Re: Oracle SQL Injection vulnerability

From: Zed Qyves (zqyves.spamtrap@gmail.com)
Date: Tue Nov 20 2007 - 05:04:40 EST


Hello,
Wild guess but can the username be numeric only rather thanalphanumeric as everyone expects? People often misconceive that theusername field as alpha while it may very well not be ...That wouldexplain why you are still getting the "ORA-01756: quoted string notproperly terminated" even when you appear to terminating correctly.what if you input "123 or 1=1--" (strip ") in the username field?
regards,./ZQ
-- ---------------------------------------------------------------------Κρέωνἐν τῇδ᾽ ἔφασκε γῇ· τὸ δὲ ζητούμενονἁλωτόν, ἐκφεύγειν δὲ τἀμελούμενον.Οιδίπους Τύρρανος [110]---------------------------------------------------------------------CreonIn this our land, so said he, those who seek Shall find; unsought, welose it utterly.Oedipus Rex [110]---------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:58:13 EDT