SQL blind Injection Based on Time Difference

Source: Internet
Author: User
Tags sql injection commands

The main idea of the technique proposed by the author is: When the blind injection (blind SQL injection) is performed, if the results of different SQL Injection commands are not known by HTTP Response itself, you can determine the time difference. You can design a very time-consuming SQL command. If the SQL Injection succeeds, the execution result of this SQL Injection command will affect the speed at which the Web server replies to HTTP response, this can be used to determine the execution result of the SQL Injection command.

Time-based blind SQL injection using heavy queries:
A practical approach for ms SQL Server, MS access, Oracle and MySQL Databases and marathon Tool

Author:
Chema Alonso
Microsoft MVP Windows security, inform ática64
Jos é Parada
Microsoft it pro evangelist, Microsoft

. Abu. Comments:

The contents of the package include the paper of the speech and the slide PDF Format http://butian.org/security/Learning-materials/20080907/166.html.

Marathontool powerful blind injection tool http://butian.org/security/software/attack/20080907/165.html

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.