MySQL Security

MySQL Security News, Articles, and Blogs

Mysql-Proxy Heuristic SQL Injection Detection

Because I am new to MySQL Proxy and the Lua language I tried to implement a very simple script that waits for incoming SQL queries, tokenizes them and tries to detect SQL Injection heuristically by searching for certain disallowed SQL …
css education greensql 0 3 3 leave a comment linux […]

August 5th, 2008. Comment now »

New SQL Injection Concept (Comments, 9e999, MySQL Specific)

The examples below use MySQL because it seems to be most used database on the web. Meanwhile similar techniques can apply to others. In every SQL there is a one “feature” that is unique to that product. MySQL allows usage of comments in …
mysql datemysql date
More here: New SQL Injection Concept (Comments, 9e999, MySQL […]

June 30th, 2008. Comment now »

Database Security Functions

These two functions escape data for sql queries, and apply backticks to table/column names. They can be used in conjunction with the mysql functions for easy updating, insertion, etc. that I will be posting soon. DB Security Functions.
configuring datamal blog …
See the original post here: Database Security Functions
blog blog archive database […]

March 11th, 2008. Comment now »

describe database security?

database security in hospitals movie internet database.
mysql linuxmysql linux
Here is the original: describe database security?
describe database describe database security oracle php mysql database security table table in oracle view this webcastdescribe database, describe database security, oracle, php mysql database, security, table, table in oracle, view this webcast

December 2nd, 2007. Comment now »

MySQL table and column names

Published by | Filed under mid, reiners-8217-weblog, web-security, sqli, table

Getting the table and column names on MySQL within a SQL injection attack is often a problem and I’ve seen a lot of questions about this on the internet. Often you need them to start further SQLi attacks to get the data. …
mysql attackmysql attack
The rest is here: MySQL table and column names
mid reiners […]

November 16th, 2007. Comment now »

How to Prevent MySQL Injections

In the password input we put an SQL injection. It stops the first statement by closing the value and using the semicolon. The second statement in this query is “DELETE FROM `Users`;”, which will delete all the rows …
Read more here: How to Prevent MySQL Injections
closing delete injection input password […]

July 31st, 2007. Comment now »


Cheap Domain Names | Resume Help | slamming.us


Cheap Web Hosting