Collected research
Advanced SQL injection to operating system full control
Black Hat Europe 2009 slides mapping SQL injection to full OS control. File access uses LOAD_FILE/DUMPFILE, COPY/lo_export and BULK INSERT/debug.exe; command execution uses custom UDF shared libraries and xp_cmdshell. It then builds a Metasploit out-of-band channel, relays SMB credentials via UNC paths, exploits MS09-004, and escalates with access-token abuse.
Record
- Researcher
- Bernardo Damele Assumpção Guimarães
- Published by
- blackhat.com
- Format
- Whitepaper
- Topic
- Injection
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Bernardo Damele Assumpção Guimarães, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .