[sqlmap-users] mysql_fetch_array(): - false positive
Brought to you by:
inquisb
From: Mardian G. <gun...@gm...> - 2013-03-22 06:27:36
|
Hi, How you doing guys. im testing and manually put ' (tick) and the web spawn this error: Warning: mysql_fetch_array(): supplied argument is not a valid MySQL result resource in /var/www/status.php on line 9 using sqlmap level=3 and risk=3, sqlmap says "heuristic (parsing) test shows that GET parameter 'user' might be injectable (possible DBMS: 'MySQL')" yet I got is false positive. the web has no protection, I'm using --check-waf too. mostly with this error sqlmap can get through, any suggestion/hint guys? Thanks :)) -- Cheers, Gunma http://gunma.rootedker.nl -- Cheers, Gunma http://gunma.rootedker.nl |