Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Sql-Injection and XSS on ASP.Net Internal Application |
|---|---|
| Date: | Mon, 6 Mar 2006 20:37:08 -0000 |
Hi.
André
Hi,
We are doing Penetration Testing, inclusive of Web Application Assessment, for our client's internal application. We have identified the OS as Windows 2003 server and Web server as IIS 6.0. The sever has ports number 80 and 443 open.
Now when I visit the site I get a login form. I insert a simple sql injection statement ' OR 1=1-- in username or password field and get the result below from the server:
Microsoft OLE DB Provider for ODBC Drivers error '80004005'
[Microsoft][ODBC Visual FoxPro Driver]Function name is missing ).
/home.asp, line 34
Does this mean that the backend database server is Visual FoxPro? I was hoping for an MSSQL server listeing at the backend.
I also did a simple XSS test on the username field <script>alert('vulnerable');</script> and got following:
Microsoft OLE DB Provider for ODBC Drivers error '80040e14'
[Microsoft][ODBC Visual FoxPro Driver]Command contains unrecognized phrase/keyword.
/home.asp, line 34
But nothing really popped up. So I don't think it is vulnerable to XSS. Maybe the error came due to the ' in the statement.
Looking forward to some inputs from SQL Injection champions and anyone who has some tricks in mind that I can play on this server.
Thanks.
------------------------------------------------------------------------------ This List Sponsored by: Lancope
"Discover the Security Benefits of Cisco NetFlow"
Learn how Cisco NetFlow enables cost-effective security across distributed
enterprise networks. StealthWatch, the veteran Network Behavior Analysis (NBA)
and Response solution, leverages Cisco NetFlow to provide scalable,
internal network security.
Download FREE Whitepaper "Role of Network Behavior Analysis (NBA) and Response
Systems in the Enterprise."
http://www.lancope.com/resource/ ------------------------------------------------------------------------------
------------------------------------------------------------------------------ This List Sponsored by: Cenzic
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Opening PKI encrypted with Public Key outside your Escrow Authority., Benson, Sean M |
|---|---|
| Next by Date: | Vulnerability discovered on Lotus Domino server "admin4.nsf", 3 shool |
| Previous by Thread: | Sql-Injection and XSS on ASP.Net Internal Application, 3 shool |
| Next by Thread: | Opening PKI encrypted with Public Key outside your Escrow Authority., Benson, Sean M |
| Indexes: | [Date] [Thread] [Top] [All Lists] |