MySQL Security

MySQL Security News, Articles, and Blogs

keld-sql.txt

Published by | Filed under author, crimson, magic, guys, source, code, password, , select, query, mysql

Keld: PHP-MySQL News Script version 0.71 suffers from a remote SQL injection vulnerability.
phpmyadmin securityphpmyadmin security
Go here to see the original: keld-sql.txt
author code crimson guys magic mysql password query select sourceauthor, code, crimson, guys, magic, mysql, password, query, select, source

August 4th, 2008. Comment now »

phpwebnews-sql.txt

phpWebNews version 0.2 MySQL Edition suffers from a SQL injection vulnerability.
html html in mysql injection mysql php prevention sql sql injection toadz via view all posts in php wordpresshtml, html in mysql, injection, mysql, php, prevention, sql, sql injection, toadz, via, view all posts […]

July 10th, 2008. Comment now »

New SQL Injection Concept (Comments, 9e999, MySQL Specific)

The examples below use MySQL because it seems to be most used database on the web. Meanwhile similar techniques can apply to others. In every SQL there is a one “feature” that is unique to that product. MySQL allows usage of comments in …
mysql datemysql date
More here: New SQL Injection Concept (Comments, 9e999, MySQL […]

June 30th, 2008. Comment now »

Memcached Functions for MySQL 0.3 (Default branch)

Memcached Functions for MySQL is a set of MySQL UDFs (user defined functions) to work through memcached using libmemcached. With these functions you engender, set, append, prepend, and delete objects in memcached. …
css education greensql 0 3 3 leave a comment linux medical news open source open […]

March 4th, 2008. Comment now »

automated search for open mysql system user accounts? (fwd)

Did anybod= y of you observe similar activity on publicly accessible systems? I wonder if th= ere is some known vulnerability that these login attempts try to exploit? A MyS= QL user account with a known password or no password? …
accepts automagic canonical configuration connections default leaves mysql […]

October 22nd, 2007. Comment now »

PHP / MYSQL search feature

Published by | Filed under advised, problem, closed, chris, string, injection, select, aware, network

For information, here is my code ( I am aware of the SQL injection problem but. but this is for a small closed network ) Any advised would be welcome, Thanks Chris. PHP:.
Read the original: PHP / MYSQL search feature
advised aware chris closed injection network problem select […]

June 27th, 2007. Comment now »

2 Interesting SQL Vectors.

Published by Admin | Filed under modified, examples, benchmark, benchmarkmdxnull, ifpassword, select, injection

Like these examples I modified to work in a real SQL injection: SELECT IF(password > ‘1′, BENCHMARK(1000000,MD5(’x’)),null) FROM test SELECT IF(password > ‘09′, BENCHMARK(1000000,MD5(’x’)),null) FROM test SELECT IF(password > ‘09a’, …
Original post: 2 Interesting SQL Vectors.
benchmark benchmarkmdxnull examples ifpassword injection modified selectbenchmark, benchmarkmdxnull, examples, ifpassword, injection, modified, select

June 26th, 2007. Comment now »


Get a shorter URL | 2008 Presidential Candidates | ity.cc


Cheap Web Hosting