Jump to content
begood

SFX-SQLi: A new SQL injection technique tool

Recommended Posts

be4c185b570adaff7ce5ea4f6d3c5abe.jpg

SFX-SQLi (Select For XML SQL injection) is a new SQL injection technique which allows to extract the whole information of a Microsoft SQL Server 2005/2008 database in an extremely fast and efficient way.

This technique is based on the FOR XML clause, which is able to convert the content of a table into a single string, so its contents could be appended to some field injecting a subquery into a vulnerable input of a web application.

SFX-SQLi (Select For XML SQL injection)

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.


×
×
  • Create New...