| To: | |
|---|---|
| Subject: | [Yaesu] FT-757GX problems. XE3WR |
| From: | |
| Date: | Fri, 28 May 2004 22:25:05 +0000 |
| List-post: | <> |
: The attacker starts with a value that likely doesn't exist in the database. This forces the original query to return no results, making it easier to see the data injected by the attacker.
If you are a developer looking to protect your site, the primary defense is to use . This ensures the database treats the input as literal text rather than executable code. : The attacker starts with a value that
: The attacker uses NULL placeholders to match the exact number of columns in the original table. This is a "trial and error" phase used to find the correct database structure without triggering an error. : The attacker starts with a value that
In a technical context, this specific snippet is a . Anatomy of the Attack : The attacker starts with a value that
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Yaesu] Re: FT 990, eswap |
|---|---|
| Next by Date: | [Yaesu] Paintaing your FT-101 / FR-101 / FL-101, certified-electronics |
| Previous by Thread: | [Yaesu] Re: FT 990, eswap |
| Next by Thread: | [Yaesu] Paintaing your FT-101 / FR-101 / FL-101, certified-electronics |
| Indexes: | [Date] [Thread] [Top] [All Lists] |