SQL Injection

From: Alex Harasic (aharasic@terra.cl)
Date: 02/20/02


Date: 20 Feb 2002 15:54:16 -0000
From: Alex Harasic <aharasic@terra.cl>
To: pen-test@securityfocus.com


('binary' encoding is not supported, stored as-is)


Hi, I was trying SQL Injection things and I ran into the
following problem:

http://www.targethost.com/test.asp?pm=')

And I get the following results:

Microsoft VBScript runtime error '800a000d'

Type mismatch: '[string: "'"]'

D:\WEBROOT\..\..\include\ConstantesDNAfs.inc,
line 53



Ok. Besides the Path Disclosure problem, I'm trying
to build a SQL Query but it seems the server won't
let me pass quotes ( ' ) to it.

If instead of sending ') as a parameter I just put a ', it
brings me back to the start page.

Is there any way to bypass this type mismatch
thing?, I could make sql queries work with other .asp
but not this one..


Alex S. Harasic
aharasic@terra.cl

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • RE: SQL
    ... Subject: SQL ... statement being executed in the ISS server ... > This list is provided by the SecurityFocus Security ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • RE: SQL
    ... Subject: SQL ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: SQL Injection
    ... The + signs are used for string concatenation in MS SQL Server. ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: Send output to file in SQL
    ... the main idea of my posting was to create a file using sql ... > This list is provided by the SecurityFocus Security ... > SecurityFocus' SIA service which automatically alerts you to ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • Re: SQL
    ... Subject: SQL ... SELECT * FROM tblUsers WHERE Username='admin'; ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)