SQL Injection Preview.pdf

(9173 KB) Pobierz
TEAM
Editor-in-Chief

Joanna Kretowicz 

joanna.kretowicz@eforensicsmag.com
Editors:
Marta Sienicka

sienicka.marta@hakin9.com
Marta Strzelec

marta.strzelec@eforensicsmag.com
Marta Ziemianowicz

marta.ziemianowicz@eforensicamag.com
Proofreader:
Lee McKenzie
Senior Consultant/Publisher:
Paweł Marciniak 
CEO:
Joanna Kretowicz 

joanna.kretowicz@eforensicsmag.com 
Marketing Director:
Joanna Kretowicz 

joanna.kretowicz@eforensicsmag.com
DTP
Marta Sienicka

sienicka.marta@hakin9.com
Cover Design
Hiep Nguyen Duc
Publisher
Hakin9 Media Sp. z o.o.

02-676 Warszawa

ul. Postępu 17D 

Phone: 1 917 338 3631 
www.hakin9.org
All trademarks, trade names, or logos mentioned or used are the
property of their respective owners.
The techniques described in our articles may only be used in private,
local networks. The editors hold no responsibility for misuse of the
presented techniques or consequent data loss.
Dear students,
We gathered all the reading materials from the course “Web Application Hacking: Advanced SQL Injec-
tion and Data Store Attacks” and prepared a stand alone ebook. While reading this workshop you will
examine how SQL and Data stores work in a web server, and you will be introduced to data store attack-
ing and several injection methods with practical examples. You will dive deep into SQL Injection with ad-
vanced ways and you will see ways to encrypt your attacks to make it more effective.
Note: Some of the original course materials, like videos or particular exercises, are not presented
in this issue. If you would like to gain access to all the materials, you have to enroll in the course.
The main aim of this e-book is to present our publication to a wider range of readers. We want to share
the material we worked on and we hope we can meet your expectations.
Enjoy your reading,
Hakin9 Magazine
Editorial Team
Web Applications & SQL:
Introduction and suggested reading
9
Module 1
Introduction to SQL, Data stores, Data Store Injection and SQL
Injection
14
Module 2
Advanced SQL
34
Module 3
Injecting into XPath, LDAP and NoSQL
56
Module 4
Data Store web application security measures
75
5
About the
Course
Zgłoś jeśli naruszono regulamin