fix this error
hello
i have nearly been suspended from attending my collage, because of and the qr code, the only thing that saved me was sending the email to collage. please learn the lesson of dont hack your school/collage/work network even if you succeeded the consequences are bigger than that little buzz.
I am not sure you can exploit SQLi in this case. It just a programming flaw because someone did not declare variable or that variable was out of scope.
The error in itself doesn’t say if there exists SQLi or no. The error is that in the code someone is trying to access a variable that hasn’t been set yet. This may occur for example in the case when you don’t get anything from the database and you don’t check if no rows are returned..
TL;DR the bug exists because of sloppy coding.
Additionally it’s bad practice to show detailed error messages to “public” and the admins should update the “customErrors” tag in their web.config
- daMage
Sorry if that sounded stupid.
All your karamas are belong to us.
the thing about .net and iis errors is that they mostly show no relation to the error it self…
been working with windows servers for the past 2 years, and 99% of the errors are something you have to guess how to fix ….
like for example if you forgot to upload something to the bin directory you get some class is not defined in the .cs file …. but the cs file has it and the class exists … so guessing all the way.
I Hate Signatures.
@zLKidda It can be SQLi vuln, but not necessarily. You could try to confirm it with time-based injections or you could try to make the syntax correct while injecting it.
Just going to leave this here:
If you are going to exploit it (or even try to), you could end up suspended from the school or worse. You should report the bug and ask for (preferably a written) permission to determine how bad it is (read: exploit it to the max).
- daMage
no need to censor the img nothing is valuable on it except the outlook (wow you have my email XD o nooooo) and the URL need credentials :D very few accounts are linked to email shown so its cool :F :p
Well but that gives info on where you study -> where you live, and I’m sure someone (not me) could SE his way into deeper details… Just saying! :D
Also nice extensions + we use the same theme on Chrome. Yes I’m a wannabe.
Sorry if that sounded stupid.
All your karamas are belong to us.
all the same as being a friend on facebook, scary when you think about it. privacy is dead. and it’s a good theme