SQL Injection Isn't Dead: Smuggling Queries at the Protocol Level
simonwillison.net
simonwillison.net
SQL injection isn't dead, because I stumble upon a sql injection vulnerability every other day as a part of my job.
Anyone know if DEF CON publish videos of this kind of session?
Though SQL injection and other injection attacks are definitely not dead. All it takes is one programmer mistake and poof! Lots of XSS rely on accidentally injection of some value. Also hey lots of LLM based attacks are injection. Injection is not dead... oh no oh no
You can’t use a dumb appliance to fix developer stupidity.
(A case could be made for calling it a buffer underflow maybe?)
So it is complex field and there is always more vectors like this.
Interesting...a security researcher that thinks it's ok to trust the client.
His point is that adding in a request limit in your server config may not be enough because protocols like websocket might not inherit those size restrictions automatically due to specialized logic for implementing sockets over http.