Full Disclosure mailing list archives

Re: New Technique to Exploit Blind SQL Injections in MySQL


From: R00T_ATI <r00t_ati () ihteam net>
Date: Tue, 21 Jun 2011 15:46:10 +0200

Hi Haxxor,
nothing new, sorry :S

http://www.ihteam.net/papers/blind-sqli-regexp-attack.pdf

Il 21/06/2011 14:26, Haxxor Security ha scritto:
Hi list,
the last 2 weeks I've been researching a technique to both increase the
speed and reduce the number of requests needed to exploit a blind SQL
injection.
I expect it to be at least 10 times faster than the old benchmark method.

I hope you will find this useful and/or interesting.
http://ha.xxor.se/2011/06/speeding-up-blind-sql-injections-using.html



_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: