sign in • sign up
web | myLot | discussions | blogs | news | photos
homeinterestsdiscussionsblogsnewsmessages friendsphotosearningsmyLot

Will SQL injections get me into trouble? email this discussion to a friend?

myLot reputation of 92/100. oyenkai (396)   ranked 45 out of 81 in software developer3 months ago

I subscribed to a site and when I was accessing my account, I found out that it wasn't as secure as it should be.

On the email textbox, I inputted a jo'hn@smith.com and received an SQL Error on the next page. I wanted to try more elaborate SQL injections - the ones that I am just learning right now but I figured that there might be laws against this and I don't want to get into trouble.

 
 
software developer
sponsors
Aspx Errors
Free Download: Aspx Errors Repair Tool. 100% Safe& Guaranteed.
AspxErrors.FreshPCFix.com

Psychic Love Answers Now
Accurate Psychic Readings only $10 - Call Now 1-866-574-5971.
www.LoveAnswersNow.com

Answer Your Bankruptcy Questions
Bankruptcy Questions and answers provided by a qualified and experienced attorney for all chapters of bankruptcy with over 20 years experience.
www.bankrupt-law.com

mr_mlk (228) response was accepted on 9/8/2008.
denotes best response.
tags:  sql, technology, hack, geek, security
 
1. myLot reputation of 91/100. repzkoopz (952)   ranked 17 out of 81 in software developer   3 months ago

hmmm.. this is pretty much a wild guess.. but i think the ' causes the trouble. you mentioned that you got an error when you put jo'hn@smith.com on the email textbox. in SQL coding, the use of ' or " means whatever is in between two of these is a string.
(i hope i'm on the right track here.. happy)


myLot reputation of 92/100. oyenkai (396)   ranked 45 out of 81 in software developer  3 months ago

Yeah, I actually understood what the error was. It's just that things like that kinda make you itch and wanna see how far you can get.

So if I try a few more stuff in the log in, will I get in trouble? I mean against the law kind of trouble.


myLot reputation of 91/100. repzkoopz (952)   ranked 17 out of 81 in software developer  3 months ago

naaaahh.. erroneous login doesn't exactly qualify as a violation. you're not hacking the website in any way with this. wink


myLot reputation of 92/100. oyenkai (396)   ranked 45 out of 81 in software developer  3 months ago

but I want to try to log in as admin o.o because I think their system is THAT vulnerable.

It just so happens that I've been reading a lot about SQL injections since I want to make sure that the system we're developing is secure. That's why I have a few scripts that I was itching to try. There was this one log in string that actually took more than 10 seconds to load so I decided to stop the browser because I thought it was actually retrieving everything...


myLot reputation of 91/100. repzkoopz (952)   ranked 17 out of 81 in software developer  3 months ago

hmmm.. seems like you're a specialist in this field. i guess the best you could do is contact the webmaster and tell them what you intend to do. besides, it'll be quite useful for them since you might be pointing out to a particular security flaw in their. who knows, your instincts might just be right. c",)


myLot reputation of 92/100. oyenkai (396)   ranked 45 out of 81 in software developer  3 months ago

I actually did that but I have not received any response. I gave them the right information to catch the bug. However, when I tried signing up for a different but similar site, I observed that they had the same layout. So now I'm thinking it's a scam, if it is then my email will never get any response.

I guess that's just too bad.


myLot reputation of 91/100. repzkoopz (952)   ranked 17 out of 81 in software developer  3 months ago

I actually did that but I have not received any response. I gave them the right information to catch the bug. However, when I tried signing up for a different but similar site, I observed that they had the same layout. So now I'm thinking it's a scam, if it is then my email will never get any response.

I guess that's just too bad.

hmmm.. scam huh.. lemme guess.. are these sites "money-earning" sites? if so then its either the site owners don't care, too busy, or probably your email even went to the spam folders of their webmail.
we can give them the benefit of a doubt, but hey, they may really be scam sites.. rolleyes

Aspx Errors Free Download: Aspx Errors Repair Tool. 100% Safe & Guaranteed. AspxErrors.FreshPCFix.com
 
2. myLot reputation of 83/100. mr_mlk (228)   ranked 30 out of 81 in software developer   3 months ago

Get you in trouble - no, the site might mouth off but unless you actively start putting stuff like '; delete from tuser;(1) they will not be able to do anything. Inform the website and find a different provide.


1) Unless that is you name. [ http://xkcd.com/327/]

Psychic Love Answers Now Accurate Psychic Readings only $10 - Call Now 1-866-574-5971. www.LoveAnswersNow.com
 
sponsors
Internet Answering Services
Catch-A-Call allows you to receive and answer incoming calls and faxes while you are online. No need for a second phone line. Satisfaction Guaranteed.
www.gadgetshack.com

Let Us Be There When You Can't
Rite Response Telemessaging, A full Service Center, celebrating 17 years. Live "Quality" Answering 24/7 for Commercial, Professional, Medical, large or small. BBB Member.
www.riteresponse.com

answering office phone virtual
Find providers of answering services in our directory.
www.business.com

similar discussions
In Demand IT Job
I am starting to enhance my programming skills but with so much available tools in the market, I am...
PTC database
Can someone please help? I have installed a script for a new PTC site but i do not have a sql...
For IT developers
Hello, I just want to notice, that if someone need help in PHP, Delphi, SQL, or any programing...
SQL Problem
Anyone good at SQL? I'm sort of stuck with a problem at work. I work with a huge database with 10s...
SQL Server..
Is there anyone who is familiar with the SQL Server? We use SQL Server as the backend for our...
How can we send mail from Sql Server?
how can we send mail from Sql Server? what are the configuration setting we have to be followed for...
How many of you can write SQL queries?
I have learned oracle database along with writing queries using PLSQL. How many of you familier...
what's difference in java.sql and javax.sql package?
Is there any one tell me the difference between the java.sql and javax.sql package?.i know a little...
sponsors
Internet Answering Services
Catch-A-Call allows you to receive and answer incoming calls and faxes while you are online. No need for a second phone line. Satisfaction Guaranteed.
www.gadgetshack.com
Let Us Be There When You Can't
Rite Response Telemessaging, A full Service Center, celebrating 17 years. Live "Quality" Answering 24/7 for Commercial, Professional, Medical, large or small. BBB Member.
www.riteresponse.com
answering office phone virtual
Find providers of answering services in our directory.
www.business.com
Answer Racing Products
Come see the complete line of Answer riding apparel.
www.gmo1.com
How Long Are You Going To Sit There?
Learn simple system that allows us to get paid to have fun.
www.AchieveProsperityToday.com
Free Psychic Answers
Love, Money, Future and much more. Solve your Questions now for Free.
www.Free-Astrology-Reports.com
Office Suites PLUS
Providing a full line of services designed to keep you and your costumers connected. Services include personalized telephone answering services as well as call screening and call forwarding.
www.officesuitesplus.com
Vtech Answering Machine
Buy Today! Vtech Phones w/ Digital Answering Machine. Free Shipping.
Vtech.FactoryOutletStore.com