Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 63 guests and 2 members online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Programmingarrow SQL / OS / LDAP Injection
EH-Net
May 18, 2013, 11:56:45 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: SQL / OS / LDAP Injection  (Read 3344 times)
0 Members and 1 Guest are viewing this topic.
Civilsurvivor
Newbie
*
Offline Offline

Posts: 3


View Profile
« on: April 19, 2012, 07:39:08 AM »

*I hope this is in the correct section, if not can a moderate take me to the correct section*

Hi, Im currently writing a report for university around SQL / OS / LDAP injections, would any of you fine people have any suggestions to papers, journals, books or reports people have written that would be worth the read towards my research?

Cheers!
Logged
ajohnson
Recruiters
Hero Member
*
Online Online

Posts: 1056


aka dynamik


View Profile WWW
« Reply #1 on: April 19, 2012, 08:41:41 AM »

Welcome to the forums.

Is this in the context of web applications? If so, The Web App Hackers Handbook (2nd) covers all of those items extensively: http://www.amazon.com/The-Web-Application-Hackers-Handbook/dp/1118026470/ref=dp_ob_title_bk

www.exploit-db.com hosts a lot of papers, and they likely have some on those topics (the quality here can vary quite a bit). The SANS Reading Room hosts the papers that have been written for their Gold certifications, and they may also have some papers of interest: http://www.sans.org/reading_room/

Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
Civilsurvivor
Newbie
*
Offline Offline

Posts: 3


View Profile
« Reply #2 on: April 19, 2012, 10:53:24 AM »

Thank you, its in contex to the type of attacks in general, i might shorten the report to SQL / OS since ive struggled finding LDAP information.

I use SANS quite requently but thank you for getting back to me ill be sure to look at the exploit db and i have a similar book to the web app hackers handbook
Logged
ajohnson
Recruiters
Hero Member
*
Online Online

Posts: 1056


aka dynamik


View Profile WWW
« Reply #3 on: April 19, 2012, 01:55:40 PM »

WAHH2 contains LDAP as well. Even if you have a similar book, I'd encourage you to pick that one up too. It's easily the best book on the subject.

Also, once you understand these types of injection attacks from the perspective of a web application, you should find the same principles are also applicable to other technologies.
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
Civilsurvivor
Newbie
*
Offline Offline

Posts: 3


View Profile
« Reply #4 on: April 19, 2012, 05:49:59 PM »

haha, the reason why it's so similar because it's the first edition of the book, borrowed it from a friend, thank you for the information!
Logged
j0rDy
Hero Member
*****
Offline Offline

Posts: 590


View Profile
« Reply #5 on: April 20, 2012, 02:23:29 AM »

If you want to learn more about the nature of these attacks i suggest you look at the very first disclosure of the vulnerabilitiy. A nice example would be smashing the stack for fun and profit regarding to buffer overflows (http://insecure.org/stf/smashstack.html) which gives great information about how the attack actually works. Now there are several sites and papers that outline these attacks for you. Almost all show you the how, but most are missing the why, which i think you are looking for.

after some googling i saw that even wikipedia has a nice writeup explaining SQL-injection. i guess the underground is not the only place any more to find such information.

Oh and remember that OWASP has alot of information also.
Logged

ISC2 Associate, CEH, ECSA, OSCP, OSWP

earning my stripes appears to be a road i must travel alone...with a little help of EH.net
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.077 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.