[Full-disclosure] MS Access SQL injection column enumeration

From: Akash Shrivastava (Akash.Shri_at_in.ibm.com)
Date: 10/20/05

  • Next message: SPI Labs: "[Full-disclosure] Oracle 10g - emagent.exe Stack-Based Overflow"
    To: full-disclosure@lists.grok.org.uk
    Date: Thu, 20 Oct 2005 11:54:01 +0530
    
    
    

    Hi,

    I am trying SQL Injection on one of my own developed Web Application. This
    Application uses MS Access Database. I treid so many methods like using
    strings (', ", " OR 1=1 -- etc) as well as commands like

    SELECT Name, from MSysObjects where Type=1 (with or without " before
    SELECT), but all I got in return is that usrname n pwd is invalid. It
    means the query

    is somewhere working n not not entirely wrong. Can you please help me
    regarding this? Thanks.

    Regards,

    Akash Shrivastava
    Sr. IT Security Analyst,
    IBM Global Services
    EGL - C Block, Level 0,
    Off Koramangala Intermediate Ring Road,
    Bangalore
    India. 560 071
    Phone: 91-80-5192 7990
    Mobile: +91 988099 4169
    Availability: 11:00 AM - 20:00 PM IST

    "Great Minds don't think alike...
    But they DO think to get ahead."

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/


  • Next message: SPI Labs: "[Full-disclosure] Oracle 10g - emagent.exe Stack-Based Overflow"