DEF CON 32 - SQL Injection Isn't Dead Smuggling Queries at the Protocol Level - Paul Gerste

Поделиться
HTML-код
  • Опубликовано: 17 ноя 2024

Комментарии • 17

  • @devongreene6403
    @devongreene6403 19 дней назад +3

    Excellent presentation Paul! The TLV charts and sequencing diagrams were perfect. I also really liked the mentality of crafting payloads like you would simple stack overflows w/ NOPs or trampolines (exploitation really is art). Paul really opened a lot of eyes with this talk about how you can still achieve SQL Injection in the most impossible of scenarios. Well done 👏👏👏

  • @mrvescovi
    @mrvescovi Месяц назад +5

    This is amazing thanks!

  • @logiciananimal
    @logiciananimal 27 дней назад +2

    Given that Azure actually exposes Postgres DBMSes to the internet ... I wonder this can be used to attack these. People claim these are ok since there is access control at the DB layer, but ...

    • @peterwmdavis
      @peterwmdavis 25 дней назад +2

      For postgres, this is an attack on the application’s pg client, not the pg server.

  • @recklessroges
    @recklessroges 27 дней назад

    25:16 I got some deja vu - I felt like that BSON attack had been presented before, at some conference. (We probably meta a searchable meta db that can help cross-reference all tech conference talks.)

  •  25 дней назад

    I wonder if anyone is still using PHP.

  • @Aaaaaaahron
    @Aaaaaaahron 24 дня назад +2

    26:37
    ouch

  • @werawerlnwerlnrlnelr
    @werawerlnwerlnrlnelr 27 дней назад +7

    Sounds interesting but I stopped watching at "home of clean code", clean code is a bad cult

    • @MiesvanderLippe
      @MiesvanderLippe 27 дней назад +17

      Lol. They develop one of the most impactful security tools used for development. You should check your own presumptions if this is how you actually feel.

    • @notoriouslycuriouswombat
      @notoriouslycuriouswombat 26 дней назад +6

      weird reason not to watch a very good talk lol

    • @werawerlnwerlnrlnelr
      @werawerlnwerlnrlnelr 21 день назад

      @@MiesvanderLippe that might well be, but besides Clean Code being an absolute bullshit cult, Bob Martin, the guy behind Clean CodeTM!!!, is a Trump supporter, rabid sexist, etc. Tech has massively drifted to the right and I won't be silent about this trash. Responsibility is a thing.

    • @MissingInterval
      @MissingInterval 20 дней назад +2

      People you disagree with can still have great ideas.

    • @werawerlnwerlnrlnelr
      @werawerlnwerlnrlnelr 20 дней назад

      @@MissingInterval Sure! I just don't wanna have right wing weirdos in the back of my head when I'm consuming infosec content. (and on a technical level, clean code still sucks, but granted: that's probably not too relevant for this talk in particular. Though I would potentially not do business with clean code adherents on the suckiness alone)