Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

SQL Injection Basics

From: <raul.johhut(at)hushmail.com>
Date: Sat Feb 08 2003 - 20:21:47 EST

I am pen testing a webapp and am having some problems with SQL injection.

The app creates an ODBC error. Is this a garuntee of SQL Injection ?

If I use www.victim/test.asp?userid=sfdsd

the error is "inncorrect syntax near line 28 of test.asp" (or thats the English translation equiv in my case).

I know the database is called master, and has a table test. What is the syntax I should use ?

What are the best freeware and open source tools for testing SQL injection ? I tried WPosion which was OK.

I also tried WebSleuth (which seems to have gone from GPL to closed source commercial btw). Am I right is saying that the SQL plugin has to connect directly to the database to work ? I can only see port 80 so don't think this will work ?

Do you need help?X

Thanks, Raul.

Concerned about your privacy? Follow this link to get FREE encrypted email: https://www.hushmail.com/?l=2

Big $$$ to be made with the HushMail Affiliate Program: https://www.hushmail.com/about.php?subloc=affiliate&l=427 Received on Sat Feb 8 20:24:42 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:48 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library