Book description
SQL Injection Attacks and Defense, First Edition: Winner of the Best Book Bejtlich Read Award
"SQL injection is probably the number one problem for any server-side application, and this book unequaled in its coverage." –Richard Bejtlich, Tao Security blog
SQL injection represents one of the most dangerous and well-known, yet misunderstood, security vulnerabilities on the Internet, largely because there is no central repository of information available for penetration testers, IT security consultants and practitioners, and web/software developers to turn to for help.
SQL Injection Attacks and Defense, Second Edition is the only book devoted exclusively to this long-established but recently growing threat. This is the definitive resource for understanding, finding, exploiting, and defending against this increasingly popular and particularly destructive type of Internet-based attack.
SQL Injection Attacks and Defense, Second Edition includes all the currently known information about these attacks and significant insight from its team of SQL injection experts, who tell you about:
- Understanding SQL Injection – Understand what it is and how it works
- Find, confirm and automate SQL injection discovery
- Tips and tricks for finding SQL injection within code
- Create exploits for using SQL injection
- Design apps to avoid the dangers these attacks
- SQL injection on different databases
- SQL injection on different technologies
- SQL injection testing techniques
- Case Studies
- Securing SQL Server, Second Edition is the only book to provide a complete understanding of SQL injection, from the basics of vulnerability to discovery, exploitation, prevention, and mitigation measures
- Covers unique, publicly unavailable information, by technical experts in such areas as Oracle, Microsoft SQL Server, and MySQL---including new developments for Microsoft SQL Server 2012 (Denali)
- Written by an established expert, author, and speaker in the field, with contributions from a team of equally renowned creators of SQL injection tools, applications, and educational materials
Table of contents
- Cover image
- Title page
- Table of Contents
- Copyright
- Acknowledgements
- Dedication
- Contributing Authors
- Lead Author and Technical
- Introduction to the 2nd Edition
- Chapter 1. What Is SQL Injection?
- Chapter 2. Testing for SQL Injection
- Chapter 3. Reviewing Code for SQL Injection
-
Chapter 4. Exploiting SQL injection
- Introduction
- Understanding common exploit techniques
- Identifying the database
- Extracting data through UNION statements
- Using conditional statements
- Enumerating the database schema
- Injecting into “INSERT” queries
- Escalating privileges
- Stealing the password hashes
- Out-of-band communication
- SQL injection on mobile devices
- Automating SQL injection exploitation
- Summary
- Solutions Fast Track
- Chapter 5. Blind SQL Injection Exploitation
- Chapter 6. Exploiting the operating system
- Chapter 7. Advanced topics
- Chapter 8. Code-level defenses
- Chapter 9. Platform level defenses
- Chapter 10. Confirming and Recovering from SQL Injection Attacks
- Chapter 11. References
- Index
Product information
- Title: SQL Injection Attacks and Defense, 2nd Edition
- Author(s):
- Release date: June 2009
- Publisher(s): Syngress
- ISBN: 9781597499736
You might also like
book
SQL Injection Attacks and Defense
Winner of the Best Book Bejtlich Read in 2009 award! "SQL injection is probably the number …
book
SQL Injection Strategies
Learn to exploit vulnerable database applications using SQL injection tools and techniques, while understanding how to …
book
Cybersecurity Blue Team Toolkit
A practical handbook to cybersecurity for both tech and non-tech professionals As reports of major data …
video
Security Penetration Testing The Art of Hacking Series LiveLessons
10 Hours of Expert Video Instruction Overview This course is a complete guide to help you …