lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Thu Oct 20 17:58:14 2005
From: Akash.Shri at in.ibm.com (Akash Shrivastava)
Subject: MS Access SQL injection column enumeration

Hi,

I am trying SQL Injection on one of my own developed Web Application. This 
Application uses MS Access Database. I treid so many methods like using 
strings (', ", " OR 1=1 -- etc) as well as commands like 

SELECT Name, from MSysObjects where  Type=1 (with or without " before 
SELECT), but all I got in return is that usrname n pwd is invalid. It 
means the query 

is somewhere working n not not entirely wrong. Can you please help me 
regarding this? Thanks.


Regards,

Akash Shrivastava
Sr. IT Security Analyst,
IBM Global Services
EGL -  C Block, Level 0,
Off Koramangala Intermediate Ring Road,
Bangalore 
India. 560 071
Phone: 91-80-5192 7990
Mobile: +91 988099 4169
Availability: 11:00 AM - 20:00 PM IST

"Great Minds don't think alike... 
But they DO think to get ahead."
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20051020/f38e7c4f/attachment.html

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ