SQL Injection: Hacking Web
SQL Injection: Hacking Web
SQL Injection
' OR 1 = 1; --
FDIst - HACKING WEB
SQL INJECTION
FDIst - HACKING WEB
SQL INJECTION
La magia de SQL Injection
¡Atacad!
https://vulnerable.devpgsv.com/
FDIst - HACKING WEB
SQL INJECTION
Automatizando
● SQLNinja
● The Mole
● SQLBrute
● SQLMap
FDIst - HACKING WEB
SQL INJECTION
SQLMap
sqlmap -u [URL]
want to try with a random integer value for option=Y,due to huge table size
do you want to remove ORDER BY clause gaining speed over
consistency=Y" --threads=10
SQL INJECTION
FDIst - HACKING WEB
SQL INJECTION
Database Injection
Solución
● Escapar caracteres
● Filtros
● Prepared Statements
FDIst - HACKING WEB
SQL INJECTION
FDIst
@FDIstUCM
https://t.me/joinchat/Ar4agkCACYELE5TZ5AWtAA
https://fdist.fdi.ucm.es
FDIst - HACKING WEB
SQL INJECTION
Pablo García de los Salmones Valencia
Febrero 2018
under a
SQL INJECTION