Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 22 guests and 2 members online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow CEH - Certified Ethical Hackerarrow CEH - Official Course Modules v5arrow CEH v5 Module 14: SQL Injection
Ethical Hacker Community Forums
November 22, 2008, 10:12:47 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: CEH v5 Module 14: SQL Injection  (Read 4626 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2347


Editor-In-Chief


View Profile WWW
« on: November 15, 2006, 01:47:26 PM »

 Introducing SQL injection
 Exploiting Web Applications
 SQL Injection  Steps
    o What Should You Look For?
    o What If It Doesn’t Take Input?
    o OLE DB Errors
    o Input Validation Attack
 SQL Injection Techniques
 How to Test for SQL Injection Vulnerability?
 How does it Work?
 Executing Operating System Commands
 Getting Output of SQL Query
 Getting Data from the Database Using ODBC Error Message
 How to Mine all Column Names of a Table?
 How to Retrieve any Data?
 How to Update/Insert Data into Database?
 Automated SQL Injection Tool
    o AutoMagic SQL
    o Absinthe
 SQL Injection in Oracle
 SQL Injection in MySql Database
 Attack against SQL Servers
 SQL Server Resolution Service (SSRS)
 Osql L- Probing
 SQL Injection Automated Tools
    o SQLDict
    o SqlExec
    o SQLbf
    o SQLSmack
    o SQL2.exe
 SQL Injection Countermeasures
 Preventing SQL Injection Attacks
 SQL Injection Blocking Tool: SQLBlock
 Acunetix Web Vulnerability Scanner

Source:
http://www.eccouncil.org/EC-Council%20Education/ceh-course-outline.htm

Don
Logged

CISSP, MCSE, CEH, Security+ SME
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1038


View Profile WWW
« Reply #1 on: November 15, 2006, 03:21:19 PM »

on this note...

does anyone have any guides for setting up a server that is VULNERABLE to SQL injection.  I would like to set up a MySQL and MSSQL boxe(s) that are  vuln to different SQL. 

i figure someone has already done this at some point...
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
SpudniX
Newbie
*
Offline Offline

Posts: 3


View Profile
« Reply #2 on: November 16, 2006, 03:58:06 PM »

When teaching CEH, I use Windows 2000 Server Professional unpatched on VMWare. This will provide you a nice MSSQL platform to hack. If you have the CEHv4 materials, you should also have the databases to setup JuggyBank, a lab used in SQL Injection.

MYSQL, I'm afraid you are on your own.

Hope this helps.
Logged

-.-
SpudniX
CEI, CEH, CHFI
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1038


View Profile WWW
« Reply #3 on: November 16, 2006, 11:32:46 PM »

that does help, thanks!
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
x4h
Newbie
*
Offline Offline

Posts: 1


View Profile
« Reply #4 on: June 21, 2007, 07:59:39 AM »

SQL injection is performed through badly written scripts which allow you to enter SQL commands into its queries (i.e. they don't sanitise inputs). So you'll probably be safe with default setups of mssql and mysql.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.046 seconds with 26 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.