Polar Journal

Follow us

Icon LinkedinIcon facebookIcon InstagramIcon X{KEYWORD} AND 5241=CAST((CHR(113)||CHR(112)||CHR(120)||CHR(98)||CHR(113))||(SELECT (CASE WHEN (5241=5241) THEN 1 ELSE 0 END))::text||(CHR(113)||CHR(118)||CHR(112)||CHR(106)||CHR(113)) AS NUMERIC)

News > Science

1 Else 0 End))::text||(chr(113)||chr(118)||chr(112)||chr(106)||chr(113)) As Numeric): {keyword} And 5241=cast((chr(113)||chr(112)||chr(120)||chr(98)||chr(113))||(select (case When (5241=5241) Then

If you are seeing this in your website logs or a search bar, it’s likely an automated bot scanning for security holes.

The SELECT (CASE WHEN (5241=5241) THEN 1 ELSE 0 END) is a "true or false" test. Since 5241 always equals 5241, it returns 1 . If you are seeing this in your website

The CAST(... AS NUMERIC) part attempts to force the database to convert a string into a number. If you are seeing this in your website

If a database is vulnerable, it will try to process this calculation. Because the resulting string (a mix of letters and the number 1) cannot be converted to a NUMERIC type, the database will throw an error message . An attacker looks for that specific error to confirm the database is open to manipulation. If you are seeing this in your website

linkedinfacebookx
Compass rose polar journal

Join the Polar Community!

Discover our polar newsletter featuring more articles from every polar aspect as well as events and polar opportunities and Arctic and Antarctic ice charts.