[prev in list] [next in list] [prev in thread] [next in thread] 

List:       full-disclosure
Subject:    Re: [Full-disclosure] SQID v0.2 - SQL Injection Digger.
From:       icecoldeuro () gmail ! com
Date:       2006-12-27 0:28:57
Message-ID: f7ba524d0612261628y4a23cc05tf318fb7298cbe29a () mail ! gmail ! com
[Download RAW message or body]

[Attachment #2 (multipart/alternative)]


So - hypothetically - the first result of the sample run at
sqid.rubyforge.org would only yield a Microsoft OLE DB provider error (Unclosed
quotation mark before the character string).

Now, granted, this is bad practice if they can't trap their errors, but I
also don't see how this constitutes proof of an XSS vulnerability. The usual
XSS variations - again, purely hypothetically - all just yield the same
error message.

Would you consider this a potential false positive then? In my opinion it's
not a vuln unless it's exploitable.

[Attachment #5 (text/html)]

So - <font face="Arial" size="2">hypothetically - the first result of the sample run at <a \
href="http://sqid.rubyforge.org">sqid.rubyforge.org</a> would only yield a Microsoft OLE DB \
provider error (</font><font face="Arial" size="2"> Unclosed quotation mark before the \
character string</font><font face="Arial" size="2">).</font> <p><font face="Arial" \
size="2">Now, granted, this is bad practice if they can&#39;t trap their errors, but I also \
don&#39;t see how this constitutes proof of an XSS vulnerability. The usual XSS variations - \
again, purely hypothetically - all just yield the same error message.</font></p><p><font \
face="Arial" size="2">Would you consider this a potential false positive then? In my opinion \
it&#39;s not a vuln unless it&#39;s exploitable.</font></p><p></p><p><br> </p>
<p><font face="Arial" size="2"><br>
</font></p>



_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic