|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 72
Members: 0
Total: 72
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
Little Help |
|
Posted: Thu Jul 30, 2009 4:13 pm |
|
|
delta |
Advanced user |
|
|
Joined: Jan 11, 2009 |
Posts: 60 |
|
|
|
|
|
|
|
I'm stucked in this injection
ir.php?pagina=noticia&id=12
Can't put special chars, otherwise site will block.
If i try to put a letter in the id, error will come:
Code: | Warning: mssql_query(): message: Error converting data type varchar to bigint. (severity 16) in c:\appserv\www\noticia.php on line 11
Warning: mssql_query(): Query failed in c:\appserv\www\noticia.php on line 11
Warning: mssql_fetch_row(): supplied argument is not a valid MS SQL-result resource in c:\appserv\www\noticia.php on line 12 |
Any idea? |
|
|
|
|
Posted: Thu Jul 30, 2009 6:57 pm |
|
|
Chb |
Valuable expert |
|
|
Joined: Jul 23, 2005 |
Posts: 206 |
Location: Germany |
|
|
|
|
|
|
Imho you won't be able to exploit this parameter. As you can see in the error message, there is an implicit convertion to bigint, meaning, you are only able to use numbers. |
|
|
|
|
Posted: Thu Jul 30, 2009 9:54 pm |
|
|
delta |
Advanced user |
|
|
Joined: Jan 11, 2009 |
Posts: 60 |
|
|
|
|
|
|
|
And if i encode the url?
The server will recognize the commands? |
|
|
|
|
Posted: Fri Jul 31, 2009 3:31 pm |
|
|
Chb |
Valuable expert |
|
|
Joined: Jul 23, 2005 |
Posts: 206 |
Location: Germany |
|
|
|
|
|
|
Should not change anything. |
|
|
|
|
www.waraxe.us Forum Index -> Sql injection
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|