期刊文献+

浅析SQL盲注攻击的实现 被引量:5

Analysis of Blind SQL Injection Techniques
原文传递
导出
摘要 文章主要介绍了在SQL注入攻击中的一种新攻击技术—盲注攻击,首先介绍了SQL盲注技术的定义和危害,然后讨论了在错误信息被屏蔽的情况下如何探测SQL注入漏洞,确定SQL注入点,构造正确的注入句法及其利用代码,最后详细阐述了利用UNION SELECT语句来统计数据表的列数和判断列的数据类型的方法和步骤。 This paper presents a new attack technique for SQL Injection Attack-Blind SQL Injection Technique. In this paper, the definition and risk of Blind SQL Injection is first presented. Then, the paper discusses that, when detailed error messages are suppressed, how to identify SQL Injections based on minimal reaction of the server, and how to identify SQL Injection vulnerable parameters, to generate valid injection syntax and to build the required exploit. Finally, one attack model by UNION SELECT is described in detail. This paper tries to make it clear that application level vulnerabilities must be handled by application level solutions, and that relying on suppressed error messages for protection from SQL Injection is eventually useless.
出处 《信息安全与通信保密》 2008年第5期71-73,76,共4页 Information Security and Communications Privacy
关键词 盲注 数据库攻击 SQL注入 网络应用程序安全 blind injection database attack SQL injection Web application security
  • 相关文献

参考文献4

  • 1[1]Kost S.Introduction to SQL Injection Attacks for Oracle Developers[EB/OL].Integrigy Corporation,2004[2006-10-23].http://www.net-security.org/dl/articles/IntegrigyIntrotoSQLInjectionAttacks.pdf.
  • 2[2]Anley C.Advanced SQL Injection In SQL Server Applications[EB/OL].An NGSSoftware Insight Security Research(NISR),2002[2006-10-23].Publication,http://www.ngssoftware.com/papers/advanced_sql_injection.pdf.
  • 3[3]Anley C.(more)Advanced SQL Injection[EB/OL].An NGSSoftware Insight Security Research (NISR)Publication,2002[2006-10-23].http://www.ngssoftwamcom/papers/more_advanced_sql_injection.pdf.
  • 4[4]Cerrudo C.Manipulating Microsoft SQL Server Using SQL Injection[EB/OL].2002[2006-10-23].http://www.appsecinc.com/presentations/Manipulating_SQL_Server_Using__SQL_Injection.pdf.

同被引文献23

引证文献5

二级引证文献14

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部