
|
|
|
Posted: Mon Mar 09, 2009 3:10 pm |
|
|
delta |
Advanced user |
|
|
Joined: Jan 11, 2009 |
Posts: 60 |
|
|
|
|
|
|
|
Nothing... Nothing happened =/
No error. The page always loads ok. Only get error when i put an invalid ID.
And this need to be blind, I'm just showing the query to be more easy to do it. |
|
|
|
|
Posted: Wed Mar 25, 2009 8:01 pm |
|
|
delta |
Advanced user |
|
|
Joined: Jan 11, 2009 |
Posts: 60 |
|
|
|
|
|
|
|
Sorry for recovering this topic. But still need help with that. Anyone knows if this injection is possible? |
|
|
|
|
Posted: Wed Mar 25, 2009 8:06 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
This is not sql injection, it's just lazy programmer, who did not care about error checks. If you provide invalid id, then first sql query returns null rows. Without checking results are used in second sql query and empty "IN ()" will induce sql error:
Code: |
WHERE post_blabla.postid IN () ORDER BY
|
It's not exploitable ... |
|
|
|
|
Posted: Wed Mar 25, 2009 8:45 pm |
|
|
delta |
Advanced user |
|
|
Joined: Jan 11, 2009 |
Posts: 60 |
|
|
|
|
|
|
|
Hm... I imagined so... =) |
|
|
|
|
www.waraxe.us Forum Index -> Sql injection
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|