Woozle Wuzzle
SQL Injection Inference

I never put too much thought into how one mines a database via SQL injection especially when a web page is designed for only a certain type of output. This paper has quite a bit of information about mining through inference. Much of the paper is directed at MS SQL Server but there is information about other databases as inference is a general attack.

Comments
Comment by n/a at December 12, 2006 12:39 AM

95% of most pen-testers are relying on sql injection attacks. Once these are cleaned up, the attack surface will become very, very slim.

 

Post a comment













Remember personal info?






Creative Commons License Unless otherwise expressly stated, all original material of whatever nature created by Rob Grzywinski and included in this weblog and any related pages, including the weblog's archives, is licensed under a Creative Commons License.