|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 94
Members: 0
Total: 94
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
Blind SQL - Error-based feedback |
|
Posted: Mon Jul 06, 2009 6:31 pm |
|
|
badrh0 |
Active user |
|
|
Joined: Jul 06, 2008 |
Posts: 32 |
|
|
|
|
|
|
|
Hi everybody;
Can someone tell why and how this injection works:
z' AND IF(ascii(lower(substring(database(),$i,$j)))>100,(SELECT 1 UNION ALL SELECT $k),'$l')='1
I mean, what does the differnet variables mean, fos substring I know the function but what does it mean to write database() as arguments, is it an array?
If I want to create a script to tackle responses (1 or 0) what must I change in this injection?
Is there other possible injections to extract table names?
In short, I want know the theoretical basis of all that
PS: wenta skout :-p |
|
|
|
|
www.waraxe.us Forum Index -> Sql injection
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|