RE: sql injection with order by

From: Ernest Nelson (juridian_at_juridian.com)
Date: 04/09/05

  • Next message: Byron L. Sonne: "Re: Fingerprinting Firewall"
    To: "'dietf dietf'" <dietf@yahoo.com>, <pen-test@securityfocus.com>
    Date: Fri, 8 Apr 2005 15:30:06 -0700
    
    

    Adding the '--' comments out everything after the sql you're putting in. It
    won't work without it because you are getting a syntax error on what you are
    trying to run.

    -----Original Message-----
    From: dietf dietf [mailto:dietf@yahoo.com]
    Sent: Thursday, April 07, 2005 8:52 PM
    To: pen-test@securityfocus.com
    Subject: sql injection with order by

    Hi all,
    I am trying to make an injection with the statement below,

    SQL = "SELECT ProID, CusID, Name FROM ProTur WHERE Lan=0 AND
    CusID='%Customer%' ORDER BY Sira, ProjeTurID"

    in the statement above I inject ")select @@version-- for the variable
    Customer. But unless I have ended inject code with -- nothing happens.
    I get
    SQL = "SELECT ProID, CusID, Name FROM ProTur WHERE Lan=0 AND
    FirmaID=")select @@version-- ORDER BY Sira, ProjeTurID"
    what is the problem? can anybody tell me?
    Is the problem occurs from the word ORDER BY?
    Thanks


  • Next message: Byron L. Sonne: "Re: Fingerprinting Firewall"

    Relevant Pages

    • Official release of SQL Power Injector 1.2
      ... One of the major improvements is an innovative way to optimize and accelerate the dichotomy in the Blind SQL injection, saving time/number of requests up to 25%. ... Also another great time saver is a new Firefox plugin that will launch SQL Power Injector with all the information of the current webpage with its session context. ... No more time wasted to copy paste the session cookies after you logged... ...
      (Bugtraq)
    • Official release of SQL Power Injector 1.2
      ... One of the major improvements is an innovative way to optimize and accelerate the dichotomy in the Blind SQL injection, saving time/number of requests up to 25%. ... Also another great time saver is a new Firefox plugin that will launch SQL Power Injector with all the information of the current webpage with its session context. ... No more time wasted to copy paste the session cookies after you logged... ...
      (Pen-Test)
    • Official release of SQL Power Injector 1.2
      ... One of the major improvements is an innovative way to optimize and accelerate the dichotomy in the Blind SQL injection, saving time/number of requests up to 25%. ... Also another great time saver is a new Firefox plugin that will launch SQL Power Injector with all the information of the current webpage with its session context. ... No more time wasted to copy paste the session cookies after you logged... ...
      (Security-Basics)
    • [Full-disclosure] OTRS 1.x/2.x Multiple Security Issues
      ... OTRS, the Open Source Ticket Request System, is a trouble ... ranging from cross site scripting to SQL injection. ... A malicious user may be able to conduct blind SQL code ... an attacker may be able to exploit this issue. ...
      (Full-Disclosure)
    • Official release of SQL Power Injector 1.1
      ... I have the pleasure to announce that a new version of SQL Power Injector is now officially available on my web site: ... For now it is SQL Server, Oracle and MySQL compliant, but it is possible to use it with any existing DBMS when using the inline injection (Normal ... Response of the SQL injection in a customized browser ...
      (Pen-Test)