RE: MS SQL, find list of tables

From: BHAI JAINUDDINBHAI, TRUNKWALA KUTBUDDIN (TRUNKWALA KUTBUDDIN)** CTR ** (qutub_at_lucent.com)
Date: 09/28/05

  • Next message: Tim Hurman: "Exploring Windows CE Shellcode"
    To: pen-test@securityfocus.com
    Date: Wed, 28 Sep 2005 10:54:58 +0530
    
    

    I don't think there is an easy way to get the list of tables on the db u r
    testing.
    Use trial and error to try all the table names that are likely be used for
    storing user information. If the application u r testing is based on an open
    source software, it will be easy to get the default db schema by downloading
    the application from the respective website.

    -----Original Message-----
    From: Cedric Foll [mailto:cedric.foll@ac-rouen.fr]
    Sent: Monday, September 26, 2005 7:31 PM
    To: pen-test@securityfocus.com
    Subject: MS SQL, find list of tables

    Hi,

    I'm doing a pen test on a IIS/MS SQL box and find a SQL Injection on it
    which permit to execute some SQL command on it.

    In fact I have a "select" where I can inject an "UNION something".
    I'd like to use that in order to get login/passwd in the database.

    I can do:
    <somethin.asp?page=contact' UNION SELECT * FROM users WHERE '1'='1>
    But the table users doesn't exist and I failed to guess an existing
    table name :(.

    I've tried:
    <something.asp?page=contact' UNION SELECT * FROM MSysObjects'>
    but I get

    ----
    Microsoft OLE DB Provider for ODBC Drivers error '80040e09'
    [Microsoft][ODBC Microsoft Access Driver] Record(s) cannot be read; no
    read permission on 'MSysObjects'.
    ----
    Someone has an idea ????
    Regards
    -- 
    Cedric Foll
    Ingénieur Sécurité & Réseaux
    Division Informatique, Rectorat de Rouen
    "More people are killed every year by pigs than by sharks,
    which shows you how good we are at evaluating risk."
    Bruce Schneier
    ----------------------------------------------------------------------------
    --
    Audit your website security with Acunetix Web Vulnerability Scanner: 
    Hackers are concentrating their efforts on attacking applications on your 
    website. Up to 75% of cyber attacks are launched on shopping carts, forms, 
    login pages, dynamic content etc. Firewalls, SSL and locked-down servers are
    futile against web application hacking. Check your website for
    vulnerabilities 
    to SQL injection, Cross site scripting and other web attacks before hackers
    do! 
    Download Trial at:
    http://www.securityfocus.com/sponsor/pen-test_050831
    ----------------------------------------------------------------------------
    ---
    ------------------------------------------------------------------------------
    Audit your website security with Acunetix Web Vulnerability Scanner: 
    Hackers are concentrating their efforts on attacking applications on your 
    website. Up to 75% of cyber attacks are launched on shopping carts, forms, 
    login pages, dynamic content etc. Firewalls, SSL and locked-down servers are 
    futile against web application hacking. Check your website for vulnerabilities 
    to SQL injection, Cross site scripting and other web attacks before hackers do! 
    Download Trial at:
    http://www.securityfocus.com/sponsor/pen-test_050831
    -------------------------------------------------------------------------------
    

  • Next message: Tim Hurman: "Exploring Windows CE Shellcode"

    Relevant Pages

    • RE: 3rd party vuln assesment firms
      ... > "We use the same tools hackers bring to bear against your systems. ... >> I'm looking for a firm to conduct annual 3rd party vulnerability ... Up to 75% of cyber attacks are launched on shopping ... >> your website for vulnerabilities to SQL injection, ...
      (Pen-Test)
    • RE: 3rd party vuln assesment firms
      ... > "We use the same tools hackers bring to bear against your systems. ... >> I'm looking for a firm to conduct annual 3rd party vulnerability ... Up to 75% of cyber attacks are launched on shopping ... >> your website for vulnerabilities to SQL injection, ...
      (Pen-Test)
    • RE: Penetration test of 1 IP address
      ... Before I do anything very intrusive I personally go to the website ... Also remember once you have found a vulnerability, ... Hackers are concentrating their efforts on attacking applications on ... Up to 75% of cyber attacks are launched on shopping ...
      (Pen-Test)
    • Re: Whitespace in passwords
      ... input password is alphanumeric + special characters -- chances are strong ... >> Hackers are concentrating their efforts on attacking applications on ... Up to 75% of cyber attacks are launched on shopping ... >> your website for vulnerabilities to SQL injection, ...
      (Pen-Test)
    • Re: Qualys
      ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Hackers are concentrating their efforts on attacking applications on ... Up to 75% of cyber attacks are launched on shopping carts, ...
      (Pen-Test)