官术网_书友最值得收藏!

In-band SQLi (classic SQLi)

In-band SQL injection is the classis SQL injection attack and it occurs when the attacker is able to use the same parameter and channel to launch an attack and get the corresponding results. In-band SQLi is divided into two types mainly:

  • Error-based SQLi: In this type of in-band SQLi, error messages are returned as a response from the database and allow the attacker to gain information about the backend database itself. In certain scenarios, error-based SQLi in itself is essential for an attacker to gain access to the backend database; this is why errors should be disabled in all cases.
  • Union-based SQLi: Union-based is a type of in-band SQL injection attack that takes advantage of the union SQL operator to concatenate the responses of two SQL statements into a single consolidated response.

主站蜘蛛池模板: 垫江县| 泰兴市| 奉贤区| 枣强县| 平邑县| 安乡县| 沧州市| 内乡县| 白朗县| 泰来县| 浦北县| 奎屯市| 芜湖市| 东台市| 大方县| 天气| 云浮市| 淳化县| 棋牌| 嘉兴市| 都昌县| 婺源县| 桐庐县| 渑池县| 兰考县| 扬州市| 蛟河市| 仙居县| 苗栗县| 邢台县| 卢龙县| 抚顺市| 临朐县| 泰来县| 福海县| 沾益县| 巴塘县| 张家界市| 阳山县| 漳州市| 新兴县|