a question about sql injection

a question about sql injection

Post by _-- RAZOR --_ on Wed Jul 09, 2008 4:44 pm
Warning: mysql_fetch_assoc(): supplied argument is not a valid MySQL result resource in /home/iaulahij/public_html/administrator/default.php on line 11

Warning: Cannot modify header information - headers already sent by (output started at /home/iaulahij/public_html/administrator/default.php:11) in /home/iaulahij/public_html/administrator/default.php on line 28

is this website vulnerable?
would you help me understanding this sql errors?
_-- RAZOR --_
Re: a question about sql injection

Post by thedotmaster on Thu Jul 10, 2008 1:38 pm
Perhaps, perhaps not.
If you had forced that error, then yeah it might be.
But if you went on that webpage and it came up with that, then no (although it may be vulnerable anyway).
say the url is: http://www.website.com/blah/code.php?file=hello
and you typed in: http://www.website.com/blah/code.php?file=`or 1=1--
and it came up with an error, then you'd know it was vulnerable (or might be vulnerable) because it is taking your input and not filtering the SQL out of it.
By the way, typing ` or 1=1-- will never h4x0r a webpage, it's just a good way of trying to force an error.
