Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Web Application Security
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
RE: SQL injection (no single quotes used) Dec 15 2004 11:12PM
Brett Moore (brett moore security-assessment com)
> Thanks and sorry for sending a not so tested POC to
> all of you.

Don't be... I often use the CR/LF pairs to bypass filters
in SQL (against MS SQL). %0a%0d can sometimes work, but it
is better to send the 'raw' bytes as a post. Using a
textarea field works great for this.

The GO statement, (from...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus