SecurityTubeBeta
Watch ... Learn ... Contribute
|
|
|
|
 |
|
|
|
| |
|
| |
|
|
|
|
|
|
SQL Injection but not only AND 1 eq 1 (SnowFROC)
|
| |
|
| |
This presentation titled "SQL injection: Not only AND 1=1" was given by Bernardo Damele Assumpcao Guimaraes at SnowFROC 2009.
The presentation has a quick preamble on SQL injection definition, sqlmap and its key features. Damele will then illustrate into details common and uncommon problems and respective solutions with examples that a penetration tester or a SQL injection tool developer faces when he wants to take advantage of any kind of web application SQL injection flaw on real world web applications, for instance SQL injection in ORDER BY and LIMIT clauses, single entry UNION query SQL injection, blind SQL injection algorithm speed enhancements, specific web application technologies IDS bypasses and more.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Related Videos from: Interesting Security Talks at SnowFROC 2009 (2) |
 |
| | | | | |
You are Viewing this Video Now! | | | | | |
2400 views | 2178 views | 1553 views | | | |
|
|
|
|
|
|
|
|
|
Author |
 |
Vivek
Ramachandran is a security evangelist and has been working in
computer security related fields for the past 7 years. In 2007,
Vivek spoke at world renowned conferences Defcon (WEP Cloaking Exposed) and Toorcon (The Caffe
Latte Attack). The discovery of the Caffe Latte Attack was
covered by CBS5 news, BBC online, Network World etc news
agencies.In 2006, Vivek was announced as one of winners of the
Microsoft Security Shootout contest held in India among 65,000
participants. He has also been a recipient of a Team Achievement
at Cisco Systems for his work
on 802.1x and Port Security modules on the Catalyst 6500 switches.
Currently he spends all of his time maintaining Security-
Freak.Net , SecurityTube.Net and is the
co-founder of Axonize. Vivek,
is a Bachelor in Electronics and Communications Engineering from
the prestigious Indian Institute of Technology, Guwahati.You can contact him at vivek[at]securitytube.net
|
|
 |
|
|
|
|
| |
 |
|