Re: SQL Cracking.....

From: Peter A. Schott (pschott@drivefinancial.com)
Date: 02/18/03


From: Peter A. Schott <pschott@drivefinancial.com>
Date: Tue, 18 Feb 2003 10:04:44 -0600


Can you use SQL Injection anywhere? :-) You can do ALL sorts of fun things
if the program's running under 'sa' and allows those wonderful dynamic queries
to filter through.

-Pete

"Denny" <mrdenny@gamespy.com> wrote:

> Remotly dump a sql script on the c drive (ports 135 and 139) then use at (or
> soon, or now from Resource Kit) to run osql and run the script that you just
> put there, or run a command line query with the -Q command. I'd recommend
> simumlating something nasty like dropping the db, or truncateing a table.
>
> Hope that works for you.



Relevant Pages

  • Re: Practical jokes for mainframe systems programmers
    ... then walk over and proceed to logon as normal. ... "command prompt" of the interactive system we used. ... people's reactions, while FUN was running, was FUN! ... send email to listserv@xxxxxxxxxxx with the message: GET IBM-MAIN INFO ...
    (bit.listserv.ibm-main)
  • Re: System call not acting as expected
    ... You seem to be expecting the latter behaviour, ... Why are you using commas there ... all sorts of fun problems, like having to sort out terminal escape ... > The result of this line confirms that it is generating exactly the command ...
    (comp.lang.perl.misc)
  • Big Website Hack Documented
    ... not a zombie virus floating around the net. ... That's the bad news. ... a command I typed earlier. ... Just for fun of course. ...
    (alt.computer.security)
  • Big Website Hack Documented
    ... not a zombie virus floating around the net. ... That's the bad news. ... a command I typed earlier. ... Just for fun of course. ...
    (comp.security.unix)
  • Re: CheckBox.Value executes Click function? - What the!
    ... have been a fun argument. ... checkbox program for DOS... ... I still write command line DOS stuff, very handy and the perfect choice ... I'd happily write a command line version of my "checkbox" program, ...
    (comp.lang.basic.visual.misc)