Cenzic 232 Patent
Paid Advertising
sla.ckers.org is
ha.ckers sla.cking
Sla.ckers.org
How do you completely compromise a machine given a text box or badly validated input box? This is a place to talk about code issues (PHP includes, null byte injection, backticks, pipe, etc...) as well as how to properly construct an SQL injection attack. 
Go to Topic: PreviousNext
Go to: Forum ListMessage ListNew TopicSearchLog In
sql injection for converted fields..how?
Posted by: huz
Date: March 28, 2012 10:19AM

hello guys.. i have an app.. usually in the login page we put the hi' or 1=1-- in the username field rite? but how if anything that being put in the username will be converted into integer??

when i put hi' or 1=1--, the server will show Error:for input string....
putting the tautology in the password field may be not suitable because lets say i put the id = 3, when i bypassed the login the id will be different.. it is very weird..what happen actually?

anyone has the idea how to bypass that? tq :)

Options: ReplyQuote


Sorry, only registered users may post in this forum.