3 ms·
This is fantastic stuff, building these machines out of odd primitives. They kind of remind me of blind SQL injection attacks. When you can inject SQL, but can
by rikthevik 2y ago
This is fantastic stuff, building these machines out of odd primitives.
They kind of remind me of blind SQL injection attacks. When you can inject SQL, but can't view the output, so you use things like `pg_sleep()` to get a low-fidelity form of query output. Depending on how far you want to go, you can use different sleep lengths to slowly exfiltrate data.
https://owasp.org/www-community/attacks/Blind_SQL_Injection https://owasp.org/www-community/attacks/Blind_SQL_Injection