12.07.2015 Views

How to Rob an Online Bank (and get away with it) - Acros Security

How to Rob an Online Bank (and get away with it) - Acros Security

How to Rob an Online Bank (and get away with it) - Acros Security

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

SQL Injection – Messing W<strong>it</strong>h Tr<strong>an</strong>sactions”BEGIN TRANSACTION””UPDATE accounts SET bal<strong>an</strong>ce = 0WHERE account_id = ’123’””UPDATE accounts SET bal<strong>an</strong>ce = 100WHERE account_id = ’456’ ORaccount_id = ’123’””COMMIT TRANSACTION”31

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!