mssql

2 articles
sort: new top best
clear filter
0 8/10

A detailed writeup on converting a blind error-based MSSQL injection vulnerability into an exploitable boolean-based injection using the IIF() and CONVERT() functions to systematically enumerate database names and table metadata. The author demonstrates bypassing restrictions on verbose error messages and character limits through clever payload construction and Burp Intruder automation.

Ozgur Alp Synack Microsoft SQL Server IIS Burp Intruder SQLMap SQLFiddle
ozguralp.medium.com · kh4sh3i/bug-bounty-writeups · 17 hours ago · details
0 7/10

A Time-Based SQL Injection vulnerability discovered in a forget password function of an ASP.NET application, exploited through single-quote escaping to break the SQL query and WAITFOR DELAY statements to exfiltrate database information using SQLMap automation.

SQLMap Burp Suite MSSQL ASP.NET
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 17 hours ago · details