Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email email@example.com
RE: ODBC Injection
From: DAN MORRILL (dan_20407msn.com)
Date: Wed Nov 30 2005 - 07:16:54 CST
Don't use access, access has no security model. Use Oracle or MS SQL or a
database that you can segment everything off to proceedures, don't allow
nested triggers, build the e-commerce site so that it calls nothing but
stored proceedures, and sanitizes the data at the web page, and at the
Just my 2 cents.
Sometimes MSN E-mail will indicate that the mesasge failed to be delivered.
Please resend when you get those, it does not mean that the mail box is bad,
merely that MSN mail is over worked at the time.
>From: "John Cobb" <johncnobytes.com>
>Subject: ODBC Injection
>Date: Wed, 30 Nov 2005 11:38:53 -0000
>Received: from outgoing.securityfocus.com ([188.8.131.52]) by
>bay0-mc2-f4.bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.211); Wed, 30
>Nov 2005 03:46:14 -0800
>Received: from outgoing.securityfocus.com by outgoing.securityfocus.com
> via smtpd (for mx2.hotmail.com [184.108.40.206]) with ESMTP; Wed, 30
>Nov 2005 03:23:07 -0800
>Received: from lists.securityfocus.com (lists.securityfocus.com
>[220.127.116.11])by outgoing3.securityfocus.com (Postfix) with QMQPid
>040782378A8; Wed, 30 Nov 2005 04:08:04 -0700 (MST)
>Received: (qmail 15179 invoked from network); 30 Nov 2005 11:44:52 -0000
>Mailing-List: contact webappsec-helpsecurityfocus.com; run by ezmlm
>Delivered-To: mailing list webappsecsecurityfocus.com
>Delivered-To: moderator for webappsecsecurityfocus.com
>X-Mailer: Microsoft Office Outlook, Build 11.0.5510
>X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
>X-Virus-Scanned: ClamAV version 0.87, clamav-milter version 0.87 on
>X-OriginalArrivalTime: 30 Nov 2005 11:46:15.0137 (UTC)
>I'm testing an ecommerce app on IIS6 with an M$ Access Database and I have
>found some injection:
>I get the following error when I insert alpha characters rather than
>I cannot manipulate this much, does anybody have any suggestions?
>Database operations error:
>ODBC driver does not support the requested properties.
>SELECT * FROM Products WHERE idProduct = test
>ADODB.Recordset error '800a0e78'
>Operation is not allowed when the object is closed.
>/test.asp, line 135
Donít just search. Find. Check out the new MSN Search!