The main idea of the technique proposed by the author is: When the blind injection (blind SQL injection) is performed, if the results of different SQL Injection commands are not known by HTTP Response itself, you can determine the time difference. You can design a very time-consuming SQL command. If the SQL Injection succeeds, the execution result of this SQL Injection command will affect the speed at which the Web server replies to HTTP response, this can be used to determine the execution result of the SQL Injection command.
Time-based blind SQL injection using heavy queries:
A practical approach for ms SQL Server, MS access, Oracle and MySQL Databases and marathon Tool
Author:
Chema Alonso
Microsoft MVP Windows security, inform ática64
Jos é Parada
Microsoft it pro evangelist, Microsoft
. Abu. Comments:
The contents of the package include the paper of the speech and the slide PDF Format http://butian.org/security/Learning-materials/20080907/166.html.
Marathontool powerful blind injection tool http://butian.org/security/software/attack/20080907/165.html