官术网_书友最值得收藏!

In-band SQLi (classic SQLi)

In-band SQL injection is the classis SQL injection attack and it occurs when the attacker is able to use the same parameter and channel to launch an attack and get the corresponding results. In-band SQLi is divided into two types mainly:

  • Error-based SQLi: In this type of in-band SQLi, error messages are returned as a response from the database and allow the attacker to gain information about the backend database itself. In certain scenarios, error-based SQLi in itself is essential for an attacker to gain access to the backend database; this is why errors should be disabled in all cases.
  • Union-based SQLi: Union-based is a type of in-band SQL injection attack that takes advantage of the union SQL operator to concatenate the responses of two SQL statements into a single consolidated response.

主站蜘蛛池模板: 海宁市| 广宁县| 塔河县| 沙河市| 米易县| 娄底市| 长岛县| 江源县| 讷河市| 广灵县| 长治县| 从化市| 夏津县| 呼伦贝尔市| 五家渠市| 瑞丽市| 正安县| 保亭| 岑巩县| 德保县| 北辰区| 诸暨市| 会昌县| 石阡县| 南木林县| 太谷县| 晋江市| 汉寿县| 衡南县| 育儿| 林甸县| 安福县| 清流县| 马边| 南郑县| 富川| 翁牛特旗| 汤原县| 北川| 贞丰县| 大英县|