Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Security Basics: Table enumeration in mysql injection

Table enumeration in mysql injection

From: Matt Gibson <MattG_at_blueedgetech.ca>
Date: Wed, 2 Mar 2005 23:40:33 -0800

Hi everyone!

Working on some SQL injection to hone my skills, but I'm coming up
against a problem early on. I'm working on a mysql database, and it
seems I can directly inject into the url. However, since I don't know
the name of the table I'm on, I don't seem to be able to extract any
information from it. How does one go about determining the current
table, or even a list of all tables in the database?

Thanks!

-Matt
Received on Mar 03 2005

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]