  Using Alternative Channels  ã This topic is four separate alternative channels for blind SQL injection. The basic idea is to package the results of an SQL query in such a way that they can be carried back to the attacker using one of the three alternative channels.  Database Connections  ã The first alternative channel is specific to Microsoft SQL Server and permits an attacker to create a connection from the victim’s  database to the attacker’s  database and carry query data over the connection. ã This is accomplished using the OPENROWSET command and can be an attacker’s  best friend where available. ã For this attack to work the victim database must be able to open a Transmission Control Protocol (TCP) connection to the attacker’s  database on the default port 1433


Jul 23, 2017
