(more) Advanced SQL Injection

From: Chris Anley (chrisat_private)
Date: Tue Jun 18 2002 - 11:25:16 PDT

  • Next message: Niels Provos: "external policy enforcement [Re: Apache httpd: vulnerability...]"

    Hi folks,
    
    I've written another SQL injection whitepaper; it can be found at
    http://www.ngssoftware.com/papers/more_advanced_sql_injection.pdf
    
    I'm aware that I'm running the risk of becoming a one-topic poster; if
    anyone's bored, I apologise. Other stuff is in the pipeline, I promise. :o)
    
    The paper clears up some points I glossed over in the previous paper and
    introduces some new techniques, notably the use of time delays as a
    communication channel to extract information from the database, and the many
    uses of OPENROWSET.
    
    If anyone has other examples of the use of time as a communication channel,
    I'd be extremely interested. It seems to me to be a powerful technique,
    since defence mechanisms tend to abstract it out.
    
         -chris.
    



    This archive was generated by hypermail 2b30 : Tue Jun 18 2002 - 14:13:29 PDT