Wrong confirmation ID
  • Email
  • Favorite
  • Download
  • Embed
  • Private Content

Loading…

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

Advanced SQL injection to operating system full control (slides)

by Bernardo Damele A. G. on Apr 20, 2009

  • 26,201 views

Over ten years have passed since a famous hacker coined the term "SQL injection" and it is still considered one of the major web application threats, affecting over 70% of web application on the Net. A...

Over ten years have passed since a famous hacker coined the term "SQL injection" and it is still considered one of the major web application threats, affecting over 70% of web application on the Net. A lot has been said on this specific vulnerability, but not all of the aspects and implications have been uncovered, yet.

It's time to explore new ways to get complete control over the database management system's underlying operating system through a SQL injection vulnerability in those over-looked and theoretically not exploitable scenarios: From the command execution on MySQL and PostgreSQL to a stored procedure's buffer overflow exploitation on Microsoft SQL Server. These and much more will be unveiled and demonstrated with my own tool's new version that I will release at the Conference (http://www.blackhat.com/html/bh-europe-09/bh-eu-09-speakers.html#Damele).

These slides have been presented at Black Hat Euroe conference in Amsterdam on April 16, 2009.

Accessibility

Categories

Tags

inject bind text file bof overflow sqlmap meterpreter postgresql dll reverse shell binary bulletin buffer sqlinjection heap metasploit mysql mssql security sql injection black hat

More...

Upload Details

Uploaded via SlideShare as Adobe PDF

Usage Rights

© All Rights Reserved

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

Cancel

23 Embeds 757

http://bernardodamele.blogspot.com 299
http://ricardo.parente.us 173
http://www.slideshare.net 123
http://vaidacerto.blogspot.com 91
http://www.arcanesecurity.net 22
http://mhlabs.wordpress.com 11
http://static.slidesharecdn.com 7
http://feeds2.feedburner.com 4
http://vaidacerto.blogspot.com.br 4
http://translate.googleusercontent.com 3
http://bernardodamele.blogspot.in 3
http://bernardodamele.blogspot.com.au 3
http://bernardodamele.blogspot.pt 2
http://bernardodamele.blogspot.co.uk 2
http://www.blogger.com 2
http://webcache.googleusercontent.com 1
http://bernardodamele.blogspot.fr 1
http://vaidacerto.blogspot.pt 1
http://74.125.93.132 1
http://bernardodamele.blogspot.de 1
http://bernardodamele.blogspot.it 1
http://www.hanrss.com 1
https://twimg0-a.akamaihd.net 1

More...

Statistics

Favorites
7
Downloads
1,046
Comments
1
Embed Views
757
Views on SlideShare
25,444
Total Views
26,201

11 of 1 previous next

  • sumsid1234 sumsid1234 SQL Server 2000 by default runs as 'system' and hence the smb relay attack mentioned in your slide will fail(slide 50).

    Very nice talk, looking forward to use the overflow in SQL server.
    3 years ago Reply
    Are you sure you want to Yes No
Post Comment
Edit your comment Cancel

Advanced SQL injection to operating system full control (slides) — Presentation Transcript