Top 10 winner
SQL Injection Isn't Dead: Smuggling Queries at the Protocol Level
Database client drivers write a message's size into a four-byte length field, so a parameter of about four gigabytes makes that integer overflow and the tail of the attacker's string is read by the database as a fresh protocol message. This injects whole SQL statements past parameterised queries, and trampoline bytes cut the offset guessing to about two attempts.
Record
- Researcher
- Paul Gerste
- Published by
- SonarSource
- Date
- Format
- Slides
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Paul Gerste, first published at the original source. Preserved copies are kept so the citation survives its host.