The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws



Download 5,76 Mb.
Pdf ko'rish
bet514/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   510   511   512   513   514   515   516   517   ...   875
Bog'liq
3794 1008 4334

292

Chapter 9 



Injecting Code

70779c09.qxd:WileyRed  9/14/07  3:13 PM  Page 292



Oracle:

ORA-01790: expression must have same datatype

as corresponding expression

MS-SQL:


Msg 245, Level 16, State 1, Line 1

Syntax error converting the varchar value

‘foo’ to a column of data type int.

MySQL:


(MySQL will not give you an error.)

Translation:

You will see this when you are attempting a 

UNION SELECT

attack, and you have specified a different data type from that

found in the original 

SELECT

statement. Try using a 



NULL

, or


using 

1

or 



2000

.

Oracle:



ORA-01722: invalid number

ORA-01858: a non-numeric character was found

where a numeric was expected

MS-SQL:


Msg 245, Level 16, State 1, Line 1

Syntax error converting the varchar value

‘foo’ to a column of data type int.

MySQL:


(MySQL will not give you an error.)

Translation:

Your input doesn’t match the expected data type for the field. 

You may have SQL Injection, and you may not need a single

quote, so try simply entering a number followed by your SQL

to be injected.

In MS-SQL, you should be able to return any string value with

this error message.

Oracle:

ORA-00923: FROM keyword not found where

expected

MS-SQL:


N/A

MySQL:


N/A

Translation:

The following will work in MS-SQL:

SELECT 1


But in Oracle, if you want to return something, you must

select from a table. The 

DUAL

table will do fine:



SELECT 1 from DUAL

Oracle:


ORA-00936: missing expression

MS-SQL:


Msg 156, Level 15, State 1, Line 1

Incorrect syntax near the keyword ‘from’.




Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   510   511   512   513   514   515   516   517   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish