Web Hack List

Collected research

Expanding the control over the operating system from the database

The SOURCE Barcelona 2009 deck shows how database access becomes operating-system control: file read/write and command execution across MSSQL, MySQL and PostgreSQL, then a sys_bineval() UDF that runs a Metasploit payload inside DBMS memory, DEP/NX-safe and SEH-wrapped. It closes with exploitation of the MS09-004 sp_replwritetovarbin heap overflow, restoring ESP/EBP from the TEB to avoid a crash.

Record

Researcher
Bernardo Damele A. G.
Published by
Slideshare
Date
Format
Slides
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Bernardo Damele A. G., first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .