{JS-ON: Security-OFF}: Abusing JSON-Based SQL Queries

แชร์
ฝัง
  • เผยแพร่เมื่อ 30 มี.ค. 2023
  • All major SQL-based database engines such as Postgres, SQLite, MS SQL, and MySQL have in the last few years started to adopt native JSON features that enable data interactions with complicated JSON-type objects. While these native JSON features are enabled by default, developers and researchers may still not be aware of the risk they introduce. We decided to find out, and whether they can be hacked....
    By: Noam Moshe
    Full Abstract and Presentation Materials:
    www.blackhat.com/eu-22/briefi...

ความคิดเห็น •