ycliper

Популярное

Музыка Кино и Анимация Автомобили Животные Спорт Путешествия Игры Юмор

Интересные видео

2025 Сериалы Трейлеры Новости Как сделать Видеоуроки Diy своими руками

Топ запросов

смотреть а4 schoolboy runaway турецкий сериал смотреть мультфильмы эдисон
Скачать

RuhrSec 2025 | SQL Injection Isn't Dead: Smuggling Queries at the Protocol Level

Автор: Hackmanit – IT Security

Загружено: 2025-03-27

Просмотров: 183

Описание: RuhrSec is the annual English speaking IT security conference with cutting-edge security talks by renowned experts. RuhrSec is organized by Hackmanit.
🔽 More information …

———

Talk // SQL Injection Isn't Dead: Smuggling Queries at the Protocol Level

Abstract // SQL injections seem to be a solved problem; databases even have built-in support for prepared statements, leaving no room for injections. In this session, we will go a level deeper: instead of attacking the query syntax, we will explore smuggling attacks against database wire protocols, through which remote, unauthenticated attackers can inject entire (No)SQL statements into an application's database connection. Using vulnerable database driver libraries as case studies, we will bring the concept of HTTP request smuggling to binary protocols. By corrupting the boundaries between protocol messages, we desynchronize an application and its database, allowing the insertion of malicious messages that lead to authentication bypasses, data leakage, and remote code execution.

———

Biography // Paul Gerste is a vulnerability researcher on Sonar's R&D team. He has a proven talent for finding security issues, demonstrated by his two successful Pwn2Own participations and discoveries in popular applications like Proton Mail, Visual Studio Code, and Rocket.Chat. When Paul is not at work, he enjoys playing and organizing CTFs with team FluxFingers.


Speaker //
Paul Gerste
Mastodon – https://infosec.exchange/@pspaul
X –   / pspaul95  

➡️ Slides - Download
https://www.ruhrsec.de/downloads/slid...

———

🚀 Subscribe to Our Channel:
   / @hackmanit-it-security  

👉 Read More About Interesting It Security Topics on Our Blog:
https://hackmanit.de/en/blog-en

✍️ Want a Deeper Dive
Training courses in Single Sign-On (OAuth, OpenID Connect, and SAML), Secure Web Development, TLS, and Web Services are available here:
https://hackmanit.de/en/training/port...

———

🌍 RuhrSec Conference Website: https://www.ruhrsec.de
🌍 Visit Our Website - Hackmanit: https://hackmanit.de/en

✖️ Follow RuhrSec on X:   / ruhrsec  
✖️ Follow Hackmanit on X:   / hackmanit  

✔ Follow RuhrSec on Linkedin:   / ruhrsec  
✔ Follow Hackmanit on Linkedin:   / hackmanit  

Follow Hackmanit on XING: https://www.xing.com/pages/hackmanitgmbh

———

Thanks for your attention and support. Stay secure. 🫶


#SQL #nosql #sqli #sqlinjection #hacking #RuhrSec #itsecurity #itsicherheit #cybersecurity #cybersicherheit

Не удается загрузить Youtube-плеер. Проверьте блокировку Youtube в вашей сети.
Повторяем попытку...
RuhrSec 2025 | SQL Injection Isn't Dead: Smuggling Queries at the Protocol Level

Поделиться в:

Доступные форматы для скачивания:

Скачать видео

  • Информация по загрузке:

Скачать аудио

Похожие видео

RuhrSec 2025 | Breaking and Securing Memory Isolation in Texas Instruments Microcontrollers

RuhrSec 2025 | Breaking and Securing Memory Isolation in Texas Instruments Microcontrollers

Doda - Pamiętnik (Official Video)

Doda - Pamiętnik (Official Video)

184 Spotkanie #wgdotnet: Rafał Schmidt: Balancing between business and technical metrics.

184 Spotkanie #wgdotnet: Rafał Schmidt: Balancing between business and technical metrics.

The Angular Renaissance - Key New Features | Lance Finney at PTH Conf 2025

The Angular Renaissance - Key New Features | Lance Finney at PTH Conf 2025

Physics Simulation Just Crossed A Line

Physics Simulation Just Crossed A Line

RuhrSec 2025 | Keynote – Complexity Kills – Why Adding Layers of Security Doesn’t Solve Much

RuhrSec 2025 | Keynote – Complexity Kills – Why Adding Layers of Security Doesn’t Solve Much

Generative AI-Powered Automated Workload Evaluation with Python, CloudWatch, and Amazon Q

Generative AI-Powered Automated Workload Evaluation with Python, CloudWatch, and Amazon Q

.NET Conf 2025 Spokane: What's New in Visual Studio 2026 - Benjamin Michaelis

.NET Conf 2025 Spokane: What's New in Visual Studio 2026 - Benjamin Michaelis

Report Analysis with Anvil Web  |  TLS-Anvil  |  KoTeBi Project – BSI

Report Analysis with Anvil Web  |  TLS-Anvil  |  KoTeBi Project – BSI

AI ruined bug bounties

AI ruined bug bounties

RuhrSec 2025 | Glitching AP4: A Technical Deep Dive Into Tesla’s Autopilot Computer

RuhrSec 2025 | Glitching AP4: A Technical Deep Dive Into Tesla’s Autopilot Computer

CyberCamp 2019 - Detección de amenazas a escala con osctrl

CyberCamp 2019 - Detección de amenazas a escala con osctrl

Agentic AI: Build a Multi-Agent Application with CrewAI | Alessandro Romano at PTH Conference 25

Agentic AI: Build a Multi-Agent Application with CrewAI | Alessandro Romano at PTH Conference 25

RuhrSec 2025 | 5G Security (And Why You Should Care About It)

RuhrSec 2025 | 5G Security (And Why You Should Care About It)

RuhrSec 2025 | Terrapin Attack: Breaking SSH Channel Integrity by Sequence Number Manipulation

RuhrSec 2025 | Terrapin Attack: Breaking SSH Channel Integrity by Sequence Number Manipulation

RuhrSec 2025 | Parse Me, Baby, One More Time: Bypassing HTML Sanitizer via Parsing Differentials

RuhrSec 2025 | Parse Me, Baby, One More Time: Bypassing HTML Sanitizer via Parsing Differentials

RuhrSec 2025 | Behind Closed Curtains - Insights on Security Vulnerabilities in Smartphone Basebands

RuhrSec 2025 | Behind Closed Curtains - Insights on Security Vulnerabilities in Smartphone Basebands

RuhrSec 2025 | Salesforce Snafus: Unveiling and Exploiting Security Misconfigurations Using ...

RuhrSec 2025 | Salesforce Snafus: Unveiling and Exploiting Security Misconfigurations Using ...

How Can MCP Servers Attack You - 1/2

How Can MCP Servers Attack You - 1/2

Робототехническая революция стала реальностью: почему Boston Dynamics и Figure вот-вот изменят всё.

Робототехническая революция стала реальностью: почему Boston Dynamics и Figure вот-вот изменят всё.

© 2025 ycliper. Все права защищены.



  • Контакты
  • О нас
  • Политика конфиденциальности



Контакты для правообладателей: [email protected]