Web Hack List

Other nomination

Turning Blind Error Based MSSQL Injection into Exploitable Boolean One

Where a Microsoft SQL Server injection point returns no error text, the application differing redirect targets still reveal whether a query succeeded. Wrapping the IIF function inside a convert to char, so a true branch yields a convertible integer and a false branch yields a value that fails conversion, turns each guess into one bit and extracts data character by character.

Record

Researcher
Ozgur Alp and @ozgur_bbh
Published by
Medium
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Ozgur Alp and @ozgur_bbh, first published at the original source. Preserved copies are kept so the citation survives its host.