The Web Application Hacker’s Handbook Discovering and Exploiting Security Flaws



Download 5,76 Mb.
Pdf ko'rish
bet506/875
Sana01.01.2022
Hajmi5,76 Mb.
#293004
1   ...   502   503   504   505   506   507   508   509   ...   875
Bog'liq
3794 1008 4334

Chapter 9 



Injecting Code



285

70779c09.qxd:WileyRed  9/14/07  3:13 PM  Page 285




■■

You may be able to compromise the operating system of the database

server.

■■

You may be able to gain network access to other systems. Typically, the



database server is hosted on a protected network behind several layers

of network perimeter defenses. From the database server, you may be

in a trusted position and be able to reach key services on other hosts,

which may be further exploitable.

■■

You may be able to make network connections back out of the hosting



infrastructure to your own computer. This may enable you to bypass

the application altogether, easily transmitting large amounts of sensi-

tive data gathered from the database, and often evading many intrusion

detection systems.

■■

You may be able to extend the database’s existing functionality in arbi-



trary ways by creating user-defined functions. In some situations, this

may enable you to circumvent hardening that has been performed on

the database, by effectively re-implementing functionality that has been

removed or disabled. There is a method for doing this in each of the

mainstream databases, provided that you have gained database admin-

istrator (DBA) privileges.




Download 5,76 Mb.

Do'stlaringiz bilan baham:
1   ...   502   503   504   505   506   507   508   509   ...   875




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish