Login|Japanese
May 15, 2009
 Blindfolded SQL Injection Demonstration Video
We've already demonstrated several SQL Injection methods. These can be found in multiple parts: This video demonstration is focused on "Blindfolded SQL Injection". You can find a detailed technical white paper from Imperva on this subject here.

In short, Blindfolded SQL Injection is a method of exploitation that gets around good coding practices which disallow sensitive error messages, system internals, and related information from being displayed to the user. This level of detail is very helpful for SQL injection attacks. Since most documents describing SQL Injection rely on gathering information through the error messages we thought we would explore how it can be done without any such messages with equivalent success.

« Podcast: Hacking Power Plants "Red Team Style" with Ray Parks from Sandia National Labs | Main | Viva Interop Las Vegas '09 »