28.10.2014 Views

SQL Injection Attacks and Defense - 2009

SQL Injection Attacks and Defense - 2009

SQL Injection Attacks and Defense - 2009

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

454 Chapter 10 • References<br />

■■<br />

■■<br />

■■<br />

■■<br />

“Advanced <strong>SQL</strong> <strong>Injection</strong> in <strong>SQL</strong> Server Applications” by Chris Anley:<br />

www.ngssoftware.com/papers/advanced_sql_injection.pdf<br />

“Buffer Truncation Abuse in .NET <strong>and</strong> Microsoft <strong>SQL</strong> Server” by Gary<br />

O’Leary-Steele:<br />

http://scanner.sec-1.com/resources/bta.pdf<br />

“Access through Access” by Brett Moore:<br />

www.insomniasec.com/publications/Access-Through-Access.pdf<br />

“Time-Based Blind <strong>SQL</strong> <strong>Injection</strong> with Heavy Queries” by Chema Alonso:<br />

http://technet.microsoft.com/en-us/library/cc512676.aspx<br />

<strong>SQL</strong> <strong>Injection</strong> Cheat Sheets<br />

■■<br />

■■<br />

■■<br />

■■<br />

PentestMonkey.com <strong>SQL</strong> injection cheat sheets for Oracle, Microsoft <strong>SQL</strong> Server,<br />

My<strong>SQL</strong>, Postgre<strong>SQL</strong>, Ingres, DB2, <strong>and</strong> Informix:<br />

http://pentestmonkey.net/cheat-sheets/<br />

Michaeldaw.org <strong>SQL</strong> injection cheat sheets for Sybase, My<strong>SQL</strong>, Oracle,<br />

Postgre<strong>SQL</strong>, DB2, <strong>and</strong> Ingres:<br />

http://michaeldaw.org/sql-injection-cheat-sheet/<br />

Ferruh Mavituna cheat sheets for My<strong>SQL</strong>, <strong>SQL</strong> Server, Postgre<strong>SQL</strong>, <strong>and</strong> Oracle:<br />

http://ferruh.mavituna.com/sql-injection-cheatsheet-oku/<br />

Ferruh Mavituna cheat sheets for Oracle:<br />

http://ferruh.mavituna.com/oracle-sql-injection-cheat-sheet-oku/<br />

<strong>SQL</strong> <strong>Injection</strong> Exploit Tools<br />

■■<br />

■■<br />

■■<br />

Absinthe is a Windows GUI-based exploit tool that supports Microsoft <strong>SQL</strong> Server,<br />

Oracle, Postgre<strong>SQL</strong>, <strong>and</strong> Sybase using both blind <strong>and</strong> error-based <strong>SQL</strong> injection:<br />

www.0x90.org/releases/absinthe/<br />

<strong>SQL</strong>Brute is a time- <strong>and</strong> error-based blind <strong>SQL</strong> injection tool that supports<br />

Microsoft <strong>SQL</strong> Server <strong>and</strong> Oracle:<br />

www.gdssecurity.com/l/t/sqlbrute.py<br />

Bobcat is a Windows GUI-based tool that supports Microsoft <strong>SQL</strong> Server<br />

exploitation:<br />

http://web.mac.com/nmonkee/pub/bobcat_files/BobCat_Alpha_v0.4.zip

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!