Full Disclosure mailing list archives

Re: New Technique to Exploit Blind SQL Injections in MySQL


From: Haxxor Security <h () xxor se>
Date: Tue, 21 Jun 2011 19:00:20 +0200

I got an actual usefull comment that someone had published the same thing
in Russian earlier.
Here http://qwazar.ru/?p=26


2011/6/21 Haxxor Security <h () xxor se>

Hi r00t_ati,
I see that you didn't even take the time to read through the whole article.
You see I read through your whole paper when you published it and they are
nothing alike.

Please try again.


2011/6/21 R00T_ATI <r00t_ati () ihteam net>

**
Hi Haxxor,
nothing new, sorry :S

http://www.ihteam.net/papers/blind-sqli-regexp-attack.pdf

Il 21/06/2011 14:26, Haxxor Security ha scritto:

Hi list,
the last 2 weeks I've been researching a technique to both increase the
speed and reduce the number of requests needed to exploit a blind SQL
injection.
I expect it to be at least 10 times faster than the old benchmark method.

I hope you will find this useful and/or 
interesting.http://ha.xxor.se/2011/06/speeding-up-blind-sql-injections-using.html


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: