Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Penetration Testing: Re: [PEN-TEST] Hacking SQL queries ...

Re: [PEN-TEST] Hacking SQL queries ...

From: Nicolas GREGOIRE <nicolas.gregoire_at_7THZONE.COM>
Date: Wed, 7 Feb 2001 23:13:37 +0100

"Aurobindo Sundaram (+1 512 918 1390)" a écrit :
>
> I have to audit a bit of code that does the following
>
> SELECT Name FROM Users WHERE Name LIKE '%input%' ORDER BY Name

Bad, so bad ...

Check r.f.p.'s PacketStorm hack
(http://www.wiretrip.net/rfp/p/doc.asp?id=42&iface=7)

The Perl module DBI doesn't allow several queries in one line.
So you can just insert some fields in the "where"
But with MS-SQL, all is possible (delete table, mail results, ...)

Nicob
Received on Feb 08 2001

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos