character-enumeration

1 article
sort: new top best
clear filter
0 8/10

A detailed writeup demonstrating how to convert a blind error-based SQL injection vulnerability on MSSQL into an exploitable boolean-based injection using the IIF() function combined with type conversion, enabling data exfiltration through character enumeration attacks despite a 100-character payload limitation.

Ozgur Alp Synack Burp Intruder SQLMap SQLFiddle MSSQL IIS
ozguralp.medium.com · kh4sh3i/bug-bounty-writeups · 5 hours ago · details