发新话题
打印

[转载]Manipulating Microsoft SQL Server Using SQL Injection

[转载]Manipulating Microsoft SQL Server Using SQL Injection

原始出处:http://www.appsecinc.com/present ... g_SQL_Injection.pdf

This paper will not cover basic SQL syntax or SQL Injection. It is assumed that the reader has a strong understanding of these topics already. This paper will focus on advanced techniques that can be used in an attack on a (web) application utilizing Microsoft SQL Server as a backend. These techniques demonstrate how an attacker could use a SQL Injection vulnerability to retrieve the database content from behind a firewall and penetrate the internal network.

附件

Manipulating_SQL_Server_Using_SQL_Injection.rar (166 KB)

2007-3-19 15:05, 下载次数: 73

曾几何时,有人对我说:装B遭雷劈。我说:去你妈的。于是,这个人又对我说:如果再说脏话,上帝会惩罚你的。我说:我操上帝。结论:彪悍的人生不需要上帝。

TOP

发新话题