Re: PerlModule Apache::AuthDBI

From: Martin Eiszner (martin@websec.org)
Date: 01/09/03

  • Next message: Deus, Attonbitus: "Re: MS Terminal Services open to the world"
    Date: Thu, 9 Jan 2003 07:44:00 +0100
    From: Martin Eiszner <martin@websec.org>
    To: "Joe Luna" <joeluna@socal.rr.com>
    
    

    On Tue, 7 Jan 2003 17:29:55 -0800
    "Joe Luna" <joeluna@socal.rr.com> wrote:

    > the username/password which I'm assuming is some sort of administrative
    > account.
    > What I'm not sure of is the type of database or even how to connect
    > using the credentials gained from the conf file.
    > Any pointers?

    .. this tells you that they are using a postgreSql database.
    if you dont have a local account, postgresql might help you to get one.

    if you can find a single sql-injections flaw (http://www.owasp.org/asac/input_validation/sql.shtml)
    postgresql will supply you with anything you need. it supports multiple statements (1st'; your query; aso.)

    Mei
     

    mei@websec.org
    http://www.websec.org

    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
    Service. For more information on SecurityFocus' SIA service which
    automatically alerts you to the latest security vulnerabilities please see:
    https://alerts.securityfocus.com/



    Relevant Pages

    • Re: How to setup STORE depository visible to the internet?
      ... This is a Microsoft Windows question more than a PostgreSQL or Smalltalk ... stop services (e.g. you are have an admin account). ... It owns the 'postgres database'. ... I use my own account as the store admin account. ...
      (comp.lang.smalltalk)
    • Re: PostgreSQL Connection
      ... >> I am trying to connect to a PostgreSQL database using asp. ... > I am not familiar with PostgreSQL, but i do have a couple comments. ... The connection stringworks fine in a UDL file but it doesn't ... This email account is my spam trap so I ...
      (microsoft.public.inetserver.asp.db)
    • RE: XSS LAB DEMO IDEAS
      ... User registers, providing their account details, locations, etc. ... Subject: XSS LAB DEMO IDEAS ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
      (Pen-Test)
    • Re: PerlModule Apache::AuthDBI
      ... This is a Postgres database. ... access with the privileges of the web server UID. ... > This list is provided by the SecurityFocus Security Intelligence Alert ...
      (Pen-Test)
    • RE: Password HTML form bruteforce
      ... print Positive Authentication with Login: ACCOUNT, ... >> This list is provided by the SecurityFocus Security Intelligence ... For more information on SecurityFocus' SIA service which ... automatically alerts you to the latest security vulnerabilities please see: ...
      (Pen-Test)