Research of the Fast Attack Method for the SQL Blind Injection

ZHANG Ling-tong,LUO Sen-lin
DOI: https://doi.org/10.3969/j.issn.1671-1122.2013.05.005
2013-01-01
Abstract:To provide the theoretical basis and technical support for the detection of leaks for the SQL injection, by studying the attack technology of the SQL injection and analyzing the essential characteristics of leaks for the SQL injection, this paper extracts the attack template set of SQL, which can dynamically configure interior parameters. Based on the template set, we propose a fast attack method of SQL, and establish a set of fast attack prototype system of the SQL blind injection, combining with blind injection technology and multi-threading technology. The system uses the attack template set of the SQL injection to launch an attack and apply the multi-threading technology to improve attack efficiency. The experimental results show that the system, which can be well applied to detect the possibility of leaks existing in the application programs of Web, can accurately realize the attack goal and obtain the data of backstage database.
What problem does this paper attempt to address?