There are some database specifics, every pentester should be aware of, when
testing for and exploiting SQLi vulnerabilities. Besides the different string
concatenation variants already covered above, there are some other specifics
that have to be considered and might turn out useful in some circumstances. For
example with Oracle Databases, every SELECT statement needs a following FROM
statement even if the desired data is not stored within a database. So when
trying to extract e.g. the DB username using a UNION SELECT statement, the DUAL
table may be utilized, which should always be available. Another point, if
dealing with MySQL, is the possibility to simplify the classic payload
A
quick update on the workshop we’ve just finished at
Hack in the Box 2012 Amsterdam:
Due
to popular demand we decided to bring the slides online without wasting any more
time. The official website of the conference is currently experiencing some
problems due to high interest in all the stuff what was released in the last two
days. Great conference!
Update #1: Slides are available for download
here.
In the course of our ongoing
cloud security research,
we’re continuously thinking about potential attack vectors against public cloud
infrastructures. Approaching this enumeration from an external customer’s
(speak: attacker’s 😉 ) perspective, there are the following possibilities to
communicate with and thus send malicious input to typical cloud infrastructures:
Management interfaces
Guest/hypervisor interaction
Network communication
File uploads
As there are already several successful exploits against management interfaces
(e.g.
here
and here) and
guest/hypervisor interaction (see for example
this one; yes,
this is the funny one with that ridiculous recommendation “Do not allow
untrusted users access to your virtual machines.” ;-)), we’re focusing on the
upload of files to cloud infrastructures in this post. According to our
experience with major Infrastructure-as-a-Service (IaaS) cloud providers, the
most relevant file upload possibility is the deployment of already existing
virtual machines to the provided cloud infrastructure. However, since a quick
additional research shows that most of those allow the upload of VMware-based
virtual machines and, to the best of our knowledge, the VMware virtualization
file format was not analyzed as for potential vulnerabilities yet, we want to
provide an analysis of the relevant file types and present resulting attack
vectors.
Hi @all,
today im releasing a new version of our famous fuzzing framework, dizzy. The
version counts 0.6 by now and youll get some brand new features!
see the CHANGELOG:
v0.6:
– ssl support
– server side fuzzing mode
– command output
– new dizz funktions: lambda_length, csum, lambda_csum, lambda2_csum
– recursive mutation mode
– new dizz objects: fill
– new interaction objects: null_dizz
– reconnect option
– additional fuzzing values
As
in 2011
we really liked the conference; there was a number of interesting talks and we
met quite some fellows from the IPv6 security space. Btw: we plan to organize a
dedicated IPv6 security summit in late 2012 (probably on 6th and 7th of
November) in Heidelberg, similar to the
Telco Sec Day
at Troopers. We’ll annouce details as for this one in some weeks.
As I mentioned the Telco Sec Day in the last post… for those who missed Flo’s
announcement: in the interim all slides of the Telco Sec Day are available
online here.
Obviously, given I initiated the event, I’m biased 😉 but to me it provided
great insight from both the talks and the networking with other guys from the
telco security field, and it did actually what it was meant for: fostering the
exchange between different players in that space, for the sake of sustainably
improving its’ overall security posture.
SQL injection attacks have been well known for a long time and many people think
that developers should have fixed these issues years ago, but doing web
application pentests almost all the time, we have a slightly different view.
Many SQL injection problems potentially remain undetecteddue to a lack of
proper test methodology, so we would like to share our approach and experience
and help others in identifying these issues.
In march 2012 Microsoft announced a critical vulnerability
(Microsoft Security Bulletin MS12-020)
related to RDP that affects all windows operating systems and allows remote code
execution. A lot of security professionals are expecting almost the same impact
as with MS08-067 (the conficker vulnerability) and that it will be only a matter
of time, until we will spot reliable exploits in the wild. Only a few days later
an exploit, working for all unpatched windows versions was released, so it seems
that they were right ;-), but of course no one will run an exploit without
investigating the code. So lets have a look into the exploit Code.
Some days ago a security advisory related to web application firewalls (WAFs)
was published on Full Disclosure. Wendel Guglielmetti Henrique found another bug
in the IBM Web Application Firewall which can be used to circumvent the WAF and
execute typical web application attacks like SQL injection (click
here
for details). Wendel talked already (look
here)
at the Troopers Conference in 2009 about the different
techniques to identify and bypass WAFs, so this kind of bypass methods are not
quite new.
TROOPERS12 came to an end last week on Friday; needless to say it was an
awesome event. 😉
The first two days offered workshops on various topics. On Monday Enno,
Marc “Van Hauser” Heuse and I gave a one day workshop on
“Advanced IPv6 Security”. I think attendees as well as trainers had a real good
time during and after the workshop fiddling around with IPv6. Especially Marc
had quite some fun as he discovered that we provided “global” IPv6 Connectivity
for the conference network, and according to one of his tweets, TROOPERS12 was
the first security conference he visited, offering this kind of connectivity.