Is my website vulnerable to SQL injection ???

alpha5
10 years ago | edited 10 years ago

0

Hello.
I have a personal site created in ASP.
When I try to see if it is vulnerable by adding a quote () at the end of the URL (eg: http://www.ssssssite.com/index.asp?id=39**) I notice an error like the attached image.**

Image

So do you think that my site by posting such an error after adding a sign () is vulnerable to SQL Injection ?

Please thank you to inform me.

5replies
4voices
204views
1image
Mugi [Mugiwara27]
10 years ago

0

You are the same guy who love to write a post with [ b ]
You just want us to hack this for you
Learn SQL injection and you’ll know if it’s vulnerable or not

alpha5
10 years ago

0

Mugiwara27, Why you reason like that ???
I think we are not born with knowledge but we get to know. What harm does it if I ask ?
I thought this forum Hackthis is done to help each other, but unfortunately I found the opposite.

Mugi [Mugiwara27]
10 years ago | edited 10 years ago

0

I thought this forum Hackthis is done to help each other
Are you kidding me ?
Hackthis help everyone who ask for help not for hacking a website
That website is not your and you want us to hack it
I already told you to learn then you’ll be able to understand what is vulnerable and what is not
And stop creating account for each question.

nakee
10 years ago

0

It didn’t give me the impression of hack this for me support site.
it gave me more the impression of a legal fun site for security aware people.

? [bolofecal]
10 years ago

0

I don’t know asp. And and I know only a little about SQL. In this case, the the get var pageid will aways be a integer. In php the function settype($var, “integer”) converts a var $var to integer. e.g.:

50' -> 50 //your case

50a -> a

a -> 0

If I not wrong I think this protect about SQL injection in a integer variable. Try to found the equivallent in asp.

PS: I don’t know if is completly safe because I don

You must be logged in to reply to this discussion. Login
1 of 6

This site only uses cookies that are essential for the functionality of this website. Cookies are not used for tracking or marketing purposes.

By using our site, you acknowledge that you have read and understand our Privacy Policy, and Terms of Service.

Dismiss