WebApp Sec mailing list archives

Re: DB2 and Oracle with SQL injection


From: "Kevin Spett" <kspett () spidynamics com>
Date: Wed, 13 Aug 2003 16:13:27 -0400

Oracle offers free trial downloads of all of its products.  They're
fully-functional, so you can just grab what you're interested in and start
experimenting.  Here's the link for the DB server stuff:
http://otn.oracle.com/software/products/oracle9i/content.html


Kevin Spett
SPI Labs
http://www.spidynamics.com/

----- Original Message ----- 
From: "fr0stman" <fr0stman () sun-tzu-security net>
To: <webappsec () securityfocus com>
Sent: Wednesday, August 13, 2003 11:05 AM
Subject: DB2 and Oracle with SQL injection


Hi all,

I was curious if any of you have ran across good documents on default
tablespaces, etc to enumerate in DB2 or Oracle when using SQL injection. Or
just good SQL injection papers on those databases. There's tons o data on
MSSQL but not much covering the other two that are fairly widespread that I
have happened across anyhow.

Thanks in advance,

-- fr0stman --




Current thread: