MS SQL injection



Colleagues,
I have a basic understanding of sql injection for ms sql, but on
this recent pen test the methods I have used in the past aren't
cutting it.

I was able to enumerate the table name and columns utilizing the '
having 1=1;-- and ' group by x,x,x,x having 1=1;--, but once I got all
of the column names on the group by list it issued the following error
instead of returning without an error. "Microsoft][ODBC SQL Server
Driver][SQL Server]Unclosed quotation mark before the character string
' '." Any ideas on what I need me to do to overcome this problem?

Thanks guys

--
Michael Klingler, CISSP
SecurityMetrics Penetration Tester

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------



Relevant Pages

  • Re: Sql injection automated check tool
    ... Don't forget blind sql inyection tool bsqlbf at: ... Cenzic Hailstorm finds vulnerabilities fast. ... Click the link to buy it, try it or download Hailstorm for FREE. ...
    (Pen-Test)
  • RE: Sql injection automated check tool
    ... SQL Power Injector: http://www.sqlpowerinjector.com/ ... Cenzic Hailstorm finds vulnerabilities fast. ... Click the link to buy it, try it or download Hailstorm for FREE. ...
    (Pen-Test)
  • RE: (illegal?) Informing Companies about security vulnerabilities...
    ... Someone said you have to see sensitive data to validate SQL ... That is SQL Injection. ... Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)
  • Re: RE: Informing Companies about security vulnerabilities...
    ... he said that he was doing XXS and SQL injections on someone else's web site. ... --when you get the script alert testing XSS is that seeing private data? ... Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)
  • Re: DateCreated
    ... and then for good measure I tried cutting the SQL right ... I posted a follow-up. ... I will see if I can knock something together to prove it. ...
    (microsoft.public.vb.database.ado)