Tidy up
This commit is contained in:
103 files changed
+3663
-3779
No files matched your search
@@ -9,9 +9,9 @@
|
||||
#### SQL Security
|
||||
|
||||
- Three entities
|
||||
1. Users
|
||||
2. Actions
|
||||
3. Objects
|
||||
1. Users
|
||||
2. Actions
|
||||
3. Objects
|
||||
- Users invoke actions on objects
|
||||
- Newly created objects are owned by the creator
|
||||
- Privileges can be granted
|
||||
@@ -41,7 +41,7 @@ This view abstracts the drugs away from the patients, so that the admin can orde
|
||||
|
||||
##### Why Not?
|
||||
|
||||
- `INSERT` / `UPDATE` actions depends on the `CHECK` options, else might be **blind inserts**
|
||||
- `INSERT` / `UPDATE` actions depend on the `CHECK` options, else might be **blind inserts**
|
||||
- This is where someone can’t access the data, but can update it
|
||||
- Completeness and consistency are not achieved automatically
|
||||
- Can quickly become very inefficient
|
||||
@@ -49,7 +49,7 @@ This view abstracts the drugs away from the patients, so that the admin can orde
|
||||
|
||||
#### Statistical Databases
|
||||
|
||||
- Where access to data is restricted access to aggregates is permitted
|
||||
- Where access to data is restricted, access to aggregates is permitted
|
||||
- This means averages, sums can be looked at
|
||||
- However, individual records cannot be viewed
|
||||
|
||||
@@ -93,7 +93,7 @@ Salary = V + T + U - S
|
||||
|
||||
- It’s common for user input to be read and then used within an SQL query
|
||||
- Unexpected user input can completely rewrite the query
|
||||
- Nears striking similarities to XSS attack
|
||||
- Bears striking similarities to an XSS attack
|
||||
- An application or website is vulnerable to an injection if it doesn’t filter SQL control characters:
|
||||
- `‘` Represents the beginning or end of a string
|
||||
- `;` represents end of a command
|
||||
@@ -123,5 +123,5 @@ This will work on `MS SQL` but not `MySQL`
|
||||
|
||||
#### Second Order SQL Injection
|
||||
|
||||
- Entry points may be checked for speical characters, but internal functions?
|
||||
- Store the exploit in one pass, then have it executed later
|
||||
- Entry points may be checked for special characters, but internal functions?
|
||||
- Store the exploit in one pass, then have it executed later
|
||||
Reference in new issue
Block a user