My experience on my daily works... helping others ease each other

Friday, December 9, 2011

Exposing Direct Database SQL Injection Attacks

SQL injection typically leverages non-validated input vulnerabilities to pass SQL commands through a Web application for execution by a backend database. Crafty attackers take advantage of SQL commands with user-provided parameters to execute arbitrary SQL queries and/or commands on the backend database server through the Web application. This video demonstration, however, shows the database being attacked directly by a non-privileged user, not through a Web application, but via direct interaction with the database.

Uploaded by on Aug 13, 2009
Share:

0 comments:

About Me

Somewhere, Selangor, Malaysia
An IT by profession, a beginner in photography

Blog Archive

Blogger templates