Re: MS SQL, find list of tables

From: Cedric Foll (cedric.foll_at_ac-rouen.fr)
Date: 09/27/05

  • Next message: Ofer Maor: "RE: MS SQL, find list of tables"
    Date: Tue, 27 Sep 2005 17:10:04 +0200
    To: pen-test@securityfocus.com
    
    

    Cedric Foll a écrit :
    > Hi,
    >
    > I'm doing a pen test on a IIS/MS SQL box and find a SQL Injection on it
    > which permit to execute some SQL command on it.

    Sorry did a mistake. It's a MS Access database behind.
    BTW, is it possible to list tables ?
    Which tables or procedure are by default in a MS Access databases ?

    Regards.

    -- 
    Cedric Foll
    Ingénieur Sécurité & Réseaux
    Division Informatique, Rectorat de Rouen
    "More people are killed every year by pigs than by sharks,
    which shows you how good we are at evaluating risk."
    Bruce Schneier
    ------------------------------------------------------------------------------
    Audit your website security with Acunetix Web Vulnerability Scanner: 
    Hackers are concentrating their efforts on attacking applications on your 
    website. Up to 75% of cyber attacks are launched on shopping carts, forms, 
    login pages, dynamic content etc. Firewalls, SSL and locked-down servers are 
    futile against web application hacking. Check your website for vulnerabilities 
    to SQL injection, Cross site scripting and other web attacks before hackers do! 
    Download Trial at:
    http://www.securityfocus.com/sponsor/pen-test_050831
    -------------------------------------------------------------------------------
    

  • Next message: Ofer Maor: "RE: MS SQL, find list of tables"

    Relevant Pages

    • Re: sql injection: url or form based?
      ... start putting your SQL injection magic in the input boxes to ... Hackers are concentrating their efforts on attacking applications ... Check your website for vulnerabilities to SQL injection, ... Cross site scripting and other web attacks before hackers do! ...
      (Pen-Test)
    • Re: database server audit tools
      ... This thing was pretty limited last time I looked at it, and had no database audit capabilities. ... this is a nice SQL injection testing tool. ... >Audit your website security with Acunetix Web Vulnerability Scanner: ... Cross site scripting and other web attacks before hackers do! ...
      (Pen-Test)
    • RE: MS SQL, find list of tables
      ... I'm doing a pen test on a IIS/MS SQL box and find a SQL Injection on it ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Hackers are concentrating their efforts on attacking applications on your ... Up to 75% of cyber attacks are launched on shopping carts, forms, ...
      (Pen-Test)
    • RE: sql injection: url or form based?
      ... I see many references to manipulation of SQL backend databases through both URL based and Forms based SQL injection but I'm wondering what are the ... Hackers are concentrating their efforts on attacking applications on your website. ... Up to 75% of cyber attacks are launched on shopping carts, forms, login pages, dynamic content etc. Firewalls, SSL and locked-down servers are ...
      (Pen-Test)
    • Re: sql injection: url or form based?
      ... start putting your SQL injection magic in the input boxes to ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Cross site scripting and other web attacks before hackers do! ...
      (Pen-Test)