|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 79
Members: 0
Total: 79
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
Simple SQL Injectio Gives Error - |
|
Posted: Mon Jun 22, 2009 11:09 am |
|
|
shyspy |
Advanced user |
|
|
Joined: Jun 08, 2009 |
Posts: 60 |
|
|
|
|
|
|
|
I am trying to learn simple sql injection.
This time not with automated tools but some manual commands.
In many cases i get this error -
---------------------------------------------------------------------------
Microsoft JET Database Engine error '80040e14'
Syntax error in string in query expression 'login='or'' order by admin_id'.
/admin/verify.asp, line 29
---------------------------------------------------------------------------
can any1 please share some more info on this. |
|
|
|
|
Posted: Mon Jun 22, 2009 11:44 am |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
Seems, that this is your input:
Instead try this:
|
|
|
|
|
|
- |
|
Posted: Mon Jun 22, 2009 2:03 pm |
|
|
shyspy |
Advanced user |
|
|
Joined: Jun 08, 2009 |
Posts: 60 |
|
|
|
|
|
|
|
Thankyou waraxe for the information but now i am getting folowing error.
Code: | The page cannot be displayed
There is a problem with the page you are trying to reach and it cannot be displayed.
Please try the following:
* Click the Refresh button, or try again later.
* Open the www..in home page, and then look for links to the information you want.
HTTP 500.100 - Internal Server Error - ASP error
Internet Information Services
Technical Information (for support personnel)
* Error Type:
Microsoft OLE DB Provider for ODBC Drivers (0x80004005)
[Microsoft][ODBC Microsoft Access Driver]General error Unable to open registry key 'Temporary (volatile) Jet DSN for process 0x3d0 Thread 0x9f0 DBC 0x23d4024 Jet'.
/ABC/hr/validate.asp, line 50
* Browser Type:
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
* Page:
POST 48 bytes to /ABC/hr/validate.asp
* POST Data:
useradmin=admin&passadmin=%27+OR+%271%27%3D%271+
* Time:
Monday, June 22, 2009, 7:18:23 PM
* More information:
Microsoft Support
|
|
|
|
|
|
|
www.waraxe.us Forum Index -> Newbies corner
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|