sql injection insert on duplicate key trick

7

Click here to load reader

Upload: mathias-karlsson

Post on 21-Apr-2017

287 views

Category:

Technology


1 download

TRANSCRIPT

Page 1: SQL Injection INSERT ON DUPLICATE KEY trick
Page 2: SQL Injection INSERT ON DUPLICATE KEY trick

• Login • Register • View article • Admin • Bcrypt, so couldn't get into admin panel :((

Page 3: SQL Injection INSERT ON DUPLICATE KEY trick

Hm!

Page 4: SQL Injection INSERT ON DUPLICATE KEY trick

+

Page 5: SQL Injection INSERT ON DUPLICATE KEY trick
Page 6: SQL Injection INSERT ON DUPLICATE KEY trick

Password of user 'admin' is now the same as password of user 'attacker'!

Page 7: SQL Injection INSERT ON DUPLICATE KEY trick

SQL Injection in INSERT is sometimes worse than SQL injection in SELECT

Lightning talk by @avlidienbrunn (Mathias Karlsson)