WebApp Sec mailing list archives

Re: Simplifying enumeration by error messages


From: Paul Johnston <paj () pajhome org uk>
Date: Thu, 29 Nov 2007 20:40:37 +0000

Hi Patrik,

I have published a brief article on how enumeration of database
information through error messages could be simplified.
Nice, I like it. You could also look at using row_number() to do the equivalent of your count(*) subquery.

Happy hacking,

Paul

-------------------------------------------------------------------------
Sponsored by: Watchfire Methodologies & Tools for Web Application Security Assessment With the rapid rise in the number and types of security threats, web application security assessments should be considered a crucial phase in the development of any web application. What methodology should be followed? What tools can accelerate the assessment process? Download this Whitepaper today!
https://www.watchfire.com/securearea/whitepapers.aspx?id=70170000000940F
-------------------------------------------------------------------------


Current thread: