Penetration Testing mailing list archives
SQL injection question
From: John <clrsky00 () yahoo com>
Date: Tue, 20 Jan 2004 20:42:06 -0800 (PST)
Hi i'm trying out SQL injection following David Litchfield's papers... All is going well, but if the Web server strip away all the space characters in the POST data, then SQL injection seems imposible. i tried to use %20, \20 etc.. but it don't seems to work any suggestions? c __________________________________ Do you Yahoo!? Yahoo! Hotjobs: Enter the "Signing Bonus" Sweepstakes http://hotjobs.sweepstakes.yahoo.com/signingbonus --------------------------------------------------------------------------- ----------------------------------------------------------------------------
Current thread:
- RE: SQL Injection question, (continued)
- RE: SQL Injection question Yvan Boily (Jan 05)
- Re: SQL Injection question Adam Tuliper (Jan 05)
- Reverse Engineering thoughts n30 (Jan 07)
- Re: Reverse Engineering thoughts Riad S. Wahby (Jan 07)
- Re: Reverse Engineering thoughts johnny cyberpunk (Jan 07)
- RE: Reverse Engineering thoughts Brett Moore (Jan 07)
- Re: Reverse Engineering thoughts Adam Tuliper (Jan 07)
- RE: SQL Injection question Yvan Boily (Jan 05)
- RE: SQL Injection question Tibor Biro (Jan 05)
- RE: SQL Injection question Lachniet, Mark (Jan 05)
- RE: SQL Injection question Scovetta, Michael V (Jan 05)
- SQL injection question John (Jan 21)
- Re: SQL injection question .Saphyr (Jan 22)
