4 ms·
The attack is clever and original. AFAIK, nothing like it has ever been seen before. Since this attack came to light, SQLite has added features so that an app
by SQLite 6y ago
The attack is clever and original. AFAIK, nothing like it
has ever been seen before.
Since this attack came to light, SQLite has added features
so that an application can ensure that views and triggers
do not have side-effects (outside of the database file
itself). And if there are no side-effects
then the attack is basically harmless. Sure, the attacker
can still exfiltrate or corrupt data, but the attacker had
to have write access to the database file in order to carry out
the attack in the first place, so exfiltrating or corrupting
data is not an issue - they could already do that. See a
quick summary at https://sqlite.org/forum/forumpost/8beceed68e https://sqlite.org/forum/forumpost/8beceed68e
- Drip33 6y agoWas the write a shell php file portion of the video/exploit patched? Sites like https://sqliteonline.com/ https://sqliteonline.com/ and https://inloop.github.io/sqlite-viewer/ https://inloop.github.io/sqlite-viewer/ could be perpetually vulnerable if not?