Security Basics mailing list archives

Table enumeration in mysql injection


From: "Matt Gibson" <MattG () blueedgetech ca>
Date: Wed, 2 Mar 2005 23:40:33 -0800

Hi everyone!

Working on some SQL injection to hone my skills, but I'm coming up
against a problem early on.  I'm working on a mysql database, and it
seems I can directly inject into the url.  However, since I don't know
the name of the table I'm on, I don't seem to be able to extract any
information from it.  How does one go about determining the current
table, or even a list of all tables in the database?

Thanks!

-Matt



Current thread: