The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws



Download 5,76 Mb.
Pdf ko'rish
bet460/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   456   457   458   459   460   461   462   463   ...   875
Bog'liq
3794 1008 4334

will produce an error

regardless of the number of columns. You can satisfy this requirement by

selecting from the globally accessible table 

DUAL


. For example:

‘ UNION SELECT NULL FROM DUAL--

When you have identified the number of columns required in your injected

query, and have found a column which has a string data type, you are in a

position to extract arbitrary data. A simple proof-of-concept test is to extract

the version string of the database, which can be done on any DBMS. For exam-

ple, if there are three columns, and the first column can take string data, you

can extract the database version by injecting the following query on MS-SQL

and MySQL:

‘ UNION SELECT @@version,NULL,NULL--

70779c09.qxd:WileyRed  9/14/07  3:13 PM  Page 254



Injecting the following query will achieve the same result on Oracle:

‘ UNION SELECT banner,NULL,NULL FROM v$version--

In the example of the vulnerable book search application, we can use this

string as a search term to retrieve the version of the Oracle database:




Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   456   457   458   459   460   461   462   463   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish