• Email
  • Like
  • Save
  • Private Content
  • Embed
 

Advanced SQL injection to operating system full control (slides)

by on Apr 20, 2009

  • 30,917 views

Over ten years have passed since a famous hacker coined the term "SQL injection" and it is still considered one of the major web application threats, affecting over 70% of web application on the Net. ...

Over ten years have passed since a famous hacker coined the term "SQL injection" and it is still considered one of the major web application threats, affecting over 70% of web application on the Net. A lot has been said on this specific vulnerability, but not all of the aspects and implications have been uncovered, yet.

It's time to explore new ways to get complete control over the database management system's underlying operating system through a SQL injection vulnerability in those over-looked and theoretically not exploitable scenarios: From the command execution on MySQL and PostgreSQL to a stored procedure's buffer overflow exploitation on Microsoft SQL Server. These and much more will be unveiled and demonstrated with my own tool's new version that I will release at the Conference (http://www.blackhat.com/html/bh-europe-09/bh-eu-09-speakers.html#Damele).

These slides have been presented at Black Hat Euroe conference in Amsterdam on April 16, 2009.

Accessibility

Categories

Upload Details

Uploaded via SlideShare as Adobe PDF

Usage Rights

© All Rights Reserved

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

Cancel

39 Embeds 963

http://bernardodamele.blogspot.com 365
http://ricardo.parente.us 178
http://www.slideshare.net 123
http://vaidacerto.blogspot.com 91
http://www.arcanesecurity.net 31
http://vaidacerto.blogspot.com.br 24
http://mhlabs.wordpress.com 21
http://bernardodamele.blogspot.co.uk 20
http://bernardodamele.blogspot.in 20
http://bernardodamele.blogspot.com.br 8
http://bernardodamele.blogspot.fr 8
http://bernardodamele.blogspot.com.au 7
http://bernardodamele.blogspot.mx 7
http://static.slidesharecdn.com 7
http://bernardodamele.blogspot.pt 5
http://bernardodamele.blogspot.it 5
http://bernardodamele.blogspot.de 5
http://feeds2.feedburner.com 4
http://bernardodamele.blogspot.ro 3
http://translate.googleusercontent.com 3
http://bernardodamele.blogspot.ie 3
http://bernardodamele.blogspot.be 3
http://bernardodamele.blogspot.jp 2
http://bernardodamele.blogspot.com.ar 2
http://bernardodamele.blogspot.com.es 2
http://bernardodamele.blogspot.ca 2
http://www.blogger.com 2
http://bernardodamele.blogspot.co.at 1
http://bernardodamele.blogspot.se 1
http://bernardodamele.blogspot.nl 1
http://bernardodamele.blogspot.ae 1
http://bernardodamele.blogspot.ch 1
http://www.hanrss.com 1
http://74.125.93.132 1
http://webcache.googleusercontent.com 1
http://vaidacerto.blogspot.pt 1
http://bernardodamele.blogspot.kr 1
https://twimg0-a.akamaihd.net 1
http://bernardodamele.blogspot.co.il 1

More...

Statistics

Likes
9
Downloads
1,191
Comments
2
Embed Views
963
Views on SlideShare
29,954
Total Views
30,917

12 of 2 previous next

  • aliakboralmahmud9 Ali Akbor Al Mahmud at Mahmud devolopement bd avira internet security antivirus 13 premium 2013 beta with windows 8 free download support download here http://freedownload-version.blogspot.com/2013/01/avira-internet-security-antivirus-13.html 4 months ago
    Are you sure you want to
  • sumsid1234 sumsid1234 SQL Server 2000 by default runs as 'system' and hence the smb relay attack mentioned in your slide will fail(slide 50).

    Very nice talk, looking forward to use the overflow in SQL server.
    4 years ago
    Are you sure you want to
Post Comment
Edit your comment

Advanced SQL injection to operating system full control (slides) Advanced SQL injection to operating system full control (slides) Presentation Transcript