Damon Cortesi's blog

Musings of an entrepreneur.

More Blind SQL

| Comments

Success! I can now successfully extract data from a Blind SQL-vulnerable web application with under 500 lines of perl. And Absinthe, after running for the entire 3-day weekend+, is just now beginning to pull the actual table names. I’m not knocking it as it’s data retrieval is probably much more robust than mine, but I’m a sucker for immediate gratification.

Now I just need to prettify the output…

dances

Comments