• Email
  • Like
  • Save
  • Private Content
  • Embed
 

SQL injection: Not only AND 1=1

by on Mar 10, 2009

  • 47,967 views

The presentation has a quick preamble on SQL injection definition, sqlmap and its key features. ...

The presentation has a quick preamble on SQL injection definition, sqlmap and its key features.
I then illustrate into details common and uncommon problems and respective solutions with examples that a penetration tester faces when he wants to take advantage of any kind of web application SQL injection flaw on real world web applications, for instance SQL injection in ORDER BY and LIMIT clauses, single entry UNION query SQL injection, specific web application technologies IDS bypasses and more.

These slides have been presented at the Front Range OWASP Conference in Denver on March 5, 2009.

Accessibility

Categories

Upload Details

Uploaded via SlideShare as Adobe PDF

Usage Rights

© All Rights Reserved

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

Cancel

52 Embeds 1,326

http://bernardodamele.blogspot.com 332
http://people.rit.edu 282
http://sqlinjections.blogspot.com 200
http://www.slideshare.net 197
http://www.pcsec.org 169
http://amxking.bokee.com 19
http://www.daxigua.com 18
http://www.scoop.it 11
http://bernardodamele.blogspot.in 10
http://sqlinjections.blogspot.in 9
http://4ppsecurity.blogspot.com 8
http://static.slideshare.net 5
http://bernardodamele.blogspot.co.uk 5
http://sqlinjections.blogspot.fr 4
http://translate.googleusercontent.com 4
http://sqlinjections.blogspot.mx 3
http://bernardodamele.blogspot.com.br 3
http://bernardodamele.blogspot.se 2
http://bernardodamele.blogspot.pt 2
http://sqlinjections.blogspot.hu 2
http://bernardodamele.blogspot.fr 2
http://sqlinjections.blogspot.be 2
http://bernardodamele.blogspot.kr 2
http://bernardodamele.blogspot.com.es 2
https://people.rit.edu 2
http://bernardodamele.blogspot.it 2
http://bernardodamele.blogspot.de 2
http://webcache.googleusercontent.com 2
http://sqlinjections.blogspot.com.au 2
http://sqlinjections.blogspot.co.at 1
http://209.85.171.132 1
http://sqlinjections.blogspot.co.uk 1
http://sqlinjections.blogspot.jp 1
http://209.85.135.132 1
http://bernardodamele.blogspot.ch 1
http://bernardodamele.blogspot.ca 1
file:// 1
http://www.hanrss.com 1
http://www.linkedin.com 1
http://static.slidesharecdn.com 1
http://sqlinjections.blogspot.com.br 1
http://nicecomputersecurity.blogspot.com 1
http://after-school-activitiesz.blogspot.com 1
http://paper.li 1
http://4ppsecurity.blogspot.in 1
http://sqlinjections.blogspot.kr 1
http://feeds2.feedburner.com 1
http://74.125.93.132 1
http://bernardodamele.blogspot.mx 1
http://bernardodamele.blogspot.hu 1
http://pinterest.com 1

More...

Statistics

Likes
12
Downloads
915
Comments
2
Embed Views
1,326
Views on SlideShare
46,641
Total Views
47,967

12 of 2 previous next

  • viralnexxus viralnexxus A`la Spock, fascinating. 2 years ago
    Are you sure you want to
  • hackertarget Hacker Target, Security Analyst at HackerTarget Offices An excellent presentation - you have made a confusing topic clear and concise - well done.

    Definitely one of the better presentations on sql injection I have seen.
    3 years ago
    Are you sure you want to
Post Comment
Edit your comment

SQL injection: Not only AND 1=1 SQL injection: Not only AND 1=1 Presentation Transcript