Penetration Testing mailing list archives

Re: Oracle SQL Injection vulnerability


From: "Zed Qyves" <zqyves.spamtrap () gmail com>
Date: Tue, 20 Nov 2007 12:04:40 +0200

Hello,

Wild guess but can the username be numeric only rather than
alphanumeric as everyone expects? People often misconceive that the
username field as alpha while it may very well not be ...That would
explain why you are still getting the "ORA-01756: quoted string not
properly terminated" even when you appear to terminating correctly.
what if you input "123 or 1=1--" (strip ") in the username field?

regards,
./ZQ

-- 
---------------------------------------------------------------------
Κρέων
ἐν τῇδ᾽ ἔφασκε γῇ· τὸ δὲ ζητούμενον
ἁλωτόν, ἐκφεύγειν δὲ τἀμελούμενον.
Οιδίπους Τύρρανος [110]
---------------------------------------------------------------------
Creon
In this our land, so said he, those who seek  Shall find; unsought, we
lose it utterly.
Oedipus Rex [110]
---------------------------------------------------------------------

Current thread: