20.05.2013 Views

from_sqli_to_shell

from_sqli_to_shell

from_sqli_to_shell

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

PentesterLab.com » From SQL Injection <strong>to</strong> Shell<br />

The SQL injection provided the same level of access as the<br />

user used by the application <strong>to</strong> connect <strong>to</strong> the database<br />

(current_user())... That is why it is always important <strong>to</strong><br />

provide the lowest privileges possible <strong>to</strong> this user when you<br />

deploy a web application.<br />

32/41

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!