4 ms·
> If you're also concerned about read-write SQL injection being used to forge tokens for arbitrary user accounts, you may want to worry instead about the attack
by foo101 10y ago
> If you're also concerned about read-write SQL injection being used to forge tokens for arbitrary user accounts, you may want to worry instead about the attacker using their access to compromise the filesystem and OS.
I don't get this part. Read-write SQL injection does not imply that the attacker has access to the filesystem. The concern about RW-SQL injection is still valid. If I can somehow protect an attacker from modifying tokens via RW-SQL injection, it is still an improvement, and I may not have to worry about the filesystem being accessed because that may require a non-SQL attack vector.
- CiPHPerCoder 10y ago> I don't get this part. Read-write SQL injection does not imply that the attacker has access to the filesystem. Theoretically no, but in practice, all you really need is SELECT '<?php eval($_GET["foo"]); ' INTO OUTFILE '/var/www/example.com/public_html/backdoor.php'; to get access to most servers.