Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Paper: SQL Injection Attacks by Example

Paper: SQL Injection Attacks by Example

From: Steve Friedl <steve_at_unixwiz.net>
Date: Wed, 5 Jan 2005 09:30:39 -0800

Hello folks (and Happy New Year),

I recently posted this to the PEN-TEST list, but it was suggested that
the wider Bugtraq readership might benefit from it.

During a recent security review for a customer, I was able to completely
compromise his web application in about two hours using SQL Injection,
logging in as the Chief Information Officer.

I've written a paper on SQL Injection Attacks, not so much as a tutorial,
but an illustrated overview showing the process (those with only a casual
knowledge of SQL have told me it's easy to understand).

Those who write (or test) web applications really ought to know about SQL
Injection attacks, because the bad guys certainly do.

        SQL Injection Attacks by Example
        http://www.unixwiz.net/techtips/sql-injection.html

Steve

-- 
Stephen J Friedl | Security Consultant |  UNIX Wizard  |   +1 714 544-6561
www.unixwiz.net  | Tustin, Calif. USA  | Microsoft MVP | steve_at_unixwiz.net
Received on Jan 05 2005
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]