官术网_书友最值得收藏!

  • Bug Bounty Hunting Essentials
  • Carlos A. Lozano Shahmeer Amir
  • 136字
  • 2021-06-10 18:35:33

In-band SQLi (classic SQLi)

In-band SQL injection is the classis SQL injection attack and it occurs when the attacker is able to use the same parameter and channel to launch an attack and get the corresponding results. In-band SQLi is divided into two types mainly:

  • Error-based SQLi: In this type of in-band SQLi, error messages are returned as a response from the database and allow the attacker to gain information about the backend database itself. In certain scenarios, error-based SQLi in itself is essential for an attacker to gain access to the backend database; this is why errors should be disabled in all cases.
  • Union-based SQLi: Union-based is a type of in-band SQL injection attack that takes advantage of the union SQL operator to concatenate the responses of two SQL statements into a single consolidated response.

主站蜘蛛池模板: 特克斯县| 上饶县| 贡嘎县| 桦川县| 徐州市| 辛集市| 汉沽区| 湖南省| 榆树市| 雅安市| 阿瓦提县| 平昌县| 海晏县| 泌阳县| 沁源县| 万盛区| 留坝县| 辽宁省| 潜山县| 共和县| 罗源县| 宁陵县| 赤水市| 德江县| 沐川县| 马尔康县| 富源县| 汕尾市| 贡觉县| 施秉县| 周口市| 汾西县| 策勒县| 嘉义县| 铜梁县| 东兰县| 沅陵县| 固镇县| 长海县| 雅江县| 潜山县|