Penetration Testing mailing list archives

sql injection: url or form based?


From: "johnny Mnemonic" <security4thefainthearted () hotmail com>
Date: Fri, 10 Feb 2006 14:06:42 +0800

I see many references to manipulation of SQL backend databases through both URL based and Forms based SQL injection but I'm wondering what are the essentials differences between both methods and when to use one over the other.
Thanks.

_________________________________________________________________
Get cheap fares online with MSN Travel http://www.msn.com.sg/travel/


------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner: Hackers are concentrating their efforts on attacking applications on your website. Up to 75% of cyber attacks are launched on shopping carts, forms, login pages, dynamic content etc. Firewalls, SSL and locked-down servers are futile against web application hacking. Check your website for vulnerabilities to SQL injection, Cross site scripting and other web attacks before hackers do! Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------


Current thread: