[sqlmap-users] Search tables MySQL exception

2011-08-02 Thread anonymous anonymous
[01:06:54] [CRITICAL] unhandled exception in sqlmap/1.0-dev (r4324), retry your run with the latest development version from the Subversion repository. If the exception persists, please send by e-mail to sqlmap-users@lists.sourceforge.net the following text and any information required to reproduce

Re: [sqlmap-users] injection into cookies

2011-08-02 Thread Robin Wood
On 2 August 2011 18:30, Miroslav Stampar wrote: > hi Robin > > you'll need to give a valid Cookie with > --cookie="&ASP.NET_SessionId=1FA...&..." and use -p > "ASP.NET_SessionId" > > thing is that when level < 4 we ignore session-like parameters in > default cases. so, either you can use expli

Re: [sqlmap-users] injection into cookies

2011-08-02 Thread Miroslav Stampar
hi Robin you'll need to give a valid Cookie with --cookie="&ASP.NET_SessionId=1FA...&..." and use -p "ASP.NET_SessionId" thing is that when level < 4 we ignore session-like parameters in default cases. so, either you can use explicit -p "ASP.NET_SessionId" or you can use --level=4. in your ca

[sqlmap-users] injection into cookies

2011-08-02 Thread Robin Wood
Hi I've got an application that is vulnerable to SQLi in one of two cookie parameters. The one that is injectable is the ASP.NET_SessionId which has to start with a valid session id but then if given an extra ' on the end it fails and dumps out a nice SQL error. So what I need to do is to tell sql

Re: [sqlmap-users] --union-char

2011-08-02 Thread Ahmed Shawky
Thanks guys for the response. Miroslav Stampar, I'm gonna send you the link :) On Tue, Aug 2, 2011 at 10:40 AM, Bernardo Damele A. G. < bernardo.dam...@gmail.com> wrote: > Hi Ahmed, > > On 2 August 2011 06:09, Ahmed Shawky wrote: > > guys is there an option to provide --union-char argument with

Re: [sqlmap-users] --union-char

2011-08-02 Thread Bernardo Damele A. G.
Hi Ahmed, On 2 August 2011 06:09, Ahmed Shawky wrote: > guys is there an option to provide --union-char argument with a range of > integers something like --union-char range(1,30) as in some cases NULL > character isn't valid and providing a single character doesn't do the job No, it's not possi

Re: [sqlmap-users] Error

2011-08-02 Thread Bernardo Damele A. G.
Hi Brad, Please find it fixed now. Thanks for reporting. Bernardo On 2 August 2011 04:11, Brad Merrell wrote: > [WARNING] unknown charset 'th'. Please report by e-mail to > sqlmap-users@lists.sourceforge.net. > > Website: http://www.dutchiefanclub.com/newsdetail.php?id=66 > ---

[sqlmap-users] Error

2011-08-02 Thread Brad Merrell
[WARNING] unknown charset 'th'. Please report by e-mail to sqlmap-users@lists.sourceforge.net. Website: http://www.dutchiefanclub.com/newsdetail.php?id=66 -- BlackBerry® DevCon Americas, Oct. 18-20, San Francisco, CA The