Yash Kadakia
Office: +91-022-23612909
Office: +1-347-99-ITSEC (+1-347-994-8732)
Mobile: +91-9833375290
Blog: http://www.yashkadakia.com/
Sent on my BlackBerry® from Vodafone
Yash Kadakia
Office: +91-022-23612909
Office: +1-347-99-ITSEC (+1-347-994-8732)
Mobile: +91-9833375290
Blog: http://www.yashkadakia.com/
Sent on my BlackBerry® from Vodafone
Sent from BlackBerry® - Vodafone
Let me know if you got it working.
-
TAS
http://twitter.com/p0wnsauc3
--
null - Spreading the right Information
null Mailing list charter: http://null.co.in/section/about/null_list_charter/
This list is supported by Institute of Information Security http://iisecurity.in
Learn information security at your own pace – eLearning programs at http://elearning.iisecurity.in
first give the valid input and try to close the bracket and then you can execute the query
input) ; then query
try possible combos
like
)input
----------
Sent via Nokia Email
------Original message------
From: TAS <p0wn...@gmail.com>
To: <null-...@googlegroups.com>
Date: Wednesday, May 18, 2011 10:44:25 AM GMT+0530
Subject: Re: [null] Oracle SQL injection
valid_input UNION SQL QUERY ') --
It will be good if you able to find what procedure or function gives the error
--
null - Spreading the right Information
null Mailing list charter: http://null.co.in/section/about/null_list_charter/
This list is supported by Institute of Information Security http://iisecurity.in
Learn information security at your own pace – eLearning programs at http://elearning.iisecurity.in