2013/03/12 by Miroslav Stampar, Stampar, Miroslav · 2 citations
Computer Science · #Cryptography and Security (cs.CR) #Databases (cs.DB) #FOS: Computer and information sciences #Network Security and Intrusion Detection #Networking and Internet Architecture (cs.NI) #Security and Verification in Computing #Web Application Security Vulnerabilities #cs.CR #cs.DB #cs.NI
paper · pdf · doi:10.48550/arxiv.1303.3047
7 pages, 3 figures, 1 table. Presented at PHDays 2012 security conference, Moscow, Russia
arxiv created 2013/03/12 · openalex publication_date 2013/03/12 · arxiv updated 2013/03/14 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28
This paper describes an advanced SQL injection technique where DNS resolution process is exploited for retrieval of malicious SQL query results. Resulting DNS requests are intercepted by attackers themselves at the controlled remote name server extracting valuable data. Open source SQL injection tool sqlmap has been adjusted to automate this task. With modifications done, attackers are able to use this technique for fast and low profile data retrieval, especially in cases where other standard ones fail.