SQL-Injection escape ')'

From: Strcpy (elite_netbios_at_yahoo.com)
Date: 07/03/04

  • Next message: Martin S: "Raptor firewall 6.1 port 80"
    Date: Sat, 3 Jul 2004 07:45:36 -0700 (PDT)
    To: pen-test@securityfocus.com
    
    

    Hi list .

    I`m working on a web-application for vulnerability
    assesments in order to complete a pen-test job.

    there is a vulnerable query there but I can`t escape
    it ad use it to go farther .
    the page script add a ')' to end of query string
    always.
    I tried to pass it by useing # or -- or ')'=')' at the
    end of my query strings , but non worked :/

    here is an example :
    i sent this :
    A') select name from sysobjects where xtype='U'--

    [Microsoft][ODBC Microsoft Access Driver] Syntax
    error. in query expression 'city_name='Tehran' and
    (agency_english ='A') select name from sysobjects
    where xtype='U'--')'

    would you mind please help me ?

    [sorry for poor English]

    thnq all

                    
    __________________________________
    Do you Yahoo!?
    Yahoo! Mail - 50x more storage than other providers!
    http://promotions.yahoo.com/new_mail


  • Next message: Martin S: "Raptor firewall 6.1 port 80"

    Relevant Pages

    • October 01, 2007 From "To Do" to "Done" in One Search
      ... That sums up Yahoo! ... Search experience that gets users the answers ... the real-time query suggestions we launched on Yahoo.com in July. ... Video, in addition to the link you get an inline ...
      (alt.internet.search-engines)
    • DSQuery on active directory
      ... more precisely, DSQUERY and others like dsmod, dsget ... I'm looking for a way to only allow administrators or ... Is there any way to limit who can query what? ... Do you Yahoo!? ...
      (Focus-Microsoft)
    • Re: Reformat Group membership table
      ... CROSS JOIN sysobjects s2 ... I would like to run SQL queries that returns a result set which has all ... believe I can do this effectively is to reformat the table to a format ... I'm looking for suggestions on how I can accomplish my SQL query... ...
      (microsoft.public.sqlserver.programming)
    • Re: Import External Date/Web query problem
      ... I like the WEB Query methos ... "Don Guillett" wrote: ... data from my Yahoo stock portfolio. ... MSN and also got the same results from a stock portfolio I set up there. ...
      (microsoft.public.excel)
    • Re: Import External Date/Web query problem
      ... Please feel free to goto the files section of xltrader yahoo group and look ... "Don Guillett" wrote: ... I have redone the query with the same results. ... MSN and also got the same results from a stock portfolio I set up ...
      (microsoft.public.excel)