Loading…
Thursday, July 30 • 5:35pm - 6:00pm
Muhaimin Dzulfakar: Advanced MySQL Exploitation

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

This talk focuses on how MySQL SQL injection vulnerabilities can be used to gain remote code execution on the LAMP and WAMP environments. Attackers performing SQL injection on a MySQL platform must deal with several limitations and constraints. For example, the lack of multiple statements in one query makes MySQL an unpopular platform for remote code execution compared to other platforms. This talk will show that arbitrary code execution is possible on the MySQL platform and explain the techniques. In this presentation, the author will demonstrate the tool he wrote, titled MySqloit. This tool can be integrated with metasploit and is able to upload and execute shellcodes using a SQL Injection vulnerability in LAMP or WAMP environments.
http://www.blackhat.com/html/bh-usa-09/bh-usa-09-speakers.html#Dzulfakar

Thursday July 30, 2009 5:35pm - 6:00pm PDT
Roman Ballroom

Attendees (0)